<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=reinvent%25202025%2520using%2520generative%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sat, 08 Aug 2026 06:29:37 +0200</lastBuildDate>
<pubDate>Sat, 08 Aug 2026 06:29:37 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - 📰 Alle Kategorien</copyright>
<managingEditor>tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-isharestuff-com/media/logo.png</url>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=reinvent%25202025%2520using%2520generative%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml?q=reinvent%25202025%2520using%2520generative%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Microsoft’s Quantum Chief Doesn’t Care That Scientists Don’t Believe His Results]]></title>
<description><![CDATA[Zulfi Alam thinks his team doesn’t need to “prove” they engineered a new state of matter in their bid to reinvent computing. Science would disagree.]]></description>
<link>https://tsecurity.de/de/3707955/it-nachrichten/microsofts-quantum-chief-doesnt-care-that-scientists-dont-believe-his-results/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707955/it-nachrichten/microsofts-quantum-chief-doesnt-care-that-scientists-dont-believe-his-results/</guid>
<pubDate>Thu, 06 Aug 2026 13:28:23 +0200</pubDate>
<content:encoded><![CDATA[Zulfi Alam thinks his team doesn’t need to “prove” they engineered a new state of matter in their bid to reinvent computing. Science would disagree.]]></content:encoded>
</item>
<item>
<title><![CDATA[Secure AI adoption starts with API best practices]]></title>
<description><![CDATA[You don’t need to be a fortune teller to understand where enterprise IT is headed. McKinsey reported in November that 62% of global organizations were experimenting, piloting or scaling agentic AI projects. More recently, Gartner forecast that worldwide spending on AI will top $2.59 trillion in 2...]]></description>
<link>https://tsecurity.de/de/3702824/it-security-nachrichten/secure-ai-adoption-starts-with-api-best-practices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702824/it-security-nachrichten/secure-ai-adoption-starts-with-api-best-practices/</guid>
<pubDate>Tue, 04 Aug 2026 12:09:02 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">You don’t need to be a fortune teller to understand where enterprise IT is headed. McKinsey<a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai"> </a><a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai">reported</a> in November that 62% of global organizations were experimenting, piloting or scaling agentic AI projects. More recently,<a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-19-gartner-forecasts-worldwide-ai-spending-to-grow-47-percent-in-2026"> </a><a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-19-gartner-forecasts-worldwide-ai-spending-to-grow-47-percent-in-2026">Gartner forecast</a> that worldwide spending on AI will top $2.59 trillion in 2026 – an increase of 47% from last year. But with all the opportunity of AI comes risk.</p>



<p class="wp-block-paragraph">Two thirds of organizations have suffered from a cybersecurity incident linked to AI agents over the past year, according to the<a href="https://cloudsecurityalliance.org/artifacts/autonomous-but-not-controlled-ai-agent-incidents-now-common-in-enterprises"> </a><a href="https://cloudsecurityalliance.org/artifacts/autonomous-but-not-controlled-ai-agent-incidents-now-common-in-enterprises">Cloud Security Alliance (CSA)</a> – highlighting that these risks are no longer hypothetical.</p>



<p class="wp-block-paragraph">As they work to protect their organization by enforcing safe, governed adoption of AI, security leaders are overlooking the critical role of mature API management. Securing AI at the agent layer is only part of the solution. Without rigorous API discovery, protection and governance in place, other investments in AI security could be in vain.</p>



<h2 class="wp-block-heading">Why API security matters to AI</h2>



<p class="wp-block-paragraph">AI is nothing without APIs. LLMs ingest and generate huge volumes of data, which is accessed via APIs, at incredible scale. APIs that once were called a hundred or so times per day receive thousands of requests every minute thanks to AI-powered workloads.</p>



<p class="wp-block-paragraph">It’s easy to see why APIs have become such a key mechanism for threat actors to exploit AI systems, or to exfiltrate data in the other direction. The challenge is that APIs have a long history of posing a challenge for security teams.</p>



<p class="wp-block-paragraph">Some 87% of organizations suffered API-related security incidents last year, with APIs linked to AI the most commonly cited incident type, according to<a href="https://www.akamai.com/lp/report/api-security-study-2026"> </a>one study. A separate study<a href="https://hubspot.wallarm.com/hubfs/Annual%202025%20API%20ThreatStatsTM%20Report.pdf"> </a><a href="https://hubspot.wallarm.com/hubfs/Annual%202025%20API%20ThreatStatsTM%20Report.pdf">last year recorded</a> 439 new AI-related CVEs over the previous 12 months, marking an annual increase of 1025%. Nearly all were directly linked to APIs; including injection flaws, misconfigurations and new memory corruption vulnerabilities.</p>



<p class="wp-block-paragraph">Closing this security gap isn’t just important to mitigate the financial and reputational damage of the worst-case scenario of a data breach. It’s also increasingly important to keep regulators happy. Both NIS2 and DORA, while not AI-focused regulations, certainly make a strong case for looking at AI capabilities through the lens of resilience and security.</p>



<h2 class="wp-block-heading">Not seeing is not knowing</h2>



<p class="wp-block-paragraph">One of the most acute challenges with API security is the proliferation of shadow and zombie APIs. Modern cloud and microservices environments are highly distributed, with APIs scattered everywhere – many of which are forgotten or have never even been recorded. That doesn’t matter to an AI agent. They’re highly resourceful at discovering APIs that are accessible, even if they’ve not been specifically asked or authorized to use that approach. If APIs offer a route to complete the task that’s been assigned to them, AI agents will invariably find and use them.</p>



<p class="wp-block-paragraph">The issue is that these shadow or zombie APIs may not have been designed securely or in line with the organization’s current governance policies, leading to data loss or other unintended consequences. This was a major challenge even before Mythos changed the game for systems defenders and adversaries alike. With frontier models capable of discovering vulnerabilities and chaining exploits at a whole new speed and scale, the task of securing APIs is even more urgent.</p>



<h2 class="wp-block-heading">Planning for the worst</h2>



<p class="wp-block-paragraph">There’s plenty of opportunities for threat actors – whether armed with the latest AI models or not, to probe for API vulnerabilities. There are also mounting real-world examples of incidents of AI agents going rogue.</p>



<p class="wp-block-paragraph">One of the most widely publicized occurred when a Cursor coding agent<a href="https://www.osohq.com/developers/ai-agents-gone-rogue"> </a><a href="https://www.osohq.com/developers/ai-agents-gone-rogue">permanently deleted</a> a customer’s production database in just nine seconds. To do so, it found an API token stored in an unrelated file, which carried blanket permissions. No confirmation was required by the API to perform the operation.In a similar incident, Replit’s AI<a href="https://codenotary.com/blog/when-ai-goes-rogue-the-replit-incident-and-its-lessons"> </a><a href="https://codenotary.com/blog/when-ai-goes-rogue-the-replit-incident-and-its-lessons">agent deleted</a> a live production database despite being instructed not to.</p>



<p class="wp-block-paragraph">These are useful cautionary tales. There are three key measures security leaders can implement to ensure this never happens to their organization:</p>



<ol class="wp-block-list">
<li><strong>Start with discovery</strong> – because you can’t protect what you can’t see. Security leaders need to ensure all APIs running in their environment – both internal and third-party – are automatically and continuously captured and documented so they have a complete, accurate and up to date inventory.</li>



<li><strong>Focus on runtime protection</strong> – to mitigate the impact of zero-day exploits. There are too many vulnerabilities to patch them all. Teams are stretched and time is in short supply. Not everything can be patched at the speed of AI – for now at least. Runtime protection techniques – such as building rules and signatures into web app firewalls, are the best solution, enabling security teams to prevent flaws being exploited from outside.</li>



<li><strong>Don’t neglect insider threats </strong>– API abuse is commonplace, so it’s also important to enforce governance around user behavior. Security leaders should implement measures that enable teams to identify anomalies that fall outside of expected behavior so they can respond faster. To do so, they need to consider what level of authentication and permissions are required for specific APIs, from both a human and agent perspective. AI tools should never have sufficient permissions to delete entire production databases.</li>
</ol>



<h2 class="wp-block-heading">Security at the speed of AI</h2>



<p class="wp-block-paragraph">What will separate the winners from the losers going forward is the ability to manage risk in a way that doesn’t constrain the business. That means agile, unintrusive, secure-by-design approaches built around runtime protection and comprehensive visibility into API posture.</p>



<p class="wp-block-paragraph">The automobile sector is a great example of what’s happening in AI right now. When the industry was in its early days, the focus was on the basics – features that enabled the owner to get from A to B. As speed increased, people demanded safety – seatbelts, ABS brakes and roll bars.</p>



<p class="wp-block-paragraph">Today the AI world is also accelerating. Businesses have moved beyond the stage of wanting to see that it works. Now, they want security and control – and that starts at the API layer.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026]]></title>
<description><![CDATA[When Cisco ran 6,986 multi-turn attacks against 15 flagship models, attackers who adapted across the conversation broke through as often as 88.3% of the time. Amy Chang, Cisco's head of AI threat intelligence and security research, brought that finding to the agentic security panel at VB Transfor...]]></description>
<link>https://tsecurity.de/de/3690018/it-nachrichten/multi-turn-attacks-broke-ai-models-88-of-the-time-single-turn-testing-missed-it-cisco-ai-security-lead-warns-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690018/it-nachrichten/multi-turn-attacks-broke-ai-models-88-of-the-time-single-turn-testing-missed-it-cisco-ai-security-lead-warns-at-vb-transform-2026/</guid>
<pubDate>Thu, 23 Jul 2026 20:48:24 +0200</pubDate>
<content:encoded><![CDATA[<p>When Cisco ran 6,986 multi-turn attacks against <a href="https://blogs.cisco.com/ai/proprietary-problems">15 flagship models</a>, attackers who adapted across the conversation broke through as often as 88.3% of the time. Amy Chang, Cisco's head of AI threat intelligence and security research, brought that finding to the agentic security panel at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>; the number should worry anyone still running single-turn red-teaming programs.</p><p><a href="https://venturebeat.com/resources/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials">VentureBeat's June 2026 Pulse survey of 107 enterprise respondents</a> explains why the room was full. More than half, 54%, have already had a confirmed agent security incident (18%) or a near-miss caught before harm (36%). Just 32% give every agent its own scoped, managed identity, and fewer still, 30%, isolate their highest-risk agents in sandboxes. Provider-native and hyperscaler controls remain the primary agent security layer at <a href="https://venturebeat.com/security/shared-api-keys-expose-ai-agent-fleets-venturebeat-research">82% of companies surveyed</a>. The world's largest security vendors have done the same math. </p><p>Palo Alto Networks closed its <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era">$25 billion acquisition of CyberArk</a> in February, CrowdStrike <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-to-acquire-sgnl-to-transform-identity-security-for-ai-era/">agreed in January to pay $740 million for SGNL</a>, and Cisco announced its <a href="https://blogs.cisco.com/news/cisco-announces-intent-to-acquire-astrix-security">intent to acquire Astrix Security</a> for a reported $400 million, all of it aimed at the identity and isolation layer most enterprises have not finished building.</p><div></div><p>Chang came to the panel with almost two decades of experience spanning cybersecurity operations, government, and the military. She ran global cybersecurity operations as an executive director at JPMorgan Chase, where she led the bank's cyber threat intelligence teams, and served as a senior staffer on the House Foreign Affairs Committee and as a U.S. Navy Reserve officer. She also teaches cybersecurity and emerging threats as adjunct faculty at the Middlebury Institute of International Studies.</p><p>Chang's 88.3% number comes from a study she co-authored with Nicholas Conley, built on 30,090 single-turn prompts and 6,986 multi-turn attacks against those 15 closed and proprietary flagship models. Multi-turn success rates ranged from 7.89% to 88.3%, every model tested showed non-trivial multi-turn exposure, and the two testing styles did not even rank the models in the same order. Cisco publishes adversarial evaluation signals for what is now 105 models on its <a href="https://leaderboard.aidefense.cisco.com/">LLM Security Leaderboard</a>, she told the audience.</p><p>"If you don't understand how models are susceptible to different types of attacks, then you are unable to account for how that model that is powering your agent, that is powering your application, to understand where those failure points are," Chang said. Single-turn testing is the one-shot malicious prompt, she explained, while extending an attack into a longer conversation "is more realistic of how we are actually engaging with our models, with our agents, with our applications." That longer arc surfaces harmful outputs and misaligned behaviors that a snapshot never catches.</p><p>Cisco has pushed the testing itself into agentic territory. Chang described a framework where agents assess a deployment scenario, develop relevant attacks, judge whether they are worth pursuing, execute them, and evaluate their own success. What surprised her most, after all that sophistication, was how simple the defensive answer stays. "The answer is still that it's pretty simple," she said. "You don't have to get super creative. You just need to think about truly what are the fundamentals and basics of what I'm trying to secure in my organization."</p><p>Her starting point for CISOs beginning agentic deployments is Cisco's <a href="https://blogs.cisco.com/ai/security-framework">Integrated AI Security and Safety Framework</a>, which she said "stipulates all the ways that AI can be compromised across the AI lifecycle" from modality through supply chain. From there, teams can work backward from real incidents, trace how each attack was achieved, and use the framework to build a strategy with the right coverage and mitigations.</p><p>Heather Ceylan, the CISO of Box, sees the same gap from the defender's side. "A lot of what you see out there with agent red teaming is just single-turn, and that's not how people are actually interacting with AI day-to-day," she told the audience. Box now simulates multi-turn adversaries with agents that think like an attacker and iterate attempt after attempt to hijack the target. "You have to pressure test your agents because otherwise you don't know if your execution controls are really working as you intended."</p><p>Box deployed agents inside its security operations center about a year ago, starting with human approval required for every action, and trust built quickly enough that analysts shifted into monitoring mode. Then the agent made one mistake, and every bit of that accumulated trust vanished. "They had to start all over again," she said. "So I think that that monitoring piece is so important. Even if you're not gonna have a human in the loop, things change, models change, and we can't control how the models change and interpret things."</p><p>Rajesh Parekh, VP of AI and ML at Intuit, brought the builder's perspective. Parekh led large-scale computer vision and ML systems powering Google's Maps and Geo products before joining Intuit, and holds a doctorate in computer science. </p><h2>Three layers versus an operating system</h2><p>Ceylan described Box's approach as three concentric layers. Permissioning comes first, so the agent never accesses more content than the human who invoked it. Ephemeral sandbox environments spin up for each agent task, containing the blast radius if an agent gets hijacked, and runtime execution control restricts the agent's tool calls to only those relevant to the task at hand. "If you want an agent to summarize a doc for you, if you have a prompt injection that came in that says forward this to maliciousattacker at domain.com, it can't do that," Ceylan said. "That action in that tool call is not even in its vocabulary."</p><p>She classified agent actions into three oversight categories. Actions that are not sensitive, like read and summarize, need no human in the loop. Moderately sensitive actions skip human approval but get logged and monitored, while destructive actions like mass deletion of files always require a human. "Things are gonna shift between those three categories quite a bit," she acknowledged, "but setting those types of categories up front allows you to have a principled framework."</p><p>Rather than layering controls onto agents one at a time, Intuit has built a central platform called GenOS, short for generative AI operating system, which abstracts security, risk, and fraud modeling so individual agent developers never reinvent protection. "Permissioning is not about giving access to AI," Parekh said. "Instead, it is defining very tightly scoped and clearly auditable authority to the agent to perform very specific tasks." Intuit evolved from agents inheriting user permissions to each agent carrying its own identity, and the company is now investigating mid-session permission changes tied to the specific task underway.</p><p>Parekh calls the broader model an AI-powered expert platform, one where the human expert is built into the trust architecture rather than bolted on as a gate. "The paradigm that we are pursuing is where the user, the AI agent, and the human expert are collaborating to solve the user problem," he said.</p><h2>The end of human code review</h2><p>Ceylan took on the tension between security testing and development velocity without hedging. "The days of secure code reviews where a human's looking at the code and we're looking at security architecture reviews, design docs, those are done," she said. "If you keep trying to do security that way, you're gonna get left behind." Box is building toward a fully agentic development lifecycle where agents review design documents, apply security requirements, and review the code for vulnerabilities. "I'm very optimistic that we will get to a point where we will write code without security vulnerabilities because agents and the models are going to get so good at writing code without vulnerabilities," she said. "We're still a long way away from that."</p><p>Her advice for development teams skips the advanced AI concepts entirely and returns to basics that predate agents. "It comes down to very basic least privilege access," she said. "If you start giving your agents overly broad permissions at the beginning, it's really hard to comb that back and build an infrastructure that allows for those ephemeral credentials and only those narrowly scoped tasks."</p><p>Parekh explained why the red teaming surface has expanded so quickly. "These agents have skills, and skills could become vulnerabilities," he said. "Agents have access to certain data, they have access to tools, and there could be threats that are lurking within those tools as well. So suddenly the blast radius of the malicious code or the intent increases dramatically." When Intuit identifies common vulnerability patterns from its manual red teaming exercises, it automates those tests back into the GenOS harness so future agents inherit protection and red teamers stay focused on new threat vectors. Runtime scanning of prompts and responses adds a final layer that can stop a suspect response and escalate to a human expert, he said.</p><p>"You need to continuously test to ensure that those remain robust to the protections that you have built, as well as to account for any sort of drift or any other types of dependencies that you introduce into your scenario that can create novel vulnerabilities," she said.</p><h2>Intent versus probability</h2><p>An audience question about intent detection set off the sharpest exchange of the session. Ceylan noted that when Box's own agent operates, the system always knows the user's intent because it controls the prompt, which means guardrails and tool-call restrictions can be engineered around it. The harder challenge, which she admitted Box is still trying to solve, arrives when external agents connect and the context behind the request is opaque.</p><p>That exchange exposed a split running through the wider industry. Mastercard, in the fireside chat immediately preceding the panel, came down on the side of quantifying intent, building an open-source framework to propagate it as a standard because complex B2B procurement cannot work without that trust. Endpoint security CTOs, in briefings with VentureBeat, have gone the other way, saying they will bet on probability rather than intent inference for production workloads. Chang explained why models, as they are trained today, cannot reliably derive intent from a prompt, which is why deterministic controls and behavioral proxies remain necessary. Ceylan agreed that both are required. "If you're not doing anything deterministic, you're really relying heavily on that intent, and I haven't seen programs that are there yet," she said.</p><p>Ceylan's story about trust collapsing after a single agent mistake landed as the panel's most memorable moment because enterprise agentic security is not a problem that gets solved and stays solved. Models change, permissions drift, and adversaries adapt across multi-turn conversations that snapshot tests never capture.</p><p>For the 82% of enterprises relying on provider-native controls as their primary security layer, and the 59% shopping for agent security tooling over the next 12 months, the panel's takeaway was blunt. Test the way attackers attack, across full conversations and continuously, or find out in production what your single-turn red teaming missed.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Startup Spotlight: MediaPact wants to reinvent digital ads for the AI era]]></title>
<description><![CDATA[As AI reshapes online search and advertising, Seattle startup MediaPact is building a marketplace to help brands and publishers strike direct sponsorship deals. Founder Lacie Thompson discusses launching the company, using AI to build without coding experience, and spotting a new opportunity in a...]]></description>
<link>https://tsecurity.de/de/3687728/it-nachrichten/startup-spotlight-mediapact-wants-to-reinvent-digital-ads-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687728/it-nachrichten/startup-spotlight-mediapact-wants-to-reinvent-digital-ads-for-the-ai-era/</guid>
<pubDate>Thu, 23 Jul 2026 00:52:58 +0200</pubDate>
<content:encoded><![CDATA[<img fetchpriority="high" loading="eager" width="1260" height="840" src="https://cdn.geekwire.com/wp-content/uploads/2026/07/Lacie-Thompson-2023-Headshot-1-1260x840.jpeg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/07/Lacie-Thompson-2023-Headshot-1-1260x840.jpeg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/07/Lacie-Thompson-2023-Headshot-1-768x512.jpeg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/07/Lacie-Thompson-2023-Headshot-1-1536x1024.jpeg 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/07/Lacie-Thompson-2023-Headshot-1-2048x1365.jpeg 2048w" sizes="(max-width: 1260px) 100vw, 1260px"><br>As AI reshapes online search and advertising, Seattle startup MediaPact is building a marketplace to help brands and publishers strike direct sponsorship deals. Founder Lacie Thompson discusses launching the company, using AI to build without coding experience, and spotting a new opportunity in a rapidly changing digital media landscape. <a href="https://www.geekwire.com/2026/startup-spotlight-mediapact-wants-to-reinvent-digital-ads-for-the-ai-era/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Leadership bottlenecks slow AI adoption]]></title>
<description><![CDATA[At Cisco, VP of engineering Jason Andrews deals with all the same technical issues as every other company deploying AI, including ensuring it’s governed, secure, and integrating multiple data sources, legacy systems, and AI models.



But these issues are relatively straightforward compared to th...]]></description>
<link>https://tsecurity.de/de/3685910/it-security-nachrichten/leadership-bottlenecks-slow-ai-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685910/it-security-nachrichten/leadership-bottlenecks-slow-ai-adoption/</guid>
<pubDate>Wed, 22 Jul 2026 12:14:12 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">At Cisco, VP of engineering Jason Andrews deals with all the same technical issues as every other company deploying AI, including ensuring it’s governed, secure, and integrating multiple data sources, legacy systems, and AI models.</p>



<p class="wp-block-paragraph">But these issues are relatively straightforward compared to the bigger challenges relating to the fast pace of change, specifically how AI can touch and transform nearly every aspect of business.</p>



<p class="wp-block-paragraph">“We’re thinking about it every day,” he says. “My belief is we’ll be seeing a massive acceleration of everything.”</p>



<p class="wp-block-paragraph">In coding, for example, he’s witnessing productivity increases up to 110% with AI assistants. “I can build apps or custom integrations a lot faster,” he adds.</p>



<p class="wp-block-paragraph">And the real benefit of AI isn’t just in speeding up individual steps in a process, but in making AI the core of a new business process. But building it from scratch puts even more pressure on organizations trying to get employees up to speed on new ways of doing things.</p>



<p class="wp-block-paragraph">“We want to move fast, train people, and get them onboarded,” he says. “But what I thought AI was going to do for my organization nine months ago is different from three months ago.” So by the time something is rolled out, it’s changed three times.</p>



<p class="wp-block-paragraph">“I struggle with the change management aspect,” he says. “The legacy model of change management isn’t fast enough. How do you create that constant learning?”</p>



<p class="wp-block-paragraph">One of the ways Cisco approaches it is to create communities where people can talk about these issues and share best practices and governance, and you have to keep people’s minds open that every day is going to be different than the last, Andrews adds.</p>



<h2 class="wp-block-heading">Testing the AI waters</h2>



<p class="wp-block-paragraph">Cisco isn’t the only organization struggling with change management in the face of the AI tsunami. <a href="https://www.ibm.com/thought-leadership/institute-business-value/en-us/c-suite-study/ceo">In a survey of 2,000 global CEOs IBM released in May</a>, 83% of them said AI success depends more on adoption than on the technology itself, and 77% said talent and technology roles are converging.</p>



<p class="wp-block-paragraph">“Thanks to Claude Code, our entire development cadence is exponentially greater than a year ago,” says Andrew Johnson, CIO at Brownstein Hyatt Farber Schreck, a Denver-based law firm with about 700 employees and clients around the US. But, as with Cisco, the biggest challenge isn’t technical.</p>



<p class="wp-block-paragraph">“In our industry, with our circumstances, we’re probably less constrained by technical capability than organizational constraints, culture, aptitude, the need to bind people to technology, and what helps me and the client,” he says. “There’s a tremendous amount of cultural shift that has to happen in our organization, which is far more demanding of my attention and complexity of thought than the technical stuff.”</p>



<p class="wp-block-paragraph">Companies that bill by the hour, such as law firms, may face additional challenges as attorney productivity increases because billable hours might go down. Alternatively, the total number of cases could go up as litigation becomes less expensive. Either way, firms that adapt will see competitive advantage, and the rest will fall behind, putting more pressure on the need for change management.</p>



<p class="wp-block-paragraph">“If people can’t embrace technology, we won’t be able to get a lot of value out of it,” says Johnson. “I’m talking to people about adapting their way of work. There are certainly a lot of people intrigued and anxious to dive in. They recognize the connection between the potential of the technology and what we do.”</p>



<p class="wp-block-paragraph">But helping everyone see that connection and then working with them to change their habits is difficult, and requires solid relationships and good communications. “That’s been far more of a bottleneck for us,” he says.</p>



<p class="wp-block-paragraph">To address the issue, the firm has developed a network of technology champions who also understand the legal side of the business. “Now we need lawyers who know how to use the technology and can articulate these things to the people we’re trying to reach,” Johnson says.</p>



<p class="wp-block-paragraph">But change management is only one leadership bottleneck slowing AI adoption. Companies also struggle with figuring out their vision for AI, with slow decision-making, and a tendency to focus on the past instead of the future.</p>



<h2 class="wp-block-heading">Vision and strategy</h2>



<p class="wp-block-paragraph"><a href="https://www.grantthornton.com/services/advisory-services/artificial-intelligence/2026-ai-impact-survey">In another survey, this time of 950 business leaders released by Grant Thornton</a> in April, 51% said strategy is the biggest driver of ROI when it comes to AI adoption, but 79% of operations leaders said they don’t have a fully developed and implemented AI strategy.</p>



<p class="wp-block-paragraph">“Having leadership understanding why AI is needed and what objective they’re trying to achieve is very important,” says Shivi Verma, senior manager of engineering at Docusign. “Sometimes leadership doesn’t have a strategy for their organization on how AI should be adopted. Many times it’s bottom-up, which creates a chaotic experience.”</p>



<p class="wp-block-paragraph">When Docusign started adopting gen AI, different teams and organizational units wanted to go in different directions. “All were coming up with their own strategy and tooling,” he says. So Docusign brought business leaders together to understand the pain points, and decide on the technology.</p>



<p class="wp-block-paragraph">“Getting requirements and placing a bet on a specific technology was important,” he says, “as well as pivoting to a different technology if needed.”</p>



<p class="wp-block-paragraph">In order to adapt to changes, the company wanted to have a nimble approach, starting with smaller use cases, with power users, and problem areas.</p>



<p class="wp-block-paragraph">“We try to plan for four to six months,” he adds. “We set expectations for our leadership that we place a bet with a specific technology, but want to be able to pivot.”</p>



<p class="wp-block-paragraph">Today, the leadership challenge front lines have moved yet again, to agentic AI. “Folks are creating their own agents and deciding their own permissions,” Verma adds. “We’re still coming up with a governance strategy.”</p>



<h2 class="wp-block-heading">Slow decision-making</h2>



<p class="wp-block-paragraph">When it comes to AI deployments, Dan Diasio, global AI consulting leader at EY and CTO for its US consulting business, admits he’s a bottleneck.</p>



<p class="wp-block-paragraph">There’s a great deal of interest in what AI can do, and using a variety of new AI tools. But since the firm deals with sensitive client data, safety is paramount. It’s a slow process, but important to build secure infrastructure, and to have trust in the technology. “That’s a reasonable bottleneck that makes sense,” he says.</p>



<p class="wp-block-paragraph">Trust in the tools they work with is essential because clients expect it. “Every tool we use has to go through a detailed security and information privacy impact assessment, as well as a whole other set of controls so they can be used appropriately and safely,” he says.</p>



<p class="wp-block-paragraph">These reviews can take a lot of time, though, and in the age of AI, speed is a highly valued currency. So how do you balance the two, when safety reviews can require input from a lot of different stakeholders and be extremely time intensive?</p>



<p class="wp-block-paragraph">“We’ve stood up a team to be able to quickly certify and address a variety of platforms,” Diasio says. “Instead of working with different departments in the way we used to, we’ve started identifying representatives from different departments into a cohort. Decisions we used to make in months now take weeks.”</p>



<p class="wp-block-paragraph">According to a <a href="https://www.westmonroe.com/insights/why-speed-matters">West Monroe survey</a> of more than 1,200 leaders released earlier this year, slow decision-making is already showing up on the bottom line. Nearly three out of four leaders said their organizations lose up to 5% of annual revenue to slow decision-making and delayed execution.</p>



<p class="wp-block-paragraph">And the top reasons for the delays? According to 40% of the managers surveyed, the problem was the skills gaps of overwhelmed teams, and 35% pointed to layers of management or approvals. Nearly half said they’re spending 10 to 25% of their time on rework, excessive approvals, and unnecessary meetings, and more than half say up to 50% of their projects fail or lose momentum to delays.</p>



<h2 class="wp-block-heading">Focus on the future, not the past</h2>



<p class="wp-block-paragraph">When it comes to the decision about where to apply AI in an organization, the tendency, Diasio says, is to turn to the experts with the most expertise in the business. But these are the same people most likely to focus on improving on what they’re already doing.</p>



<p class="wp-block-paragraph">“And that often blinds people to what’s possible in the future,” he says. “That becomes a significant bottleneck.” So the solution is to revamp the decision-making process around the new reality.</p>



<p class="wp-block-paragraph">“What we see some advanced companies do is give people who don’t understand the process but understand the technology equal footing with people who don’t understand the technology but understand the process,” he says. “A lot of companies are disproportionately focused on just addressing their operating model right now.”</p>



<p class="wp-block-paragraph">Instead of focusing on what they’re currently doing, AI-native companies will start with a focus on the customer, he says. This shift in focus isn’t likely to show up immediately on the bottom line, or result in the highest possible number of pilots going into production.</p>



<p class="wp-block-paragraph">“If leaders are in a position where they’re justifying the use of a technology to the board or their CFO, they become a bottleneck when they start demonstrating their value in terms of the number of things they’re doing,” Diasio says.</p>



<p class="wp-block-paragraph">But 150 or 200 use cases deployed into production may feel like progress, like things are happening in the organization. But all these use cases are a waste of time and money if they’re applied to existing processes that don’t move the needle. “We see that happen in organizations today,” he says. “Maybe we need to reinvent the processes.”</p>



<p class="wp-block-paragraph">It’s no secret that companies will need to change in order to adapt to AI. <a href="https://www.deloitte.com/us/en/insights/topics/technology-management/future-of-tech-leadership.html">Deloitte recently surveyed</a> 660 global technology leaders and 81% said their current operating model can deploy and govern AI enterprise-wide, but 75% also said their organization must change its operating model within the next 12 to 18 months to drive greater value.</p>



<p class="wp-block-paragraph">AI ROI is real, says China Widener, Deloitte vice chair and US tech, media, and telecom industry leader. But it’s currently weighted toward efficiency gains, with broader business transformation and revenue upside still developing.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Another Deloitte survey</a> showed that the clearest results from AI were in productivity, with 66% of organizations reporting gains, and cost efficiency, with 40% saying AI reduces costs. “However, revenue impact is still emerging,” says Widener. “Only one in five companies says AI is driving top-line growth today.” But optimism prevails, with 74% expecting it to do so in the future.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[It’s officially the end of the road for the Google Pixel 6 and 6 Pro — but here are 6 clever ways to reinvent your old Android phone]]></title>
<description><![CDATA[Software updates for the Pixel 6 and Pixel 6 Pro are ending later this year, but you've got options for reusing your old handset.]]></description>
<link>https://tsecurity.de/de/3683609/it-nachrichten/its-officially-the-end-of-the-road-for-the-google-pixel-6-and-6-pro-but-here-are-6-clever-ways-to-reinvent-your-old-android-phone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683609/it-nachrichten/its-officially-the-end-of-the-road-for-the-google-pixel-6-and-6-pro-but-here-are-6-clever-ways-to-reinvent-your-old-android-phone/</guid>
<pubDate>Tue, 21 Jul 2026 14:04:07 +0200</pubDate>
<content:encoded><![CDATA[Software updates for the Pixel 6 and Pixel 6 Pro are ending later this year, but you've got options for reusing your old handset.]]></content:encoded>
</item>
<item>
<title><![CDATA[Natural raises $30M to reinvent payments for AI agents — and take on Stripe]]></title>
<description><![CDATA[The one-year-old startup aims to reinvent financial architecture for autonomous AI transactions.]]></description>
<link>https://tsecurity.de/de/3682020/it-nachrichten/natural-raises-30m-to-reinvent-payments-for-ai-agents-and-take-on-stripe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682020/it-nachrichten/natural-raises-30m-to-reinvent-payments-for-ai-agents-and-take-on-stripe/</guid>
<pubDate>Mon, 20 Jul 2026 21:17:25 +0200</pubDate>
<content:encoded><![CDATA[The one-year-old startup aims to reinvent financial architecture for autonomous AI transactions.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI OK in Linux development, says Torvalds]]></title>
<description><![CDATA[Linus Torvalds has a complicated relationship with AI, seeing both its good and bad points. But his latest remarks on the usefulness of AI may have raised a few eyebrows in open-source circles.



Just a few weeks after the Linux founder complained that a “continued flood” of AI-generated vulnera...]]></description>
<link>https://tsecurity.de/de/3676311/ai-nachrichten/ai-ok-in-linux-development-says-torvalds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676311/ai-nachrichten/ai-ok-in-linux-development-says-torvalds/</guid>
<pubDate>Fri, 17 Jul 2026 16:19:36 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Linus Torvalds has a complicated relationship with AI, seeing both its good and bad points. But his latest remarks on the usefulness of AI may have raised a few eyebrows in open-source circles.</p>



<p class="wp-block-paragraph">Just a few weeks after the <a href="https://www.csoonline.com/article/4173224/github-scales-back-bug-bounties-reminds-users-security-is-their-responsibility-too.html#:~:text=And%20Linux%20creator%20Linus%20Torvalds%20recently%20warned%20that%20a%20%E2%80%9Ccontinued%20flood%E2%80%9D%20of%20AI-generated%20vulnerability%20reports%20had%20made%20the%20Linux%20kernel%20security%20mailing%20list%20%E2%80%9Calmost%20entirely%20unmanageable%E2%80%9D%20because%20of%20massive%20duplication%20from%20researchers%20using%20the%20same%20AI%20tools%20to%20find%20identical%20bugs.">Linux founder complained that a “continued flood” of AI-generated vulnerability reports</a> had made the Linux kernel security mailing list “almost entirely unmanageable”, he has come to see the advantages of the technology.</p>



<p class="wp-block-paragraph">“Linux is not one of those anti-AI projects,” Torvalds wrote in an email response to Linux Kernel senior engineer Roman Gushchin, <a href="https://lore.kernel.org/all/CAHk-%3Dwi4zC%2BZe8e%2Bp3tMv8TtG_80KzsZ1syL9anBtmEh5Z40vg@mail.gmail.com/">archived at Kernel.org</a>.</p>



<p class="wp-block-paragraph">“It can also be a somewhat painful tool, both for maintainer workloads and just from a ‘it keeps finding embarrassing bugs’ standpoint,” he said of the use of AI in security scanning. “The solution is to make sure those LLM tools help maintainers instead of just causing them pain.”</p>



<p class="wp-block-paragraph">Developers should be free to choose whether they use AI, he said. “We’re not forcing anybody to use it, but I will very loudly ignore people who try to argue against other people from using it.”</p>



<p class="wp-block-paragraph">Torvalds’ measured support for AI does not come completely out of the blue: Around the same time that he was complaining about AI distorting security maintenance, he also spoke about its usefulness, claiming that it could <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html#:~:text=I%E2%80%99m%20personally%20100%25%20convinced%20that%20AI%20is%20changing%20programming.%E2%80%9D">improve programmer productivity by a factor of 10</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI OK in Linux development, says Torvalds]]></title>
<description><![CDATA[Linus Torvalds has a complicated relationship with AI, seeing both its good and bad points. But his latest remarks on the usefulness of AI may have raised a few eyebrows in open-source circles.



Just a few weeks after the Linux founder complained that a “continued flood” of AI-generated vulnera...]]></description>
<link>https://tsecurity.de/de/3676290/it-nachrichten/ai-ok-in-linux-development-says-torvalds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676290/it-nachrichten/ai-ok-in-linux-development-says-torvalds/</guid>
<pubDate>Fri, 17 Jul 2026 16:18:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Linus Torvalds has a complicated relationship with AI, seeing both its good and bad points. But his latest remarks on the usefulness of AI may have raised a few eyebrows in open-source circles.</p>



<p class="wp-block-paragraph">Just a few weeks after the <a href="https://www.csoonline.com/article/4173224/github-scales-back-bug-bounties-reminds-users-security-is-their-responsibility-too.html#:~:text=And%20Linux%20creator%20Linus%20Torvalds%20recently%20warned%20that%20a%20%E2%80%9Ccontinued%20flood%E2%80%9D%20of%20AI-generated%20vulnerability%20reports%20had%20made%20the%20Linux%20kernel%20security%20mailing%20list%20%E2%80%9Calmost%20entirely%20unmanageable%E2%80%9D%20because%20of%20massive%20duplication%20from%20researchers%20using%20the%20same%20AI%20tools%20to%20find%20identical%20bugs.">Linux founder complained that a “continued flood” of AI-generated vulnerability reports</a> had made the Linux kernel security mailing list “almost entirely unmanageable”, he has come to see the advantages of the technology.</p>



<p class="wp-block-paragraph">“Linux is not one of those anti-AI projects,” Torvalds wrote in an email response to Linux Kernel senior engineer Roman Gushchin, <a href="https://lore.kernel.org/all/CAHk-%3Dwi4zC%2BZe8e%2Bp3tMv8TtG_80KzsZ1syL9anBtmEh5Z40vg@mail.gmail.com/">archived at Kernel.org</a>.</p>



<p class="wp-block-paragraph">“It can also be a somewhat painful tool, both for maintainer workloads and just from a ‘it keeps finding embarrassing bugs’ standpoint,” he said of the use of AI in security scanning. “The solution is to make sure those LLM tools help maintainers instead of just causing them pain.”</p>



<p class="wp-block-paragraph">Developers should be free to choose whether they use AI, he said. “We’re not forcing anybody to use it, but I will very loudly ignore people who try to argue against other people from using it.”</p>



<p class="wp-block-paragraph">Torvalds’ measured support for AI does not come completely out of the blue: Around the same time that he was complaining about AI distorting security maintenance, he also spoke about its usefulness, claiming that it could <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html#:~:text=I%E2%80%99m%20personally%20100%25%20convinced%20that%20AI%20is%20changing%20programming.%E2%80%9D">improve programmer productivity by a factor of 10</a>.</p>



<p class="wp-block-paragraph"><em>This article first appeared on InfoWorld.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake TTF files deliver stealthy malware in global phishing campaign]]></title>
<description><![CDATA[Threat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems.



According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively using heavily ob...]]></description>
<link>https://tsecurity.de/de/3675510/it-security-nachrichten/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675510/it-security-nachrichten/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign/</guid>
<pubDate>Fri, 17 Jul 2026 10:54:29 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Threat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems.</p>



<p class="wp-block-paragraph">According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively using heavily obfuscated JavaScript and a Lua-based loader posing as a TrueType Font (TTF) file to evade security and drop RATs and infostealers.</p>



<p class="wp-block-paragraph">A TTF file is a standard font file used by operating systems and applications to display text.</p>



<p class="wp-block-paragraph">The campaign has been deploying malware families such as <a href="https://www.csoonline.com/article/573813/malware-builder-uses-fresh-tactics-to-hit-victims-with-agent-tesla-rat.html">Agent Tesla</a>, Remcos, <a href="https://www.csoonline.com/article/4064720/xworm-campaign-shows-a-shift-toward-fileless-malware-and-in-memory-evasion-tactics.html">XWorm</a>, and a Snake Keylogger variant known as Best Private LOGGER, since at least late March 2026. “In these attacks, the threat actor impersonates several well-known companies, using the guise of business cooperation to launch phishing attacks,” FortiGuard researchers said in a blog <a href="https://www.fortinet.com/blog/threat-research/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p class="wp-block-paragraph">Talking about how a new attack technique seems to still rely on conventional phishing tricks, <a href="https://www.linkedin.com/in/shane-barney-69026528/" target="_blank" rel="noreferrer noopener">Shane Barney</a>, CISO at Keeper Security, said, “The most sophisticated technical evasion in the world still starts the same way: someone opens an email from what looks like a trusted company and acts on it.”</p>



<p class="wp-block-paragraph">“The obfuscation layers, the Lua loader disguised as a font file, the fileless execution chain – all of it exists to survive detection after that human decision has already been made, and organizations would do well to keep that in their sightline,” he added.</p>



<h2 class="wp-block-heading">Business and payment-themed phishing lures used</h2>



<p class="wp-block-paragraph">According to the researchers, victims receive phishing emails impersonating well-known companies and using business collaboration or payment-related themes to trick recipients into opening compressed archives. These archives contain the obfuscated JScript that establishes persistence before dropping either a legitimate Autolt executable or a LuaJIT interpreter, along with a malicious script packaged within a .ttf extension.</p>



<p class="wp-block-paragraph">The fake font file functions as a Lua-based loader that runs multiple de-obfuscation steps before decrypting and executing shellcode directly in memory.</p>



<p class="wp-block-paragraph">“Security controls cannot treat a file extension as proof of file type or intent,” said <a href="https://www.linkedin.com/in/jason-soroko-19b41920/" target="_blank" rel="noreferrer noopener">Jason Soroko</a>, senior fellow at Sectigo. “Each component (of the campaign) may appear less suspicious when reviewed alone, while the combined sequence leads to in-memory execution of RATs and infostealers.”</p>



<p class="wp-block-paragraph">Some of the new variants, the researchers pointed out, are getting more sophisticated by introducing segmented shellcode encryption, Vectored Exception Handler (VEH)- based runtime decryption, AMSI and ETW bypasses, API unhooking, and other anti-analysis techniques designed to evade endpoint defenses.</p>



<p class="wp-block-paragraph">The final malware payload is delivered using <a href="https://www.csoonline.com/article/4125567/this-stealthy-windows-rat-holds-live-conversations-with-its-operators.html?utm=hybrid_search#:~:text=This%20PowerShell%20loader%20decodes%20and%20executes%20shellcode%20generated%20using%20Donut%2C%20an%20open-source%20framework%20commonly%20used%20to%20convert.%20NET%20assemblies%20into%20position-independent%20shellcode.">Donut</a> shellcode, allowing execution without writing the payload to disk.</p>



<p class="wp-block-paragraph">Protection requires targeted mitigations and routine security hygiene</p>



<p class="wp-block-paragraph">Fortinet’s findings confirm the attackers’ endgame to be stealing credentials and maintaining long-term access. The malware families observed, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER, are all focused on credential theft, surveillance, or remote access.</p>



<p class="wp-block-paragraph">Barney said organizations should resist focusing exclusively on the loader’s technical sophistication and instead strengthen the systems attackers eventually want to compromise.</p>



<p class="wp-block-paragraph">In his opinion, identity and access controls are what it comes down to, as signature-based detection often fails against the loader sophistication of this grade. “Limiting what any given set of credentials can reach, enforcing least privilege, requiring re-authentication for sensitive systems, and monitoring for anomalous session behavior will not stop every phishing email from landing, but they significantly constrain what an attacker can accomplish after one succeeds,” he explained.</p>



<p class="wp-block-paragraph">Soroko, on the other hand, recommends focusing controls on the technical indicators. He urged organizations to restrict Windows Script Host, Autolt, and LauJIT wherever they are not operationally required, monitor for behaviors such as process injection, remote memory allocation, and shellcode execution, and use Fortinet’s published indicators for threat hunting.</p>



<p class="wp-block-paragraph">The indicators of compromise (IOCs) Fortinet shared include the command-and-control (C2) addresses, file hashes, and filenames.</p>



<p class="wp-block-paragraph">Soroko warned against relying solely on hashes or C2 infrastructure because the loader has changed over time. “The stronger approach is to detect the stable behavior across versions, then test controls against the complete chain,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cast yourself in AI video clips using your personal avatar with Gemini Omni in Vids]]></title>
<description><![CDATA[Users now have access to Gemini Omni directly within Google Vids. With Gemini Omni, you can create videos using your personal avatar to scale your presence without the studio time. Use a secure verification process to capture your likeness and then select it as a character in Omni generations wit...]]></description>
<link>https://tsecurity.de/de/3674708/web-tipps/cast-yourself-in-ai-video-clips-using-your-personal-avatar-with-gemini-omni-in-vids/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674708/web-tipps/cast-yourself-in-ai-video-clips-using-your-personal-avatar-with-gemini-omni-in-vids/</guid>
<pubDate>Thu, 16 Jul 2026 23:56:47 +0200</pubDate>
<content:encoded><![CDATA[<p>Users now have access to Gemini Omni directly within <a href="https://docs.google.com/videos/create?usp=blog" target="_blank">Google Vids</a>. With Gemini Omni, you can create videos using your personal avatar to scale your presence without the studio time. Use a secure verification process to capture your likeness and then select it as a character in Omni generations within Vids.</p><p><br></p><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgeIquZqGygFpCGeo8dOUArA4Hb2K8-9KiKRrSrKiNmb8cMT2Th4VemOsnJSHvvE72c_PoPoVZj-89hlds8sfiVa8759ZYz5bEYgjngBMha0u66Y8d4tkwnjlKvG19Ppu1d0u0J0QB2aDMs5w3WJZSgPg8UylT5_30RU1ASLwvKXVmGlt6v9exwLDfq9c/s1920/Cast%20yourself%20in%20AI%20video%20clips%20using%20your%20personal%20avatar%20with%20Gemini%20Omni%20in%20Vids%20-%206736.png"><img border="0" data-original-height="1200" data-original-width="1920" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgeIquZqGygFpCGeo8dOUArA4Hb2K8-9KiKRrSrKiNmb8cMT2Th4VemOsnJSHvvE72c_PoPoVZj-89hlds8sfiVa8759ZYz5bEYgjngBMha0u66Y8d4tkwnjlKvG19Ppu1d0u0J0QB2aDMs5w3WJZSgPg8UylT5_30RU1ASLwvKXVmGlt6v9exwLDfq9c/s1600/Cast%20yourself%20in%20AI%20video%20clips%20using%20your%20personal%20avatar%20with%20Gemini%20Omni%20in%20Vids%20-%206736.png"></a></td></tr><tr><td class="tr-caption">Personal avatar user experience<br><br></td></tr></tbody></table><p></p><ul><li><b>Secure verification:</b> Verify and manage your personal avatar directly within your <a href="https://myaccount.google.com/video-verification" target="_blank">Google Account</a>.</li><li><b>Seamless integration: </b>Easily add your personal avatar from the selector in Vids.</li><li><b>Administrative oversight: </b>Admins can manage or disable this feature through the Admin console.</li></ul><p></p><h4>A note on language and region availability</h4><p>At launch, personal avatars are available in English only for users 18 years and older. They’re not available in the European Economic Area, Switzerland, or the United Kingdom. Learn more about personal avatar <a href="https://support.google.com/accounts/answer/17100665?visit_id=639190374851512632-1124942400&amp;p=msa_privacy&amp;rd=1#privacy" target="_blank">privacy settings</a>.</p><h3>Getting started</h3><p></p><ul><li><b>Admins: </b>This feature will be ON by default and can be disabled or enabled at the domain level. Visit the Help Center to <a href="https://knowledge.workspace.google.com/admin/users/access/turn-vids-on-or-off-for-users#manage_personal_avatars_in_vids" target="_blank">learn more about managing personal avatars in Vids</a>.</li><li><b>End users: </b>Visit the Help Center to <a href="https://support.google.com/docs/answer/16970930" target="_blank">learn more about using personal avatars in Vids</a>.</li></ul><p></p><h3>Rollout pace</h3><p></p><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release domains:</a> Gradual rollout (up to 15 days for feature visibility) starting on July 16, 2026 </li><li><a href="https://support.google.com/a/answer/172177" target="_blank">Scheduled Release domains:</a> Gradual rollout (up to 15 days for feature visibility) starting on August 5, 2026 </li></ul><p></p><h3>Availability</h3><p></p><ul><li><b>Business: </b>Business Starter, Standard, and Plus</li><li><b>Enterprise: </b>Enterprise Starter, Standard, and Plus</li><li><b>Education: </b>Education Plus</li><li><b>Consumer: </b>Google AI Pro and Ultra</li><li><b>Other Editions:</b> Enterprise Essentials and Enterprise Essentials Plus; Nonprofits</li><li><b>Education Add-ons: </b>Google AI Pro for Education; Teaching and Learning</li><li><b>Other Add-ons: </b>AI Expanded Access*</li></ul><p></p><p><i>*Users with AI Expanded Access add-on licenses have <a href="https://support.google.com/a/answer/14700766" target="_blank">higher limits</a> on usage of Omni in Vids.</i></p><h3>Resources</h3><p></p><ul><li>Google Docs Editors Help: <a href="https://support.google.com/docs/answer/16970930" target="_blank">Create, use &amp; manage your personal avatar with Gemini in Google Vids</a></li><li>Google Docs Editors Help: <a href="https://support.google.com/docs/answer/16143507" target="_blank">Use Omni in Google Vids</a></li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Artificial Intelligence]]></title>
<description><![CDATA[Latest from todaynewsDeepMind CEO again pushes for a frontier AI standards bodyDemis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.By Evan SchumanJul 15, 20268 minsArtificial IntelligenceGovernmentLaws and Regulation...]]></description>
<link>https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</guid>
<pubDate>Wed, 15 Jul 2026 23:02:40 +0200</pubDate>
<content:encoded><![CDATA[<div><section class="latest-content"><div class="container"><header class="latest-content__header"><h2 class="latest-content__title sr-only"><span>Latest from today</span></h2></header><div class="grid latest-content__content"><div class="col-12 col-7@md col-8@lg"><div class="latest-content__content-featured"><a class="card card--xxl " href="https://www.computerworld.com/article/4197511/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body-2.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">news</span></div><div class="card__image"><div class="insider-image"><div class="image"><img width="400px" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197511-0-18848000-1784149211-shutterstock_2540223947.jpg?quality=50&amp;strip=all&amp;w=1046" data-id="idg_render_hero_index_one_card_image" sizes="
            (min-resolution: 3dppx) and (max-width: 600px) 900px,
            (min-resolution: 3dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 2dppx) and (max-width: 600px) 900px,
            (min-resolution: 2dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 1dppx) and (max-width: 600px) 900px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1300px" alt="Image" loading="eager"></div></div></div><h3 class="card__title">DeepMind CEO again pushes for a frontier AI standards body</h3><p class="card__description">Demis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.</p><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T20:59:29+00:00">Jul 15, 2026</span></span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a>
		</div><div class="grid grid--cols-7@md grid--cols-8@lg latest-content__content-main"><div class="col-12 col-7@md col-4@lg latest-content__card-main"><a class="card " href="https://www.computerworld.com/article/4197437/apples-openai-lawsuit-the-lunacy-of-trying-to-limit-what-ex-employees-can-tell-future-employers.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197437-0-98299000-1784131210-thinkstockphotos-493608259-100632547-orig.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers</h3><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:59:35+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a></div><div class="col-12 col-7@md col-4@lg latest-content__card-main"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/4197338/what-problems-would-an-ai-speaker-from-openai-actually-solve.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197338-0-98391100-1784130807-Apple-HomePod-mini-color-lineup.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">What problems would an AI speaker from OpenAI actually solve?</h3><div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:52:45+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Vendors and Providers</span></span></div></a></div></div></div><div class="col-12 col-5@md col-4@lg latest-content__content-secondary"><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4192438/how-to-unionize-your-tech-workplace.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">feature</span></div><h3 class="card__title">How to unionize your tech workplace</h3><div class="card__info"><span>By Robert Mitchell</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T11:00:00+00:00">Jul 15, 2026</span></span><span>18 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Careers</span></span><span class="card__tag"><span class="tag">IT Jobs</span></span><span class="card__tag"><span class="tag">Technology Industry</span></span></div></a>
		</div><div class="latest-content__card-secondary"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/1613762/android-widgets.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">tip</span></div><h3 class="card__title">5 wild ways to make Android widgets more useful</h3><div class="card__info"><span>By JR Raphael</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T09:45:00+00:00">Jul 15, 2026</span></span><span>12 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Mobile Apps</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Microsoft is forcing an enterprise transition to passkeys</h3><div class="card__info"><span>By Taryn Plumb</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T02:04:06+00:00">Jul 14, 2026</span></span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Access Control</span></span><span class="card__tag"><span class="tag">Authentication</span></span><span class="card__tag"><span class="tag">Identity and Access Management</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196704/siri-ai-steals-the-show-as-the-ios-27-public-beta-lands.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Siri AI steals the show as the iOS 27 public beta lands</h3><div class="card__info"><span>By Jonny Evans</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T15:47:35+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Operating Systems</span></span><span class="card__tag"><span class="tag">iOS</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196309/with-its-latest-layoffs-microsoft-goes-all-in-on-ai.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">opinion</span></div><h3 class="card__title">With its latest layoffs, Microsoft goes all in on AI</h3><div class="card__info"><span>By Preston Gralla</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T11:00:00+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">IT Strategy</span></span><span class="card__tag"><span class="tag">Microsoft</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196652/forg365-industrializes-microsoft-365-phishing-with-ai-generated-lures.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Forg365 industrializes Microsoft 365 phishing with AI-generated lures</h3><div class="card__info"><span>By Prasanth Aby Thomas</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T09:51:16+00:00">Jul 14, 2026</span></span><span>4 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span><span class="card__tag"><span class="tag">Office Suites</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></a>
		</div></div></div></div></section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><div class="content-listing-articles"><div class="container"><h2 class="content-listing-articles__title">Articles</h2><div class="content-listing-articles__container content-listing-articles__container--collapsed" data-collapse-articles="6" data-content-listing-articles><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’</h3><p class="card__description">Analysts and consultants applaud the move as potentially delivering the development consistency that the current offerings lack, but some worry that treating the company as neutral is a mistake.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Evan Schuman</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Nonprofits</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196262/ai-is-killing-low-cost-smartphones.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">AI is killing low cost smartphones</h3><p class="card__description">Data from Omdia and Counterpoint shows that while Apple and Samsung thrive, the rest of the industry takes a dive</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Mobile Phones</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196220/meta-pulls-instagram-ai-feature-amid-privacy-concerns.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta pulls Instagram AI feature amid privacy concerns</h3><p class="card__description">By specifying a public account, users could allow the AI ​​model to use the person’s images as a reference without the account holder being notified.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Viktor Eriksson</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>1 min</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Instagram</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195176/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">feature</span></div><h3 class="card__title">Q&amp;A: How Google plans to reinvent the spreadsheet with AI</h3><p class="card__description">Soon, Google wants to see AI doing the spreadsheet busywork, says Eric Birnbaum, director of product management for Google Sheets.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Matthew Finnegan</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>10 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Google Sheets</span></span><span class="card__tag"><span class="tag">Google Workspace</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">brandpost</span><span class="card__sponsor-text">Sponsored by Tether</span></div><h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3><p class="card__description"></p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By tether</span></div> <div class="card__info card__info--light"><span>Jul 9, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI</h3><p class="card__description">Apple accuses OpenAI and former Apple Vice President Tang Tan of extensive coordinated data theft and asks whether OpenAI’s hardware plans are based around exfiltrated Apple info.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">opinion</span></div><h3 class="card__title">Apple is prepping for life after the AI gold rush</h3><p class="card__description">The company's interest in compression of AI models is the right approach.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195678/microsoft-exchange-server-on-prem-gets-a-little-harder-to-use.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Microsoft Exchange Server on prem gets a little harder to use</h3><p class="card__description">The lightweight web client is going away, placing more demands on systems still clinging to Microsoft’s on-prem email system.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Email Clients</span></span><span class="card__tag"><span class="tag">Microsoft Exchange</span></span><span class="card__tag"><span class="tag">Microsoft Outlook</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195636/mistral-joins-rush-to-build-physical-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Mistral joins rush to build physical AI</h3><p class="card__description">Its Robostral Navigate AI model needs input from just one color camera, doing without Lidar, depth sensors, or multiple viewpoints.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Robotics</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195628/apple-will-buy-more-us-made-components-from-broadcom.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Apple will buy more US-made components from Broadcom</h3><p class="card__description">Chips and thin-film bulk acoustic resonator (FBAR) filters are on the menu.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Networking</span></span><span class="card__tag"><span class="tag">Wi-Fi</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195528/meta-launches-low-cost-muse-spark-1-1-as-enterprise-ai-spending-comes-under-scrutiny-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny</h3><p class="card__description">Meta says the model delivers competitive performance against OpenAI, Anthropic, and Google offerings while costing a fraction as much to run.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Anirban Ghoshal</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/1614899/android-contacts-management-ultimate-guide.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">how-to</span></div><h3 class="card__title">The ultimate guide to Android contacts management</h3><p class="card__description">Your Android phone's contacts are much more than just a glorified Rolodex. Ready for an unexpected productivity upgrade? </p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By JR Raphael</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>16 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Google</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195494/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout</h3><p class="card__description">The enterprise AI agent combines ChatGPT, Codex, and GPT-5.6 to automate workplace tasks as OpenAI broadens rollout of its latest frontier models.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Gyana Swain</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div></div><div class="grid content-listing-articles__button-wrapper">
			<div class="col-6 col-4@md col-start-5@md"><div class="content-listing-articles__button-show">
					<button class="button button--tertiary" type="button" data-toggle="expand">
						<span>Show more</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-down"></use>
							</svg>
						</span>
					</button>
				</div>
				<div class="content-listing-articles__button-show content-listing-articles__button-show--hide">
					<button class="button button--tertiary" type="button" data-toggle="collapse">
						<span>Show less</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-up"></use>
							</svg>
						</span>
					</button>
				</div></div><div class="col-6 col-4@md content-listing-articles__button-view-all">
						<a class="button" href="https://www.computerworld.com/artificial-intelligence/feed/page/2/" target="_blank"> View all </a></div></div></div></div><section class="suggested-content-upcoming-events"><div class="container">
				<h2 class="suggested-content-upcoming-events__title">Upcoming Events</h2><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cio-100-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Sep/24</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/03/4141846-0-37933000-1772809522-CIO-Summit-2025_17.jpg?quality=50&amp;strip=all&amp;w=1045" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cio-100-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CIO 100 Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>24 Sep 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span></div></div>
			</div>
		</a><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cso-awards-conference-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Nov/26</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4141741-0-97812100-1780312469-60CB82BE-5D6E-40E0-8E5E-0151C8C46E7F.jpg?quality=50&amp;strip=all&amp;w=929" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cso-awards-conference-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CSO Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>26 Nov 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span></div></div>
			</div>
		</a></div><div class="suggested-content-upcoming-events__button-container container">
						<a class="button" href="https://www.computerworld.com/events/"> View all events</a>
					</div>
				
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-resources">
				<div class="container">
				<h2 class="related-content-resources__title">Resources</h2><div class="grid related-content-resources__content"><div class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-resources__main-content">
			<div class="col-12 col-7@md col-6@lg">
				<a class="card card--xxl" href="https://us.resources.computerworld.com/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
					<div class="card__header">
						<span class="card__content-type">whitepaper</span>
					</div>
					<h3 class="card__title">Accelerate your cloud migration with Atlassian FastShift</h3>
					<p class="card__description"></p><p>Turn an Atlassian cloud migration into a faster, more predictable transformation. In this session, you’ll walk through the FastShift playbook.</p>
<p>The post <a rel="nofollow" href="https://com.wp.idg.zone/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6/">Accelerate your cloud migration with Atlassian FastShift</a> appeared first on <a rel="nofollow" href="https://com.wp.idg.zone/">Whitepaper Repository –</a>.</p>

					<div class="card__info">
						<span>
						By 
						Atlassian
						</span>
					</div>
					<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
			</div>
			<div class="col-2 related-content-resources__featured-image-wrapper">
				<img width="400px" loading="lazy" class="related-content-resources__image-featured" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040704.83.png" alt="Image">
			</div>
		</div><div class="col-12 col-5@md col-4@lg col-start-9@lg related-content-resources__cards"><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/warum-sich-teams-fur-cloud-entscheiden-9?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Warum sich Teams für Cloud entscheiden</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040716.4772.png" alt="Image">
				</div>
			</div><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/pourquoi-les-equipes-optent-pour-la-solution-cloud-3?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Pourquoi les équipes optent pour la solution cloud</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040728.9116.png" alt="Image">
				</div>
			</div></div>
		</div><div class="related-content-resources__button-container">
			<a class="button" target="_blank" href="https://us.resources.computerworld.com/"> View all </a>
		</div></div>
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-podcasts"><div class="container"><h2 class="related-content-podcasts__title">Podcasts</h2><div class="grid related-content-podcasts__content"><a class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-podcasts__main-content" href="https://www.computerworld.com/podcasts/2-minute-tech-briefing/" aria-label="Go to content"><div class="col-12 col-7@md col-2@lg related-content-podcasts__image">
			<div class="image image--aspect-ratio-1-1">
				<img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2025/11/100065453-0-01782600-1762961273-2-min-tech-briefing-logo-16x9-4.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Image">
			</div>
		</div><div class="col-12 col-7@md col-6@lg"><div class="card card--xl"><div class="card__header"><span class="card__content-type"> podcasts</span></div><h3 class="card__title">2-Minute Tech Briefing</h3><p class="card__description">Catch up on the latest enterprise IT news in a fast-paced video briefing with host Arnold Davick. Listen to the show on Computerworld, YouTube, Apple and Spotify.</p><div class="card__info card__info--light"><span>81  episodes</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Emerging Technology</span></span></div></div></div></a><ul class="col-12 col-5@md col-4@lg col-start-9@lg related-content-podcasts__cards"><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 81</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 80</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li></ul></div></div></section><section class="related-content-video"><div class="container"><h2 class="related-content-video__title">Video on demand</h2><div class="grid related-content-video__main">        <div class="col-12 col-4@lg related-content-video__main-card card card--xl">
            <div class="card__header"><span class="card__content-type">video</span></div>            
            <a class="card card--xl" href="https://www.computerworld.com/video/4196734/why-ai-agents-fail-when-enterprises-dont-define-the-job.html" aria-label="Go to content">
                <h3 class="card__title">Why AI agents fail when enterprises don’t define the job</h3>            </a>
                            <p class="card__description mt-3">Enterprises are investing heavily in AI agents, but many projects fail when companies skip clear goals, guardrails, governance and success metrics.</p>
            
                         <div class="card__info card__info--light"><span>Jul 14, 2026 </span><span>33 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div>        </div>
                <div class="col-12 col-8@lg related-content-video__video">
                            <div class="youtube-video">
                    &gt;
					
				</div>                </div>
                    </div>
        </div><div class="related-content-video__cards-container">
                        <div class="related-content-video__cards-wrap">
                            <ul class="grid related-content-video__cards">        <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4193952/why-enterprise-ai-projects-stall-before-delivering-real-value.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4193952-0-52301800-1783446508-youtube-thumbnail-gu6x40jhZ1s_3cbf50.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">Why enterprise AI projects stall before delivering real value</h3>
                                         <div class="card__info card__info--light"><span>Jul 7, 2026 </span><span>29 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">ROI and Metrics</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4191262/how-ai-is-breaking-job-interviews-skills-testing-and-evaluation.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4191262-0-24248500-1782847008-youtube-thumbnail-lVEejCXC4lU_b223c5.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is breaking job interviews, skills testing and evaluation</h3>
                                         <div class="card__info card__info--light"><span>Jun 30, 2026 </span><span>32 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Hiring</span></span><span class="card__tag"><span class="tag">IT Skills and Training</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4188534/how-ai-is-reshaping-cybersecurity.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4188534-0-45176600-1782243369-youtube-thumbnail-5DLoQMU0nZc_de9df9.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is reshaping cybersecurity</h3>
                                         <div class="card__info card__info--light"><span>Jun 23, 2026 </span><span>44 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span><span class="card__tag"><span class="tag">Cybercrime</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div>                </div>
            </a>
        </li>
        </ul></div></div><div class="related-content-video__button-container"><a class="button" target="_self" href="https://www.computerworld.com/videos/">See all videos</a></div></section></div><section class="suggested-content-various"><div class="container"><div class="grid suggested-content-various__content"><div class="col-12 col-3@lg">
			<h2 class="suggested-content-various__title">Show me more</h2><div class="suggested-content-various__filters"><span class="suggested-content-various__filter"><button class="chip chip--filter chip--active" type="button" data-filter-key="latest">Latest</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="article">Articles</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="podcast">Podcasts</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="video">Videos</button></span></div>
		</div><div class="col-12 col-9@lg suggested-content-various__items-wrap"><div class="grid grid--cols-9@lg suggested-content-various__items"><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4195055/apple-finally-calls-time-on-15-year-old-device-support.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">opinion</span> </div> <h3 class="card__title">Apple finally calls time on 15-year-old device support</h3> <div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T16:15:14+00:00">Jul 9, 2026</span><span>4 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Smartphones</span></span><span class="card__tag"><span class="tag">iPhone</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4195055-0-47500100-1783613766-iPhone4s_3up_Photo_Siri_Sprgbd_PRINT.jpg?quality=50&amp;strip=all&amp;w=219" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">brandpost</span> <span class="card__sponsor-text">Sponsored by Tether</span></div> <h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3> <div class="card__info"><span>By tether</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T11:11:53+00:00">9 Jul 2026</span><span>6 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194931-0-76347600-1783595551-QVAC-Paid-Ad-1-_-1200-x-800.png?w=375" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194914/spacexai-launches-grok-4-5-touts-lower-coding-task-costs-than-ai-rivals-2.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">news</span> </div> <h3 class="card__title">SpaceXAI launches Grok 4.5, touts lower coding-task costs than AI rivals</h3> <div class="card__info"><span>By Prasanth Aby Thomas</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T10:26:11+00:00">Jul 9, 2026</span><span>5 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194914-0-24417700-1783592810-AI-vibe-coding-one-hand-is-robot-one-hand-is-human.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T15:04:16+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-46106000-1779462321-youtube-thumbnail-5PkKYThsKy8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T14:53:18+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-06017100-1779461653-youtube-thumbnail-XH7vduM7uz8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4172579/ai-triage-gains-model-reviews-ask-jeeves-shutdown-ep-82.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">AI Triage Gains, Model Reviews, Ask Jeeves Shutdown | Ep. 82</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-18T19:31:15+00:00">May 18, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-62824900-1779132751-youtube-thumbnail-P3R6blMndrU.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4185559/why-ai-agents-could-create-a-new-control-and-security-crisis.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Why AI agents could create a new control and security crisis</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-16T11:47:15+00:00">Jun 16, 2026</span><span>28 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4185559-0-48713800-1781610470-youtube-thumbnail-uPpd9EJ4iNI_55eb26.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4182978/does-quality-suffer-when-ai-generates-code.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Does quality suffer when AI generates code?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-09T14:32:51+00:00">Jun 9, 2026</span><span>35 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Code Security</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4182978-0-61230000-1781015610-youtube-thumbnail-1hAfDQkuyhs_faa994.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4180043/what-happens-when-ai-starts-selling-to-ai.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">What happens when AI starts selling to AI?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-02T15:00:42+00:00">Jun 2, 2026</span><span>38 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Procurement Software</span></span><span class="card__tag"><span class="tag">Salesforce Automation </span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4180043-0-78180900-1780412479-youtube-thumbnail-jPv-TAenlto_c79318.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div></div></div></div></div></section>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: How Google plans to reinvent the spreadsheet with AI]]></title>
<description><![CDATA[Nearly five decades after the launch of VisiCalc, AI is reshaping one of the world’s most familiar productivity tools — the humble spreadsheet.



While a lot of knowledge workers interact with spreadsheets on a regular basis, many lack the skills and confidence to access more advanced functions....]]></description>
<link>https://tsecurity.de/de/3665017/ai-nachrichten/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665017/ai-nachrichten/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai/</guid>
<pubDate>Mon, 13 Jul 2026 13:04:15 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nearly five decades after the launch of VisiCalc, AI is reshaping one of the world’s most familiar productivity tools — the humble spreadsheet.</p>



<p>While a lot of knowledge workers <a href="https://www.acuitytraining.co.uk/news-tips/new-excel-facts-statistics/" target="_blank" rel="noreferrer noopener">interact with spreadsheets on a regular basis</a>, many lack the skills and confidence to access more advanced functions.</p>



<p>“For a very long time, spreadsheets forced you to learn spreadsheet syntax and spreadsheet ways of working,” said Eric Birnbaum, director of product management for <a href="https://www.computerworld.com/article/1657150/how-to-use-google-sheets.html" data-type="link" data-id="https://www.computerworld.com/article/1657150/how-to-use-google-sheets.html">Google Sheets</a>. “But think about how many people need to use spreadsheets at work and don’t have the skill set to create the kinds of spreadsheets that can be really helpful for them.”</p>



<p>The addition of artificial intelligence can help handle that issue, he said, making the software more accessible to a wide range of office workers. “AI is unlocking the power of spreadsheets, taking on a lot of the difficult work that’s required to use them. That can be incredibly empowering for users,” said Birnbaum.</p>



<p>Google has steadily <a href="https://www.computerworld.com/article/4131504/gemini-supercharge-google-sheets-spreadsheets.html" data-type="link" data-id="https://www.computerworld.com/article/4131504/gemini-supercharge-google-sheets-spreadsheets.html">expanded generative AI (genAI) capabilities in Sheets</a> since launching Duet AI — now Gemini — for Workspace in 2023.</p>



<p>Gemini in Sheets is available at no extra cost to Google Workspace subscribers, though a paid <a href="https://knowledge.workspace.google.com/admin/generative-ai/workspace-with-gemini/ai-expanded-access" target="_blank" rel="noreferrer noopener">AI Expanded Access add-on </a>– costing $30 per user each month – is required to remove certain usage limits.</p>



<p>Features that have rolled out in recent months include the ability for a Gemini agent in Sheets to carry out <a href="https://workspaceupdates.googleblog.com/2025/10/expanded-editing-capabilities-gemini-in-google-sheets.html" target="_blank" rel="noreferrer noopener">multi-step actions</a> such as formatting, analysis and data entry, and, more recently, the ability to <a href="https://workspaceupdates.googleblog.com/2026/04/build-and-edit-complex-spreadsheets-with-Gemini-in-Google-Sheets.html" target="_blank" rel="noreferrer noopener">create entire spreadsheets</a> from a single prompt. A <a href="https://workspaceupdates.googleblog.com/2026/04/effortlessly-automate-data-entry-in-Google-Sheets-using-Fill-with-Gemini.html" target="_blank" rel="noreferrer noopener">Fill with Gemini feature </a>builds on the<a href="https://workspaceupdates.googleblog.com/2025/06/generate-data-with-gemini-in-google-sheets.html" target="_blank" rel="noreferrer noopener"> existing AI function,</a> enabling users to automatically populate selected cells by detecting intent from information within a spreadsheet as well as from the web.</p>



<p>Another feature, Sheets Canvas (currently available in alpha), lets users generate interactive apps that update in real-time based on changes to spreadsheet data. This could be a kanban board for a sales pipeline, for instance, or an analytics dashboard that uses Sheets as its back-end data source. </p>



<p>Google claims users already see a range of benefits from Gemini in Sheets. According to an August 2025 survey of 200 Sheets users conducted by the company, the majority of knowledge workers (89%) said AI features in Sheets save them at least an hour a week, and 88% believe AI features have made them more confident in their data analysis skills. </p>



<p>The most popular AI use cases include creating spreadsheets and charts, analyzing data, and fixing broken formulas. How widely these features are actually used is unclear; Google declined to provide weekly usage statistics for Gemini in Sheets.</p>



<p>As the company embeds Gemini deeper into Sheets, questions remain about just how much businesses can trust AI tools to handle important business data, as well as what increased automation means for those who spend much of their day wrangling data. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="480" height="480" sizes="auto, (max-width: 480px) 100vw, 480px"&gt;<figcaption class="wp-element-caption"><p>Eric Birnbaum, director of product management for Google Sheets.</p></figcaption></figure><p class="imageCredit">Google</p></div>



<p><em>Computerworld</em> recently talked with Birnbaum about the potential benefits and challenges of the latest evolution of spreadsheet software. This interview has been condensed and edited for clarity.</p>



<p><strong>As businesses become more focused on seeing value from AI investments, what measurable benefits are customers seeing from Gemini in Sheets – for example, time saved or other forms of return on investment? </strong>“Spreadsheets remain one of the universal languages for businesses, and we don’t anticipate that’s going to change anytime soon. But by bringing AI into the product where people work, we think it can significantly reduce the technical tax of data: the time spent understanding it, sourcing it, analyzing it, visualizing it.</p>



<p>“Historically, data professionals spent — let’s estimate it at 80% of their time — on the mechanical groundwork, data cleaning, crafting formulas, formatting, troubleshooting, and maybe only 20% of their time on actual strategic decision-making.</p>



<p>“We think that by offloading the manual, time-consuming, error-prone data work to Gemini, we can flip that ratio a bit, so humans can focus on the things that really matter: the high-value questions to ask and the judgment calls and decisions that get made from them. We’re starting to see evidence of that in our own user base and customer base.</p>



<p>“The second point to make is that AI can democratize data analysis to some extent, and make it available to many more users. For so many years, the spreadsheet was a gatekeeper; if you couldn’t speak the rigid language of spreadsheet formulas, you couldn’t extract the value from data. But by introducing these natural language interfaces, AI is separating the analytical capability from the technical literacy. </p>



<p>“If you can ask the right questions, or describe what you want in plain language, Gemini and Sheets can help you achieve your goals in a spreadsheet, even if you have minimal spreadsheet skills yourself.</p>



<p>“What we’ve seen so far from users and customers is that it’s incredibly empowering for people who might have been scared off by data analysis or dreaded opening spreadsheets in the past. You don’t need to go and wait for a data analyst to help you; you can go and do this work yourself in a spreadsheet.”</p>



<p><strong>The flip side is, how confident can businesses be if more junior employees can take on higher-level analysis tasks by relying on AI? Given the propensity for AI models to hallucinate, to what degree can businesses trust that these tools won’t introduce errors into important business data? </strong>“It’s something we spent a ton of time thinking about. We’ve gone to great lengths to build these AI tools to collaborate with you, to show their work, explain what they did, and make sure that you can take over where they leave off.</p>



<p>“Our Sheets agent, for example, lays out a really explicit, transparent plan for you to review and approve before any data manipulation happens. It’s designed to do that in plain natural language in a way that the average user could understand, and then it gives you back that final summary, so you know exactly what it did and where it did it.</p>



<p>“The other thing is that the model is great at explaining things. If you inherit a spreadsheet that has some complex formula that you don’t understand, for example, the model does an amazing job of explaining how it works and what it’s doing.</p>



<p>“In many ways AI is not only making these features more accessible, but helping users feel more confident in the output. Human error is an inherent risk in manual data management, with or without AI. One misplaced comma or broken cell reference can completely corrupt an entire financial model, and it can be completely undetected. </p>



<p>“Our approach with AI in Sheets is to create this deliberate verification loop. You now have another spreadsheet expert working along with you, reducing the likelihood of these mistakes.”</p>



<p><strong>Even if humans produce errors too, does it ultimately come down to accountability when AI is involved? </strong>“Our point of view here is that AI should be partnering with the knowledge worker who’s doing the work here. And everything that we’ve built is designed to be that partner. You might be able to offload tasks to the model, but we’re citing sources, we’re providing plans and explanations. We’re ultimately relying on the user to do that final verification.</p>



<p>“We spend a humongous amount of time focused on quality. We know that for AI to be useful in spreadsheets, it has to be reliable. When we launched Sheets Gemini Agent, for example, we were really proud that we set a state-of-the-art benchmark on the full SpreadsheetBench data set, which at the time exceeded competitors and near-human expert ability. </p>



<p>“But we know quality is never ‘good enough’ or done. We’re constantly working to improve quality for our users and customers, and for the use cases where they’re relying on AI most.”</p>



<p><strong>What potential do you see for more agentic functionality in Gemini Sheets — for example, bringing in data from other sources, creating recurring reports, or taking more actions independently? “</strong>We’re listening closely to customers and users and building what they’re telling us they need. The agent is already capable of doing very complex multistep workflows, and we see users discover that the agent is extremely capable of doing end-to-end spreadsheet tasks. In terms of connectors, in an alpha we have connections available to HubSpot, Salesforce, and Mailchimp. We hope to expand that over time.</p>



<p>“There’s no path to have AI replacing analysts. I think AI is giving analysts more time back to actually do the more valuable parts of their job. Analysts that I work with are way more productive and impactful than they ever were before, because they can push that uninteresting spreadsheet grunt work off to the model, freeing up time for more interesting and impactful work.</p>



<p>“A great example: the visualizations I’m getting back from analysts nowadays are canvases instead of static charts that I can explore myself. It’s way more informative and useful than what I was accustomed to before.”</p>



<p><strong>Looking ahead, do you expect a larger share of spreadsheet work to be carried out by agents, with humans setting goals and reviewing results? What will be the biggest change in how people use spreadsheets with AI? </strong>“The tasks are likely to stay similar and the use cases for spreadsheets are likely to continue to be relevant. The biggest change will be the ability to push the uninteresting spreadsheet grunt work off to a model and free up time for the user to do things that are more impactful, more interesting, more meaningful to the business.</p>



<p>‘Spreadsheets have historically been these like static containers where data goes to rest. I think AI can turn spreadsheets into these dynamic, localized software applications. And I do actually think this sort of changes the game for how people might use spreadsheets moving forward. </p>



<p>“It’s not just a passive grid full of numbers; spreadsheets are evolving to become these live, long-lived, collaborative applications. Employees can build these on the fly, like a basic CRM or supply chain dashboard in seconds. This is an area of investment for us moving forward, and we’re really excited to see how this evolves.”</p>



<p><strong>AI assistants and agents, such as ChatGPT or Claude, might be able to analyze spreadsheet files and business data without users working inside a spreadsheet application. What do you think will keep Sheets central to the workflow, rather than simply making it one part of a wider AI-driven process?</strong>“We’re in constant touch with customers and users; it’s clear work is still happening in spreadsheets. I think spreadsheets remain incredibly popular tools. If we can bring the AI capabilities users need directly into the product where they already are, we’ll transform the way they work.  </p>



<p>“I think we can be the front-end for some of this great AI innovation and the products that users are accustomed to today. Everything we build is guided by user feedback: users are telling us right now they want AI to help them do their everyday or more complex tasks, and they’re starting in Sheets today.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT isn’t holding AI back, your business processes are]]></title>
<description><![CDATA[Most CIOs and other IT leaders are confident in their teams’ ability to meet the coming AI challenges, but many believe business operating models and processes need an overhaul.



More than 80% of senior IT executives surveyed for the 2026 Global Leadership Technology Study from Deloitte are con...]]></description>
<link>https://tsecurity.de/de/3656620/it-nachrichten/it-isnt-holding-ai-back-your-business-processes-are/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656620/it-nachrichten/it-isnt-holding-ai-back-your-business-processes-are/</guid>
<pubDate>Thu, 09 Jul 2026 12:17:36 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Most CIOs and other IT leaders are confident in their teams’ ability to meet the coming AI challenges, but many believe business operating models and processes need an overhaul.</p>



<p>More than 80% of senior IT executives surveyed for the 2026 <a href="https://www.deloitte.com/us/en/programs/chief-information-officer/articles/global-technology-leadership-study.html" rel="nofollow">Global Leadership Technology Study</a> from Deloitte are confident in their organizations’ ability to deploy and govern AI capabilities at scale. However, 75% think their operating models and processes must change in the next 12 to 18 months to drive greater value.</p>



<p>The survey results don’t signal an overconfidence from IT leaders in their teams’ ability to roll out AI, and they don’t seem to suggest a major AI choke point within the IT organization, says <a href="https://www.deloitte.com/us/en/about/people/profiles.anjalishaikh+80ed8985.html" rel="nofollow">Anjali Shaikh</a>, MD of Deloitte Consulting and leader of the Deloitte global CIO and US tech executive programs.</p>



<p>They do, however, point to a need for major changes to operating models and processes across the organization, not just within IT, to achieve better AI results, she says. And while CIOs can’t control how business workflows are designed, they have a role to play in pushing for processes that better make use of AI tools, she adds.</p>



<p>“What we’re hearing now is that AI isn’t just exposing those technology limitations, but enterprise design limitations,” Shaikh says. “What’s new is that technology is no longer the bottleneck, it’s the operating model and the ways of working.”</p>



<p>Business workflows that need to change are the manual processes that aren’t friendly to AI integration, like using spreadsheets for some accounting, or manual data entry.</p>



<h2 class="wp-block-heading">CIO as advocate</h2>



<p>CIOs can use their expertise to champion the redesign of enterprise workflows so they better align with AI tools like agents, Shaikh adds, creating opportunities for CIOs in a changing landscape.</p>



<p> “The AI era is starting to demand a new type of leader,” Shaikh says. “They’re going to have to guide the organization through this change, build AI-related teams, and figure out the skill set required for not only their team, but the overall business.”</p>



<p><a href="https://www.cio.com/article/4169668/ai-saddles-cios-with-new-make-or-break-expectations.html?utm=hybrid_search">Another conclusion</a> from the Deloitte report is that CIOs and other IT leaders are experiencing a make-or-break moment as they face major new expectations in their roles, including the ability to <a href="https://www.cio.com/article/3974090/state-of-the-cio-2025-cios-set-the-ai-agenda.html">lead change and build AI-ready teams</a>.</p>



<p>Leadership is important, Shaikh says, in that the organizations with the most successful AI deployments tend to be those with C-suite support for operating model and process change.</p>



<p>“It’s an investment and a commitment from the top down —  the board, CEO, and C-suite have made a commitment to saying we’re going to invest not only time, but budget, resources, and talent into helping us fundamentally shift the way we work,” she says. “When you get that alignment and commitment from the top, that sends a signal to everyone in the organization.”</p>



<p>Several IT leaders agree that several operating model and process changes are needed at many organizations.</p>



<h2 class="wp-block-heading">Focus on the right thing</h2>



<p>Many organizations are embracing AI by buying ChatGPT licenses and hosting lunch-and-learn sessions on prompt engineering, but they’re solving the wrong problem, says <a href="https://www.linkedin.com/in/ppschreuder/" rel="nofollow">Peter-Paul Schreuder</a>, chief cloud officer and VP of support at enterprise asset management software vendor Ultimo.</p>



<p>“Teaching people to use ChatGPT takes about an hour,” he says. “Teaching an organization to fundamentally rethink how work gets done takes four to five months of hard, unglamorous process work, but delivers exponentially more value.”</p>



<p>A major problem is that most organizations don’t understand their own workflows well enough to determine where AI could add value, he adds.</p>



<p>“They don’t know where the information gets stuck,” Schreuder says. “Which tasks consume disproportionate time? Where do we repeatedly reinvent the wheel because knowledge lives in someone’s head? Until you can answer those questions with specificity, no amount of AI training will matter.”</p>



<p>Getting the most out of AI takes a huge reset in the way businesses think how they complete their work, he adds, and if AI initiatives lack deep involvement from business operations leaders, they’re doomed to fail.</p>



<p>“If you can’t diagram how your work flows from intake to completion, you’re not ready for AI augmentation,” Schreuder adds. “If your list includes ‘summarize documents’ or ‘draft emails,’ you’re thinking about AI as a fancy word processor. Transformative applications are process specific.”</p>



<p>So some companies are clear about how they link new AI tools with workflow redesign. When financial services firm IMA Financial Group deploys a new AI capability, the company doesn’t treat it like a technology rollout, but as a transformation for how work gets done, says <a href="https://www.linkedin.com/in/megan-cullen-meyer-a209435/" rel="nofollow">Megan Cullen-Meyer</a>, its VP of data and AI. The company examines what tasks need to change, what roles need to be realigned, and what training and reskilling is needed, for instance.</p>



<p>With AI, IMA is automating routine, transactional work that used to burn up a lot of human time and energy.</p>



<p>“We talk a lot about how applying AI to old, outdated processes isn’t how we’re going to get the value we want from AI,” she says. “We’re taking a hard look at our core tasks and workflows to determine where we automate the work, where we augment work, and where we keep humans at the center.”</p>



<h2 class="wp-block-heading">Setting the right foundation</h2>



<p>The Deloitte report suggests that the IT team can’t build AI tools in a vacuum, says <a href="https://www.linkedin.com/in/luismesas/?locale=en" rel="nofollow">Luis Mesas</a>, VP of product engineering at IT services provider Sngular. The value of AI comes when the organization develops a good governance framework to start with, can keep learning from what’s happening in its workflows, and can adjust the system without turning every improvement into a new initiative, he adds.</p>



<p>“This requires IT to work much closer with the business problem from the beginning,” he says. “Engineering teams can’t build AI systems in isolation and expect adoption to follow later, because they need to understand the process, the quality of the data behind it, and the risk of getting the answer wrong before they can design something that’ll hold up in day-to-day use.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic brings Claude Cowork to mobile and web as usage data shows most users aren’t coding]]></title>
<description><![CDATA[Anthropic on Tuesday launched Claude Cowork on mobile and web, expanding a tool that has quietly become the company's bridge between the developer-centric world of AI coding agents and the far larger market of knowledge workers who never open a terminal.The rollout, which begins in beta with Max ...]]></description>
<link>https://tsecurity.de/de/3652421/it-nachrichten/anthropic-brings-claude-cowork-to-mobile-and-web-as-usage-data-shows-most-users-arent-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652421/it-nachrichten/anthropic-brings-claude-cowork-to-mobile-and-web-as-usage-data-shows-most-users-arent-coding/</guid>
<pubDate>Tue, 07 Jul 2026 20:03:20 +0200</pubDate>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a> on Tuesday launched <a href="https://claude.com/blog/cowork-web-mobile/">Claude Cowork on mobile and web</a>, expanding a tool that has quietly become the company's bridge between the developer-centric world of AI coding agents and the far larger market of knowledge workers who never open a terminal.</p><p>The rollout, which begins in beta with <a href="https://support.claude.com/en/articles/11049741-what-is-the-max-plan">Max subscribers</a> before expanding to additional plans, marks a strategic inflection for Anthropic. It transforms Cowork from a desktop-only agent into a cross-device platform where tasks can start on a laptop, continue autonomously in the background, and be reviewed from a phone — even after the user closes the app entirely.</p><p>"Your work goes everywhere with you, and keeps going without you," Anthropic writes in its announcement.</p><p>The timing is deliberate. Alongside the mobile launch, Anthropic published usage data from 1.2 million anonymized Claude Cowork sessions sampled between May 11 and May 31, drawn from more than 600,000 organizations. The data paints a striking picture: the overwhelming majority of what people do with Cowork has nothing to do with writing software.</p><div></div><h2><b>The biggest AI story nobody's talking about</b></h2><p>The numbers tell a story that cuts against the dominant narrative in enterprise AI, which has fixated on coding assistants and developer productivity as the primary use case for large language models.</p><p>Business process and operations — tasks like pulling scattered updates into a single report, building onboarding checklists, and reconciling spreadsheets — accounted for 33.4% of all sampled Cowork sessions, making it the single largest category by a wide margin. Content creation and copywriting — producing drafts, slide decks, posts, and proposals — came in second at 16.4%.</p><p>Together, those two categories make up roughly half of all Claude Cowork usage. Software development, by contrast, accounted for just 8.7%. DevOps and infrastructure followed at 7%, with research and intelligence at 6.4%, data analysis and business intelligence at 5.8%, document processing and extraction at 4.1%, and sales and revenue operations at 4%.</p><p>The remaining 12 categories each represented less than 4% of usage, including personal assistance at 3.8%, education at 2.4%, and meeting intelligence at 1.8%.</p><p>Anthropic describes these dominant use cases as "the work around the work" — tasks that span nearly every role in an organization but rarely appear in anyone's core job description. "People are using it for a variety of tasks that aren't necessarily the hallmark of a specific role, but instead represent the connective work around a role that moves projects forward and keeps businesses running," the company writes. "That means tasks like drafting a status update, building a slide deck, or condensing reams of research into a single report."</p><p>That phrase — "the work around the work" — is Anthropic's attempt to define and claim an entirely new category of AI productivity. It's a calculated reframing: rather than positioning AI as a tool that replaces what professionals do, Anthropic is arguing that the most valuable current application is handling everything professionals do around their actual expertise.</p><h2><b>What mobile access changes — and what it doesn't</b></h2><p>The <a href="https://claude.com/blog/cowork-web-mobile/">expansion to mobile and web</a> introduces three concrete capabilities that reflect how Anthropic envisions Cowork fitting into daily workflows.</p><p>First, sessions now sync across devices. A user can start a task at their desk, check on its progress from a phone, and retrieve the finished output from any device. Second — and arguably more significant — Cowork can now run tasks in the background with no device online at all. Users can schedule work for a specific time, and Claude will execute it autonomously. Anthropic offers the example of setting Monday morning client prep for 6 a.m.: "Claude works through the email threads, transcripts, and recent news, builds the briefing doc, and leaves the follow-up email drafted but unsent. Review it over coffee."</p><p>Third, when Claude encounters a decision that requires human judgment, it surfaces the question to the user's phone. "Nothing ships until you've reviewed and approved it," Anthropic states.</p><p>Desktop remains the most fully featured surface, with access to local files and the browser. But the web version also opens Cowork to users who cannot install a desktop application — a meaningful expansion in enterprise environments where IT departments control software installation.</p><p>The company also unified its interface: on web and desktop, chat and Cowork now share a single home screen, and projects and artifacts persist across both modes.</p><p>To encourage adoption, Anthropic is extending doubled Cowork usage limits through August 5.</p><h2><b>The strategic logic: why Anthropic is chasing the non-developer</b></h2><p>The usage data and the mobile launch together reveal a company executing a two-track strategy. <a href="https://www.anthropic.com/product/claude-code">Claude Code</a>, its terminal-based coding agent, dominates among software developers. But Cowork is designed to capture the vastly larger population of professionals whose work involves creating, organizing, and communicating information rather than writing code.</p><p>The contrast between the two products is instructive. As Anthropic notes, Claude Code "is most often used by software developers for the key parts of their role: building, debugging, and shipping code." When developers do use <a href="https://www.anthropic.com/product/claude-cowork">Cowork</a>, they tend to use it not for programming but for the communications-focused work that surrounds every role — status updates, documentation, and coordination.</p><p>This pattern — where AI handles the connective tissue of work rather than its core substance — aligns with what Anthropic describes as people using "Claude Cowork to assemble and structure the information they can use to act on their expertise." The company illustrates this with three examples: a lawyer using Cowork for document formatting and filing while reserving legal judgment for themselves, a hiring manager synthesizing interview feedback while spending more time on candidate conversations, and a team lead producing a slide deck that explains a decision while focusing on actually making that decision.</p><p>The implications for Anthropic's business model are significant. Developer-focused tools, while high-profile, serve a relatively narrow market. The <a href="https://ramp.com/data/ai-index">Ramp AI Index</a> published in May showed Anthropic pulling ahead of OpenAI in business adoption for the first time — with 34.4% of firms paying for Anthropic's services compared to OpenAI's 32.3% — and suggests the company's enterprise push is gaining traction. Claude Code was identified as the primary driver of that shift. But Cowork targets an addressable market that is orders of magnitude larger: every knowledge worker with a laptop, a pile of spreadsheets, and a slide deck due by Friday.</p><h2><b>A crowded field gets more competitive</b></h2><p>The mobile launch arrives during one of Anthropic's busiest — and most turbulent — stretches in its history. </p><p>Just last week, Anthropic launched <a href="https://www.anthropic.com/news/claude-sonnet-5">Claude Sonnet 5</a>, a new model that narrows the performance gap with its more expensive Opus-class models while maintaining lower pricing. The model is available at introductory pricing of $2 per million input tokens through August 31 before rising to $3 per million input tokens. Sonnet 5 serves as the engine underneath Cowork, and its improved agentic capabilities — better reasoning, tool use, and sustained task completion — directly enhance Cowork's ability to handle complex, multi-step workflows.</p><p>Two weeks before that, Anthropic released <a href="https://venturebeat.com/technology/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously">Claude Tag</a>, a Slack-native AI agent designed for team collaboration. Where Cowork focuses on individual task delegation, Claude Tag operates as a multiplayer tool — a single Claude identity that everyone in a Slack channel can interact with, building context from conversations over time. </p><p>According to Anthropic's announcement, 65% of the company's own product team's code is created by its internal version of Claude Tag. <a href="https://fortune.com/2026/06/23/anthropic-claude-tag-virtual-employee-tool-slack/">Fortune reported</a> that Anthropic's head of product for Claude Code and Cowork, Cat Wu, described the distinction: "Claude Code, Cowork, and chat are very single-player, whereas Claude Tag is built to be interactive and multiplayer."</p><p>Together, <a href="https://www.anthropic.com/product/claude-cowork">Cowork</a> and <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag</a> represent a pincer strategy: Cowork captures individual productivity workflows across devices, while Claude Tag embeds AI into team communication channels. Both are designed to push Anthropic deeper into enterprise operations, beyond the developer seat.</p><h2><b>The security question looms</b></h2><p>The expansion also arrives against a backdrop of unresolved security concerns. On July 1, security firm Armadin — led by Mandiant founder Kevin Mandia — published research detailing what it described as a full sandbox escape in Claude Cowork on Windows, as reported by <a href="https://siliconangle.com/2026/07/01/armadin-details-full-sandbox-escape-claude-cowork-anthropic-disputes-risk/">SiliconANGLE</a>. The attack chain involved DLL sideloading against the Claude desktop executable to gain trusted access to Cowork's virtual machine service, then exploiting undocumented parameters to achieve root access and bypass network restrictions.</p><p>Anthropic responded that the vulnerability did not qualify as a security issue because exploiting it requires an attacker to already have local code execution on the host machine. Armadin, however, raised a broader concern: that deploying local virtual machines on nontechnical users' systems creates visibility gaps that endpoint security products struggle to monitor.</p><p>This tension takes on new dimensions as Cowork moves to mobile and web. The web and mobile versions run tasks server-side rather than in a local virtual machine, which eliminates the specific attack surface Armadin identified but introduces different questions about data handling, especially for scheduled background tasks that process email threads, calendar data, and documents without real-time user oversight.</p><p>Anthropic's announcement states that "<a href="https://claude.com/blog/cowork-web-mobile/">the decisions still come to you</a>" and that nothing ships without review and approval. But as Cowork takes on increasingly complex autonomous workflows — processing contract folders, building client briefings from multiple data sources, drafting emails — the surface area for prompt injection and data exposure grows correspondingly. </p><p>When Cowork first launched in January, TechCrunch reported that Anthropic <a href="https://techcrunch.com/2026/01/12/anthropics-new-cowork-tool-offers-claude-code-without-the-code/">explicitly warned</a> about prompt injection risks, noting in its blog post: "These risks aren't new with Cowork, but it might be the first time you're using a more advanced tool that moves beyond a simple conversation."</p><h2><b>As Anthropic courts enterprises, geopolitics complicates the pitch</b></h2><p>Anthropic's enterprise push is also colliding with geopolitical reality. CNBC reported Monday that <a href="https://www.cnbc.com/2026/07/06/alibaba-anthropic-ai-ban-claude-china.html#:~:text=Alibaba%20will%20ban%20employees%20from%20using%20Anthropic%20's%20artificial%20intelligence,risks%2C%20CNBC%20confirmed%20on%20Monday.">Alibaba will ban employees from using Anthropic's AI tools</a> starting July 10, placing Claude Code on a high-risk software list. The move followed Anthropic's June letter to the U.S. Senate accusing Alibaba of carrying out what it called "<a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/">the largest known distillation attack</a>" against its models.</p><p>The Alibaba ban, combined with reports that Anthropic is closing loopholes that allowed Chinese companies to access Claude through third-country entities, underscores the increasingly fraught environment for AI companies attempting to serve global enterprise customers while navigating U.S. export and security restrictions.</p><p>At the same time, Anthropic is investing massively in infrastructure. Reuters reported Monday that <a href="https://www.reuters.com/business/terawulf-jumps-19-billion-data-center-lease-deal-with-anthropic-2026-07-06/">Anthropic signed a $19 billion, 20-year lease with TeraWulf for a data center</a> being built in Hawesville, Kentucky, with 401 megawatts of computing power expected to become fully operational in 2028.</p><p>That kind of capital commitment only makes sense if the company expects enterprise demand — not just from developers, but from the millions of knowledge workers that Cowork targets — to grow dramatically.</p><h2><b>Anthropic's own usage report comes with notable blind spots</b></h2><p>Anthropic is transparent about the limitations of its usage analysis. The taxonomy classifies sessions by the type of work being performed, not by the job title of the person doing it. </p><p>There are no standalone categories for marketing, finance, or HR — functions that are likely absorbed into the dominant "business process and operations" bucket, which may partly explain why that category commands a third of all usage.</p><p>The sample is also rate-capped rather than proportional to traffic, meaning the numbers are shares of sampled sessions, not absolute volumes. Usage during peak hours is somewhat underrepresented. And roughly 5% of sampled sessions involved personal, non-work use — hobbies, personal assistance, and companionship-style conversations — meaning the data doesn't purely reflect workplace activity.</p><p>The company also acknowledged that its labeling pipeline changed around May 11, which is why the analysis window begins on that date rather than covering a longer period.</p><h2><b>What Cowork's rise says about the future of enterprise AI</b></h2><p>Anthropic's <a href="https://claude.com/blog/cowork-web-mobile/">mobile launch</a> and usage data arrive at a moment when the enterprise AI market is shifting from proof of concept to proof of value. The question facing every company deploying AI tools is no longer whether the technology works — but whether it delivers measurable productivity gains across an organization, not just within engineering teams.</p><p>The usage data suggests that the answer, at least for Cowork, is emerging in an unexpected place. It's not in the glamorous work of building software or conducting research. It's in the unglamorous, universal labor of turning messy information into structured outputs that move organizations forward — the status reports, the onboarding checklists, the variance memos, the client decks.</p><p>By untethering that capability from the desktop and making it available on every device, Anthropic is betting that the most valuable AI agent isn't the one that writes code. It's the one that handles everything else.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can Companies Embrace A.I. Without Layoffs? This One Says It Is Trying to.]]></title>
<description><![CDATA[The German software giant SAP says it is betting that employees can reinvent jobs instead of eliminating them. Experts are divided on whether it will work.]]></description>
<link>https://tsecurity.de/de/3640126/ai-nachrichten/can-companies-embrace-ai-without-layoffs-this-one-says-it-is-trying-to/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640126/ai-nachrichten/can-companies-embrace-ai-without-layoffs-this-one-says-it-is-trying-to/</guid>
<pubDate>Thu, 02 Jul 2026 06:18:01 +0200</pubDate>
<content:encoded><![CDATA[The German software giant SAP says it is betting that employees can reinvent jobs instead of eliminating them. Experts are divided on whether it will work.]]></content:encoded>
</item>
<item>
<title><![CDATA[Using AI to reinvent care delivery at Novant Health]]></title>
<description><![CDATA[In healthcare, the pressure to improve outcomes while reducing costs has never been greater. Yet many organizations are still applying AI to existing systems rather than using it to fundamentally change them. At Novant Health, that shift is being driven in part by establishing the chief AI office...]]></description>
<link>https://tsecurity.de/de/3638074/it-security-nachrichten/using-ai-to-reinvent-care-delivery-at-novant-health/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638074/it-security-nachrichten/using-ai-to-reinvent-care-delivery-at-novant-health/</guid>
<pubDate>Wed, 01 Jul 2026 12:08:23 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In healthcare, the pressure to improve outcomes while reducing costs has never been greater. Yet many organizations are still applying AI to existing systems rather than using it to fundamentally change them. At Novant Health, that shift is being driven in part by establishing the chief AI officer role last year, which Vijay Sankararaman has held since then. He uses AI to reshape how care is accessed, delivered, and supported across the enterprise, all while being a catalyst to rethink how the organization operates end to end.</p>



<p><strong>How is AI helping Novant Health achieve its vison?</strong></p>



<p>Our cause is to provide a remarkable experience for our patients, to make it easier, more valuable, and more meaningful for them to access the healthcare we provide 24/7 across primary care, specialty, ambulatory, emergency, and pharmacy. But we live in a changing world with economic headwinds for patients and their healthcare teams, so transformation for us is about reimagining the patient experience, ease of use for clinicians, and value-add from our operations. That’s our AI lens.</p>



<p>The mantra is simple. AI isn’t put on top of a stack of technology and processes. It’s a vehicle that allows us to challenge the status quo and ask if there’s a better way, how would we construct a hospital if we started today, and what’s my ideal working environment as a nurse. We take the persona of the team member and patient, and reimagine their work with the power of predictive, generative, and agentic AI.</p>



<p><strong>What are some examples of this strategy in action on the patient side?</strong></p>



<p>We all love to ask our phones if nagging knee pain is chronic or acute, but the information we receive isn’t always valid. Novant Health created a virtual care AI agent that answers medical questions safely and clinically accurate, using your health records within secure firewalls. The agent gives the patient better information, with correct patient data, and the privacy choice not to put their personal health information into ChatGPT.</p>



<p>We’ve also launched a proactive outreach program for high-risk patients who don’t know they’re at risk. We use predictive AI to identify them based on their health factors, and conversational AI to reach out and encourage them to schedule diagnostic scans. Early detection, after all, saves lives.</p>



<p><strong>What are you doing on the operational side with AI?</strong></p>



<p>Healthcare is complex with a variety of reasons for payers to deny claims, and for providers to challenge. But in the middle are patients who are stuck. We use gen AI to draft claim appeals, which allows us to represent the patient’s interest, give clarity to the claims challenge, and raise patient satisfaction. We’re also using AI to improve patient advocacy in a very meaningful way. Whether it’s cancer outreach or patient advocacy, healthcare requires significant human capital, not just at Novant, but in any 24/7 provider environment. AI doesn’t sleep.</p>



<p><strong>This CAIO role didn’t exist a year ago. How do you define it?</strong></p>



<p>The mandate of the chief AI officer is to enact and orchestrate the transformation that leverages operational excellence, innovation, and technology while keeping the patient at the center. My team and I are designing the new choreography that runs across the entire organization.</p>



<p>Our CIO and his organization are essential partners, leading the core infrastructure across data, cyber, and ERP/EHR, while my organization complements that work by designing the system of the future. We have product leaders, AI engineers, and software and platform engineers who build homegrown AI solutions alongside the hyper-scalers and domain-specific language model partners, all of whom are positioned to leverage AI.</p>



<p><strong>What is the advantage of a CAIO as a peer to IT leadership?</strong></p>



<p>The peer seat allows AI leaders authentically to interrogate how the organization is functioning. What are our real success metrics? What are we doing to achieve them? How can automation and innovation get us to that North Star faster?</p>



<p>Every business leader is in pursuit of a goal, and every pursuit has friction. Traditionally, when a business leader brings that friction to IT, they present it as a problem, a solution, and a directive to use this technology to fix the problem. With AI, our business leaders start with a problem and an interest in consuming data differently. They want help thinking through the problem, they aren’t ordering a solution.</p>



<p>That shift is significant. The people-process-technology framework is now influenced by AI, which provides a level of context not available before. AI is a context creator, rather than a content creator. We haven’t had that before.</p>



<p><strong>What advice would you give to healthcare CEOs right now?</strong></p>



<p>Three things keep healthcare CEOs awake at night. The complexity and cost of healthcare are rising, prompting people to avoid going at all. The nurse population — arguably the most important and most populous in healthcare — is dwindling. And the cost of staying in business is a challenge, between Medicare, Medicaid, and everything else.</p>



<p>As a CEO, I’d start with literacy. The CEO and leadership team must understand what AI can do. Break those opportunities into two buckets of excellence and enrichment. Excellence is how you engage with patients and run your operations. Enrichment is augmentation in that AI is a companion to the clinician, noting very early-stage detection. This is happening at Novant Health now.</p>



<p>Then start to innovate, in both physical and digital spaces. We’re actively leveraging precision robotic surgery and launching an AI solution for diabetic retinopathy, a common high-risk condition for people who don’t get regular eye exams, or something they don’t know they have. A primary care physician, augmented by AI, can now detect it. That’s where physical meets digital.</p>



<p>Whether they decide to hire a chief AI officer or not isn’t the point. The most important question is are you thinking about AI with a viable lens. Do you have a purposed organization and leader fully empowered to challenge the status quo. If you don’t, that’s where to start.</p>



<p><strong>When should companies hire a CAIO as a peer to the CIO?</strong></p>



<p>There’s no one set formula. In some companies, the CAIO sits above the CIO and at others, below. At Novant, our organizations are healthy peers. What clicks with the DNA of your company is the right thing to do.</p>



<p>My CIO and his organization are true partners to our transformation team. We’re completely aligned, and we advance the mission together. If you’re not in a position where a CIO and CAIO can advance your position, then don’t hire one. It’s what makes sense right now for us, and like so much with AI, it’ll change over time.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is exposing the real limits of enterprise cloud strategy]]></title>
<description><![CDATA[Across the global corporations, I advise, in financial services, healthcare, retail and the public sector, the same crisis surfaces in leadership meetings. Executives approved a bold AI roadmap. Cloud spending climbed 40, 50, even 70 percent. And yet the AI workloads that made perfect sense in th...]]></description>
<link>https://tsecurity.de/de/3635329/it-security-nachrichten/ai-is-exposing-the-real-limits-of-enterprise-cloud-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635329/it-security-nachrichten/ai-is-exposing-the-real-limits-of-enterprise-cloud-strategy/</guid>
<pubDate>Tue, 30 Jun 2026 13:06:15 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Across the global corporations, I advise, in financial services, healthcare, retail and the public sector, the same crisis surfaces in leadership meetings. Executives approved a bold AI roadmap. Cloud spending climbed 40, 50, even 70 percent. And yet the AI workloads that made perfect sense in the boardroom presentation now stall, overshoot their budgets or collapse under production load before they reach real users.</p>



<p>I am writing this just after the spring 2026 conference season, and the signal from <a href="https://cloud.google.com/blog/topics/google-cloud-next/google-cloud-next-2026-wrap-up" rel="nofollow">Google Cloud Next</a>, <a href="https://news.microsoft.com/build-2026/" rel="nofollow">Microsoft Build</a>, and a run of <a href="https://aws.amazon.com/events/summits/" rel="nofollow">AWS summits</a> only sharpens the point. Over the past several weeks the industry shipped, in production form, the infrastructure to run and govern AI at scale. What most enterprises still lack is the operating model to decide how to use it.</p>



<p>The problem is not the AI models. The models work. The problem is that organizations built their AI ambitions on cloud strategies designed for a world that no longer exists: strategies built for SaaS applications, predictable traffic and linear cost curves. AI workloads break all three assumptions at once.</p>



<h2 class="wp-block-heading">Why AI breaks traditional cloud assumptions</h2>



<p>For a decade, cloud-first served enterprises well. It delivered elasticity, reduced capital expenditure and democratized access to compute, because enterprise workloads were predictable: web applications, ERP systems, databases and analytics pipelines that scaled smoothly and billed in ways finance could model on a spreadsheet. GenAI and agentic AI change every one of those assumptions at once.</p>



<p>When organizations move AI into production, real inference, retrieval pipelines, vector search and real-time decisioning, the cloud equation breaks in at least five ways:</p>



<ol class="wp-block-list">
<li>Training clusters demand power densities far above standard compute.</li>



<li>Inference needs millisecond latency that network geography can defeat.</li>



<li>Vector databases generate cost spikes invisible in standard billing.</li>



<li>Agentic workloads chain hundreds of tool calls with cascading dependencies.</li>



<li>And data-sovereignty rules constrain where any of them can run.</li>
</ol>



<p>In short, what works at the platform level fails at the workload level.</p>



<p>The costs are the first thing to surprise leaders, because they hide. <a href="https://www.cloudzero.com/blog/ai-cost-management/" rel="nofollow">CloudZero’s analysis</a> and the FinOps teams I work with put it plainly: AI spend surfaces as generic compute, storage and instance line items, rarely labeled “AI.” Three layers drive most of the waste:</p>



<ol class="wp-block-list">
<li>The most visible is LLM API cost, where stateless calls re-send the full conversation history on every request, so a deployment with a couple hundred users can burn many times the token budget in the business case.</li>



<li>The biggest is idle GPU: teams’ provision for peak and then run at 10 to 20 percent utilization, and most miss their AI cost forecasts by more than a quarter.</li>



<li>The most underestimated is the vector database and retrieval layer, where storage I/O, query volume and embedding refresh appear nowhere labeled AI until the bill arrives.</li>
</ol>



<h2 class="wp-block-heading">The dimensions leaders underweight resilience and control</h2>



<p>Cost and latency dominate the conversation. Two dimensions rarely get the same rigor until something breaks:</p>



<ol class="wp-block-list">
<li>Resilience, whether an AI-dependent system can survive failure, degrade gracefully and recover predictably.</li>



<li>Control, who can observe, halt and audit it.</li>
</ol>



<p>AI introduces failure modes that traditional architecture never faced: GPU single points of failure under revenue-critical inference, agentic pipelines that fail mid-execution with no rollback, and models that degrade silently from drift or throttling.</p>



<p>I see the pattern repeated across industries. Organizations design resilience for their traditional applications, then deploy AI on top without asking whether the same guarantees hold. In one global financial services firm I advise, a real-time credit-decisioning model running on a single cloud region took a 47-minute outage during a regional availability event. The halted loan approvals cost more than the system’s entire annual infrastructure budget, and the resilience rework that followed cost several times what designing it in from the start would have. The leaders who avoid this should ask four questions before go-live:</p>



<ol class="wp-block-list">
<li>What happens when the network fails?</li>



<li>What happens when the model degrades?</li>



<li>What happens when an agent executes only halfway?</li>



<li>Who holds the authority to halt and audit?</li>
</ol>



<h2 class="wp-block-heading">What the cloud providers signaled this spring</h2>



<p>The major providers are on track to spend <a href="https://www.statista.com/chart/35046/capital-expenditure-of-meta-alphabet-amazon-and-microsoft/" rel="nofollow">close to $700 billion on AI infrastructure in 2026</a>, roughly three and a half times the 2024 level. Their announcements are strategic signals, not just features. Last year they converged on one message: enterprises cannot run everything in public cloud, so all three built ways to bring their infrastructure into your data center and your sovereign environment. This year the signal advanced a step. They stopped talking about where workloads run and started shipping the layer that governs what agents are allowed to do: identity, containment, auditability and rollback.</p>



<p>Microsoft introduced an “Agent Computer” model with execution containers and machine identity for agents. AWS built <a href="https://aws.amazon.com/blogs/aws/top-announcements-of-aws-reinvent-2025/" rel="nofollow">Amazon Bedrock AgentCore</a> around runtime, memory, identity and auditability. Google shipped an agent gateway and sovereign controls for cross-cloud traffic. As <a href="https://www.bain.com/insights/google_cloud_next_2026_the_agentic_enterprise_control_plane_comes_into_view/" rel="nofollow">Bain observed</a>, agentic AI is now an economics and operations problem, not just a capability problem. The through-line, captured by Microsoft’s own framing, is that AI alone will not change your business; the system running it will. <a href="https://www.mckinsey.com/industries/technology-media-and-telecommunications/our-insights/the-next-big-shifts-in-ai-workloads-and-hyperscaler-strategies" rel="nofollow">McKinsey’s read</a> is consistent: workloads are becoming more distributed, specialized and operationally demanding, which forces more deliberate infrastructure decisions.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/hyperscaler-convergence-spring-2026.png?w=1024" alt="Hyperscaler convergence, Spring 2026." class="wp-image-4190723" width="1024" height="557" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Vipin Jain</p></div>



<h2 class="wp-block-heading">From platform choice to placement decision</h2>



<p>The failure I document most often is not a technology failure; it is a governance failure. Most enterprises lack a clear, repeatable way to decide what runs where, under what conditions and with what tradeoffs. Platform teams make that call informally, under deadline pressure and repeat it hundreds of times as new use cases launch. Workloads then accumulate in public cloud by default, not by design and 30 to 50 percent cost overruns follow, not because public cloud was the wrong choice but because no deliberate choice was ever made.</p>



<p>In one global manufacturer I advise, a predictive-maintenance model went live on public cloud and performed exactly as validated in staging. But real-time inference on the factory floor ran at 80 to 120 milliseconds across the WAN, when the machine-control system needed under ten. Moving the model to edge nodes fixed the latency, but the company lost most of a quarter of the cost, rework and delayed benefits, and the line had run for weeks on stale recommendations: a control failure that could have caused a safety event. The fix was never more AI talent. It was a structured placement decision at the start, weighing six dimensions:</p>



<ul class="wp-block-list">
<li><strong>Latency: </strong>real-time (under 10 ms, edge or on-prem), interactive (50 to 500 ms, cloud) or batch.</li>



<li><strong>Cost and TCO: </strong>token spend, GPU utilization, vector-database queries, egress and unit economics per workload.</li>



<li><strong>Resilience: </strong>failover architecture, degraded-mode behavior, recovery SLA and rollback policy.</li>



<li><strong>Control: </strong>observability, audit trails, governance authority and the ability to halt or reverse.</li>



<li><strong>Data sensitivity: </strong>sovereignty requirements, privacy and compliance rules, and IP protection.</li>



<li><strong>Integration: </strong>legacy system dependencies, pipeline complexity and data-residency constraints.</li>
</ul>



<p>Run consistently, those dimensions produce a placement pattern like this:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Workload</strong></td><td><strong>Latency</strong></td><td><strong>Cost predictability</strong></td><td><strong>Data sovereignty</strong></td><td><strong>Recommended path</strong></td></tr></thead><tbody><tr><td><strong>Customer-facing chatbot</strong></td><td>200-500 ms</td><td>Medium</td><td>Low risk</td><td>Public cloud, reserved instances</td></tr><tr><td><strong>Real-time fraud detection</strong></td><td>Under 10 ms</td><td>Medium</td><td>High</td><td>On-prem or sovereign private cloud</td></tr><tr><td><strong>Clinical decision support</strong></td><td>100-300 ms</td><td>Predictable</td><td>Critical</td><td>Sovereign cloud or dedicated VPC</td></tr><tr><td><strong>Demand forecasting (batch)</strong></td><td>Hours</td><td>High</td><td>Low risk</td><td>Spot instances or scheduled cloud</td></tr><tr><td><strong>Factory-floor vision AI</strong></td><td>Under 5 ms</td><td>Predictable</td><td>Medium</td><td>Edge node (Azure Local, AWS on-prem)</td></tr><tr><td><strong>Internal knowledge assistant</strong></td><td>1-3 sec</td><td>Variable tokens</td><td>High (IP risk)</td><td>Private cloud with on-prem retrieval</td></tr></tbody></table> </div></figure>



<p>This is no longer optional. <a href="https://www.storagenewsletter.com/2026/03/11/enterprise-survey-finds-93-are-repatriating-ai-workloads-or-evaluating-a-move-away-from-public-cloud/" rel="nofollow">Cloudian’s 2026 enterprise AI infrastructure survey</a> found that 79 percent of enterprises have already moved AI workloads out of public cloud, and 93 percent are repatriating or actively evaluating it, driven by data sovereignty, cost overruns and real-time performance. Repatriation is now the norm, not the exception.</p>



<p>The agentic layer makes discipline urgent. An agent chains 20 to 100 tool calls, each with its own latency, cost and failure mode, so the governance model that works for a chatbot does not work for an autonomous agent approving procurement or onboarding a customer. This spring the providers shipped production infrastructure for exactly this, yet <a href="https://www.deloitte.com/global/en/issues/generative-ai/state-of-ai-in-enterprise.html" rel="nofollow">Deloitte’s 2026 survey</a> of more than 3,000 leaders finds only about one in five companies has a mature governance model for autonomous agents. The platforms solved the mechanism. Most enterprises have not yet written the policy.</p>



<h2 class="wp-block-heading">What the leaders do differently</h2>



<p>The organizations extracting compounding value from AI, not just running experiments, share one discipline: they treat workload placement as a repeatable process, and they build resilience and control in from the start rather than after the first production incident. In practice, they do five things:</p>



<ol class="wp-block-list">
<li>Classify every use case at intake across the six dimensions, before any infrastructure is provisioned.</li>



<li>Separate AI budget lines for experiments, production inference and training, so cost is governable.</li>



<li>Treat unit economics, cost per inference, per query and per agent run, as engineering KPIs, not month-end surprises.</li>



<li>Define repatriation triggers in advance, typically 12 to 18 months of stable volume.</li>



<li>Write an explicit resilience contract, and agentic observability and rollback rules, before scaling.</li>
</ol>



<p>The gap between strategy-ready and infrastructure-ready is the remediation backlog, and most enterprises stall moving from proof of concept to production for exactly this reason. <a href="https://www.deloitte.com/us/en/insights/topics/technology-management/tech-trends/2026/ai-infrastructure-compute-strategy.html" rel="nofollow">Deloitte’s tech-trends analysis</a> frames the same shift as the move to inference economics: the bottleneck is infrastructure governance, not model capability.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/ai-governance.png?w=1024" alt="AI infrastructure maturity: The governance gap." class="wp-image-4190724" width="1024" height="555" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Vipin Jain</p></div>



<p><strong>For CIOs, a 90-day agenda. </strong>Five actions separate the leaders from those managing infrastructure crises:</p>



<ol class="wp-block-list">
<li>Audit every AI workload in production across latency, cost, sovereignty, volume, resilience, control and integration.</li>



<li>Separate AI infrastructure budget lines so each workload type is attributable and governable.</li>



<li>Define unit economics by workload and review them as engineering KPIs.</li>



<li>Set a quantitative repatriation evaluation trigger.</li>



<li>Define observability, cost attribution and rollback policy before scaling agents.</li>
</ol>



<h2 class="wp-block-heading">The strategic reframe</h2>



<p>The organizations making real progress on AI are not distinguished by the sophistication of their models or the size of their cloud contracts. One discipline sets them apart: a clear, repeatable way to decide what runs where, under what conditions, with what tradeoffs and what happens when something fails. That discipline is not an IT problem. It is a strategic capability that requires CIO ownership, CFO alignment and executive accountability.</p>



<p>This spring the cloud providers handed enterprises the infrastructure to run and govern AI, and agents, at every tier of the architecture. The gap is no longer supply. It is the operating model to use deliberately. The companies building that model now build the operating foundation for AI at scale. Everyone else builds a remediation backlog. The infrastructure decisions you make in the next 12 months will decide which of those two you become.</p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.20 Beta brings ray tracing improvements, better VRAM management]]></title>
<description><![CDATA[Coming in hot with the release of the Steam Machine, Valve released SteamOS 3.8.20 Beta with a new graphics driver for ray tracing and VRAM management changes.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3634788/linux-tipps/steamos-3820-beta-brings-ray-tracing-improvements-better-vram-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634788/linux-tipps/steamos-3820-beta-brings-ray-tracing-improvements-better-vram-management/</guid>
<pubDate>Tue, 30 Jun 2026 09:09:22 +0200</pubDate>
<content:encoded><![CDATA[Coming in hot with the release of the Steam Machine, Valve released SteamOS 3.8.20 Beta with a new graphics driver for ray tracing and VRAM management changes.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/steamos-3-8-20-beta-brings-ray-tracing-improvements-better-vram-management/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oh, behave! How Gemini can reshape the web for the way you work]]></title>
<description><![CDATA[Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.



Sure, services like Google’s Gemini and its contemporaries can be useful in certain limited, specific areas for productivity purposes. But working with them can also be pre...]]></description>
<link>https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</guid>
<pubDate>Mon, 29 Jun 2026 13:47:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.</p>



<p>Sure, services like Google’s Gemini and its contemporaries <a href="https://www.computerworld.com/article/4007736/gemini-android.html">can be useful</a> in <a href="https://www.computerworld.com/article/3845447/google-workspace-how-to-use-gemini-ai-side-panel.html">certain limited, specific areas</a> for productivity purposes. But working with them can also be pretty disheartening and overwhelming — from <a href="https://www.computerworld.com/article/4047909/burned-out-by-bots-prompt-fatigue-in-workplace.html">prompt fatigue</a> and an onslaught of <a href="https://www.cio.com/article/4077448/ai-workslop-the-new-productivity-killer-only-training-can-stop.html" target="_blank">AI workslop</a> to the fear of <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html">lost jobs</a> and even just the simple <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">inconsistencies and inaccuracies</a> these systems are <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">so prone to providing</a>. (And that’s to say nothing of <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">the ever-increasing creepy factor</a> that often accompanies this type of technology.)</p>



<p>More and more, it seems the most significant impact of these systems is in <a href="https://www.computerworld.com/article/4022711/when-everything-is-vibing.html">areas like coding</a>, where AI is allowing ambitious tech-heads to <a href="https://www.fastcompany.com/91528164/claude-code-vibe-code-word-processor" target="_blank" rel="noreferrer noopener">create their own custom programs</a> with limited to no programming knowledge (but <a href="https://www.fastcompany.com/91345791/vibecoding-replit-debugging-claude" target="_blank" rel="noreferrer noopener">a <em>lot</em> of time, vision, and patience</a>) — as well as allowing accomplished coders to produce products more quickly by letting AI do the dirty work and then spending <em>their</em> time <a href="https://www.computerworld.com/article/4066260/why-we-need-human-developers.html">guiding, tweaking, and correcting its output</a>.</p>



<p>That’s all well and good, but the reality is that most of us mere mortals are never gonna mess with anything that daunting. That doesn’t, however, mean we can’t enjoy a slice of the custom-coding pie and the productivity advantages it offers — on a much simpler but still supremely useful level.</p>



<p>The average-worker answer lies in an oft-overlooked middle-ground possibility these AI chatbots possess to help us create relatively basic but extremely high-potential custom browser extensions. As their name suggests, these simple little programs run entirely in your browser — the same exact sorts of add-ons you’d typically find and install in a marketplace like <a href="https://chromewebstore.google.com/" target="_blank" rel="noreferrer noopener">Google’s Chrome Web Store</a>.</p>



<p>But with Gemini or any other similar genAI platform, you can dream up your <em>own </em>web-improving extension and turn it into reality in a matter of minutes — simply by describing your goal and then guiding the AI gently along the way. And given how much time most of us spend on the web these days, that opens up a tantalizing series of doors for taking total control of your work environment.</p>



<p>Hate all the extraneous bells and whistles gunking up the Google Docs interface? Gemini can create a Chrome extension that removes them. Annoyed by a glitchy web app? Ask Gemini for an extension that makes some under-the-hood improvements. The possibilities are endless.</p>



<p>Let me show you how exactly it works, how easy it is to approach and master, and how many work-enhancing possibilities are out there just waiting to be created.</p>



<h2 class="wp-block-heading"><a></a>The ins and outs of Gemini’s custom Chrome extensions</h2>



<p>First things first: You don’t need any special tools or subscriptions to make this happen. For the purposes of this article, we’ll focus on Google’s Gemini for the creation and the standard desktop Chrome browser for the installation — but the same basic process would work with most any AI chatbot, if you happen to prefer ChatGPT or Claude, as well as with any extension-supporting, <a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium-compatible browser</a> (a list that includes everything from Microsoft Edge to Brave, <a href="https://www.computerworld.com/article/4148888/8-advanced-ways-vivaldi-boosts-your-productivity.html">Vivaldi</a>, and beyond).</p>



<p>Google offers a dizzying array of <a href="https://blog.google/products-and-platforms/products/google-one/google-ai-subscriptions/" target="_blank" rel="noreferrer noopener">Gemini modes and options</a> and an equally overwhelming series of <a href="https://gemini.google/subscriptions/" target="_blank" rel="noreferrer noopener">AI subscription plans</a> that control how much you can use those capabilities, but you don’t need to worry about any of that to create custom Chrome extensions. You might sometimes see better results if you switch your Gemini model to “Pro” or your Gemini <em>thinking level</em> to “Extended” — designations that even Gemini itself has trouble deciphering (believe me, I asked!) — but just using the default Gemini settings with a free Google account will generally work quite well.</p>



<p>Getting going with a custom Chrome extension is as simple as <a href="https://gemini.google.com/" target="_blank" rel="noreferrer noopener">opening up a new Gemini chat</a> and telling the system what you want it to cook up for you. The hardest part is deciding what you want and what’d be helpful for you — something we’ll explore more in a moment, via specific examples and suggestions. Once you’ve got that, you can just ask Gemini to create a Chrome extension that’ll accomplish what you’re envisioning, with as much specificity as possible about what it’ll do and how it’ll look.</p>



<p>Gemini will spit back a series of plain-text code chunks with instructions to copy each cluster and paste it into a new plain text file with a certain specific name — things like “manifest.json,” “content.js,” and “styles.css.” All you’ll do is use the on-screen button to copy each segment, then open up any simple text editor (like Windows Notepad, macOS TextEdit, or any number of <a href="https://browserpad.org/" target="_blank" rel="noreferrer noopener">simple online text editors</a>) and paste the text in, then save it under the name Gemini gives you.</p>



<p>You’ll need to put all the files into a single isolated folder on your computer, and then you can go into Chrome, type <strong>chrome:extensions </strong>into its address bar, and install your shiny new creation by:</p>



<ul class="wp-block-list">
<li>Flipping the toggle next to “Developer mode” in the upper-right corner of the screen into the on and active position, if it isn’t already</li>



<li>Clicking the “Load unpacked” button</li>



<li>And selecting the folder you just created in the pop-up that appears</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-01-chrome-extension-controls.jpg?quality=50&amp;strip=all&amp;w=1024" alt="chrome extension controls including developer mode toggle and load unpacked button" class="wp-image-4185233" width="1024" height="114" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Chrome’s “Developer Mode” toggle and “Load unpacked” button are the keys to importing any extension you create.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>And that’s pretty much it: No complicated compiling or program publishing — the extension you envisioned will be alive and working right in your browser and ready to use.</p>



<p>Now, odds are, it won’t be <em>exactly</em> what you wanted in its first iteration, and you’ll have to go back to Gemini to request several rounds of updates and corrections. Each time, Gemini will create a new set of code chunks, and you simply overwrite the text in each file with its corresponding new code chunk.</p>



<p>It’s still a bit of a process. But you’ll rarely spend more than an hour on something simple and maybe a few hours on something especially multifaceted and specific, and whatever you create will then work to your advantage indefinitely from that point onward, on any computer where you install it.</p>



<p>Before we dive into specific slivers of inspiration, let’s just note the hopefully obvious asterisk that this’ll work only if you’re <em>either </em>(a) using a personal computer that isn’t associated with an organization or (b) using a work-connected computer where custom Chrome extensions are permitted. In either scenario, you’ll want to use your own best judgment to ensure that whatever you’re adding into your browser won’t expose any corporate data or cause your IT comrades any alarm if they see you using it in your workday.</p>



<p>With most common examples, though — including all the ones we’re about to go over — you shouldn’t have any problem or cause for concern.</p>



<p>Capisce? Capisce. Let’s get into it.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #1: The interface fixer</h2>



<p>Our first custom Chrome extension category is the one that won me over to this practice initially and has been the most shapeshifting for my own browser-based workflow — and that’s the simple-seeming but transformational ability to have AI remake any web app you rely on to remove unneeded elements and redesign the interface to <em>your</em> exact specifications.</p>



<p>The best example I can show you is what I did with my completely homemade, Gemini-created Docs Zen extension. Google Docs, to put it mildly, has devolved into <a href="https://www.computerworld.com/article/1723650/google-docs-cheat-sheet-how-to-get-started.html#work">a cluttered mess</a>. There are so many on-screen elements I never use and, ironically enough, irrelevant AI elements I’d rather not have in my hair. I just want a calm, simple, minimalist environment for writing — with Google’s second-to-none syncing, universal access, and collaboration systems beneath it.</p>



<p>So rather than try to reinvent the wheel, I described to Gemini all the elements I wanted to remove from Docs and all the ways I wanted to rethink how its interface appeared for me.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-02-initial-prompt.jpg?quality=50&amp;strip=all" alt="prompt asking gemini to make a chrome extension called docs fixer that minimizes and simplifies the google docs interface" class="wp-image-4185238" width="1007" height="621" sizes="auto, (max-width: 1007px) 100vw, 1007px"><figcaption class="wp-element-caption"><p>My original request to Gemini, followed by rounds of expansions and revisions (and eventually also a more poetic name).</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I went back and forth with numerous iterations and kept coming up with interesting new additions to further flesh out and improve the experience — and I ended up with a delightful setup that gives me a distraction-free view of my writing space with a simple toggle to reveal the main Docs menus and a palette icon that allows me to switch from one eye-pleasing theme to another.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="620" height="161" sizes="auto, (max-width: 620px) 100vw, 620px"&gt;<figcaption class="wp-element-caption"><p>Google Docs with my custom Docs Zen extension — a true delight for daily writing.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>My setup deliberately doesn’t include comments or other collaborative elements, as I’m mostly writing by myself these days — but when I do need those elements, the eye icon in the upper-right corner of the screen disables my custom adjustments and takes me back to the standard Docs interface. I can then click the eye icon again in <em>that</em> environment to switch back.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-google-docs-toggle-620.gif" alt="animated screenshot of toggling between simplified and full google docs interface" class="wp-image-4185725" width="620" height="117" sizes="auto, (max-width: 620px) 100vw, 620px"><figcaption class="wp-element-caption"><p>My custom extension includes a simple on-off toggle for times when I need the full Docs setup.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I used Gemini to create something similar for <a href="https://www.computerworld.com/article/1712947/what-is-trello-a-guide-to-atlassians-collaboration-and-work-management-tool.html">Trello</a>, with which I also have a love-hate relationship — loving the foundational functions and easy access everywhere but hating the interface that’s <a href="https://www.computerworld.com/article/3832819/atlassian-refocuses-trello-on-individual-task-management.html">lost focus</a>, gained bloat, and gotten noticeably clunky and slow over time.</p>



<p>With the same sort of step-by-step, plain-English guidance, I was able to transform Trello from this…</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-05-trello-before.jpg?quality=50&amp;strip=all" alt="screenshot of busy default trello interface" class="wp-image-4185239" width="999" height="639" sizes="auto, (max-width: 999px) 100vw, 999px"><figcaption class="wp-element-caption"><p>Trello, in its typical current-day state.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>…into <em>this</em>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-06-trello-after.jpg?quality=50&amp;strip=all" alt="screenshot of trello interface simplified by custom chrome extension written by gemini" class="wp-image-4185234" width="997" height="641" sizes="auto, (max-width: 997px) 100vw, 997px"><figcaption class="wp-element-caption"><p>Trello, with my custom modifications in place.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I couldn’t even begin to recount the number of superfluous features and elements I’ve removed, along with revamping the overall interface to make it both more efficient and more visually pleasing to my eye.</p>



<p>Whether it’s a web app you rely on regularly or even just a website you open often, the possibilities are practically endless for the ways you can reshape it and mold it to make it work better <em>for you</em>.</p>



<p>Speaking of which…</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #2: The feature creator</h2>



<p>In addition to the surface-level adjustments and feature removals in my aforementioned Trello-enhancing extension, I also <em>added in </em>several components — such as one-click buttons for archiving or moving cards — and I managed to speed up the site by making some under-the-hood adjustments Gemini suggested when I asked about its choppy performance. The same sort of concept can apply to any web-based interface you’re using, if there are any options that are annoyingly buried within menus, shortcuts that’d make your life easier, or other improvements you’ve longed to see.</p>



<p>You can also consider some simple standalone extensions for giving yourself on-demand features that aren’t necessarily associated with any one specific website but could be useful in plenty of productivity scenarios. For instance:</p>



<ul class="wp-block-list">
<li>I do a fair amount of basic image editing and frequently find myself needing to reference a hex color code that corresponds with a particular brand color, and I always end up having to open up a new tab and look in a note somewhere to find the code I need. Well, no more: I used Gemini to create a super-simple custom color code pop-up where I can store all the colors I need and then copy any of ’em onto my clipboard with a single click. <em>Major </em>time-saver.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-07-color-palette.jpg?quality=50&amp;strip=all" alt="screenshot of color palette selector - a custom chrome extension created by gemini " class="wp-image-4185237" width="478" height="555" sizes="auto, (max-width: 478px) 100vw, 478px"><figcaption class="wp-element-caption"><p>All the color codes I need are now never more than a couple clicks away.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<ul class="wp-block-list">
<li>I’m also constantly converting time zones, either for meetings with clients or colleagues or for trying to wrap my head around publishing systems that insist on using random time zones with no meaning to me. It’s infinitely easier for me to manage now, thanks to the custom Chrome extension I made that shows the current time in all the zones I need most often — as well as allowing me to put any <em>other </em>time into any field and have all the other zones instantly adjust to match. It also offers a brilliant plain-text conversion box where I can just type things like “1pm-3pm PT in MT” and have it cough back up an instant answer for any conversion I need.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-08-time-zone-converter.jpg?quality=50&amp;strip=all" alt="screenshot of time zone converter  - a custom chrome extension created by gemini " class="wp-image-4185235" width="432" height="542" sizes="auto, (max-width: 432px) 100vw, 432px"><figcaption class="wp-element-caption"><p>My custom time zone conversion extension comes in handy countless times a day.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>Maybe what you want is the ability to interact with data on different websites more easily — to be able to save any table on a page in front of you as a CSV file, mayhap, or even to save any text you highlight on a page into a new Google Docs document. Whatever the case may be, Gemini can handle it — and that superpower that you’ve always wished for but never found the right tool to make possible can actually now be yours.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #3: The browser expander</h2>



<p>Our final category of custom Chrome extensions to consider moves beyond the web itself and into your actual browser. The browser is essentially the modern-day desktop, after all — and for the first time now, you can expand and enhance it in all sorts of interesting ways.</p>



<p>Some specific examples, to get your brain-motor whirring:</p>



<ul class="wp-block-list">
<li>You could walk Gemini through creating a smart auto-snooze system for your open browser tabs, both to clear clutter and help with <a href="https://www.computerworld.com/article/1666806/easy-steps-to-make-chrome-faster-and-more-secure.html">Chrome’s performance</a>. It could save any tab that hasn’t been touched in a certain amount of time to your local storage and then give you a simple searchable “Archive Dashboard” where you can find all those auto-closed tabs and re-open ’em as needed.</li>



<li>With the right guidance, Gemini could give you a custom browser research panel — where any info you highlight on a page gets beamed over into a sidebar-style panel that serves as a running scratchpad of notes from the day.</li>



<li>Or, if you find yourself often needing to see two tabs together side by side, you could have Gemini cook up a custom extension that instantly detaches any tab in front of you and puts it into a new tab window in a perfectly sized and spaced pattern. One keyboard shortcut could make that move happen, while another keyboard shortcut could recombine the two tabs into a single centered window.</li>
</ul>



<p>As with all the other ideas we’ve gone over, all you’ve gotta do is ask — and now, with the right inspiration in mind, you’re ready to get your custom extension adventures going and start bending the web to <em>your</em> will.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Valve adjusts SteamOS resolution options ready for Steam Machine]]></title>
<description><![CDATA[With the Steam Machine just about to release with the first purchasing wave beginning today - Valve released a fresh Beta to adjust screen resolutions.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3632712/linux-tipps/valve-adjusts-steamos-resolution-options-ready-for-steam-machine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632712/linux-tipps/valve-adjusts-steamos-resolution-options-ready-for-steam-machine/</guid>
<pubDate>Mon, 29 Jun 2026 13:10:24 +0200</pubDate>
<content:encoded><![CDATA[With the Steam Machine just about to release with the first purchasing wave beginning today - Valve released a fresh Beta to adjust screen resolutions.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/valve-adjusts-steamos-resolution-options-ready-for-steam-machine/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data lakehouses are becoming foundations for enterprise AI]]></title>
<description><![CDATA[Data lakehouses have become the gold standard for enterprise data platforms since they combine a data lake’s ability to support a variety of different types of data at low cost, and the reliability, structure and governance of a traditional data warehouse.



The fact they offer a central reposit...]]></description>
<link>https://tsecurity.de/de/3620899/it-nachrichten/data-lakehouses-are-becoming-foundations-for-enterprise-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620899/it-nachrichten/data-lakehouses-are-becoming-foundations-for-enterprise-ai/</guid>
<pubDate>Wed, 24 Jun 2026 12:03:48 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.cio.com/article/402574/data-lakehouses-give-enterprises-analytics-edge.html?utm=hybrid_search">Data lakehouses</a> have become the gold standard for enterprise data platforms since they combine a data lake’s ability to support a variety of different types of data at low cost, and the reliability, structure and governance of a traditional data warehouse.</p>



<p>The fact they offer a central repository of information that might come from different places at a company, together with security and auditing tools, make them a perfect fit for enterprise AI systems, too. In fact, they’ve become so popular and useful that all the major data lake and data warehouse vendors have all but converged into data lakehouse vendors. Snowflake, for example, started out as a data warehouse and over the course of several years and acquisitions, has transformed into a full data lakehouse platform.</p>



<p>Docusign is now using it to support its agentic AI ambitions, too. For example, data is pulled in from Salesforce and then used to train an internal AI agent for sales, says Shivi Verma, Docusign’s senior manager of engineering. The company is also training ML models in order to serve customers more accurately.</p>



<p>The information also goes out to LLMs using RAG embedding pipelines, and MCP connectivity is being explored as the technology matures.</p>



<p>One issue Docusign keeps top of mind when exposing the data in its lakehouse is security and governance.</p>



<p>“We’re proceeding very cautiously,” Verma says. “It goes through a stringent security review and discussion with both technical and business stakeholders to make sure we’re not doing anything that isn’t allowed from the security lens and compliance lens.”</p>



<p>The security checks are in place both when the data first goes into Snowflake, he says, and when it goes out again. The restrictions are particularly tight when it comes to access to anything sensitive, such as customer data.</p>



<p>“We’re first exposing those with a low risk profile,” he says. That can include publicly-facing information like website content or product details.</p>



<p>Docusign isn’t alone. “We see 65% adoption of lakehouses among Gartner’s client base,” says Gartner analyst Prasad Pore. “It’s a very strong number in a short time.”</p>



<p>And the future of lakehouses looks even brighter.</p>



<p>“Lakehouse is becoming the foundation for the future of AI,” Pore says, adding that vendors are evolving to support this use case. For example, lakehouse as a concept doesn’t support vector databases, which are a key type of data structure for AI systems that use RAG to feed data into LLMs.</p>



<p>“But many lakehouse vendors have added capabilities for vector indexing,” he says. “Databricks and Microsoft Fabric both have a vector capability built into their platform.” Yet smaller players might not provide the functionality, he adds.</p>



<p>Similarly, support for MCP, a standard that allows AI agents to connect to data and systems, varies by vendor, and isn’t traditionally a core lakehouse functionality.</p>



<h2 class="wp-block-heading">A matter of choice</h2>



<p>A data lakehouse isn’t the only option for companies looking to provide their AI system with the critical business context they need to be useful to the enterprise.</p>



<p>For example, companies can build vector databases or vector database pipelines manually from individual sources, or use a data fabric to make the connection.</p>



<p>“Fabric can directly connect to original sources, which is a good use case for quick analytics,” Pore says. “But then you’re overloading your source systems, which isn’t a good thing for those products and machines.”</p>



<p>Microsoft Fabric is a lakehouse platform, though, and not a data fabric platform in the way Gartner defines the term.</p>



<p>Another downside is that the data models used in original systems aren’t usually optimal for analytics, and can be expensive. “Connecting to direct sources isn’t efficient,” Pore says.</p>



<p>Finally, there are well-established processes for managing data permissions in a lakehouse.</p>



<p>“A lakehouse physically unifies your data, maintenance, security, and governance,” he says. “This is very critical for AI implementation. As an organizational single source of truth, a lakehouse is the modern way to create a central repository.”</p>



<p>Consulting firm Lemongrass originally started out with a data lake about a decade ago, and then began upgrading it to a lakehouse four years ago.</p>



<p>“Back then, the concept of a lakehouse wasn’t that popular,” says Kausik Chaudhuri, chief innovation officer at Lemongrass. So the firm built custom lakehouse functionality on top of its Amazon S3 data lake. Now that it’s using the data lakehouse to support AI, it’s time for another upgrade.</p>



<p>“Right now, we’re working on something for our incident and change management,” he says. The original data is in ServiceNow, and it’d be too expensive to pull it out directly from the lakehouse to use in an AI system. “So now we’re thinking of building an MCP server to query that data,” he adds.</p>



<p>And they also plan to upgrade from its own custom lakehouse add-ons to a standard solution. “Lemongrass was primarily an AWS evangelist when we started, and a lot of our tooling was on top of AWS,” Chaudhuri says. “Now we’re thinking of changing this because with AI, there’s a lot more opportunity.” Then again, AWS now offers lakehouse functionality. “The data’s already there,” he adds. “We don’t have to reinvent it.”</p>



<p>Plus, AWS has connectivity to Anthropic’s Claude AI and other AI models. And since the models are also running on AWS, there are no data egress fees. Lemongrass plans to start the upgrade with a POC in Q3 this year. “Everybody’s busy, so we need to pull in people and figure out when and how we implement that,” he says. For example, the company has to be careful about what data and how much is pulled in from the lakehouse and sent to the AI.</p>



<p>“We don’t send out customer data to an LLM,” he says. “And I’m not reading 10,000 rows and sending it to Claude, which would blow up to token usage. We figured out a couple of years ago we can go bankrupt if we’re not careful about the amount of tokens we use.”</p>



<p>And for some use cases, the LLM doesn’t need to see anything at all after the solution is deployed. For example, firm employees used to manually generate status reports about its customers for internal use, which was a time-consuming process. An AI model could, in theory, take over that job, but then it’d see the customer data. And since AIs aren’t deterministic, each report would look different.</p>



<p>Or, say, the firm needs to generate forms to fill out and then the customer would sign. Again, an LLM could create a custom form each time. “So then we asked Claude to write a program that takes this input and writes this report,” says Chaudhuri. The process of generating reports or the forms is traditional, deterministic software. The customer data is never exposed, and the reports are cheap and fast to produce.</p>



<p>But other companies are use AI to make better use of its data. In a <a href="https://www.databricks.com/resources/ebook/state-of-ai-agents" rel="nofollow">recent report</a> by Databricks based on data from 20,000 organizations, the percentage of databases created by AI agents rose from 0.1% to 80% over the past two years, and agents now create 97% of database branches.</p>



<h2 class="wp-block-heading">Security and governance</h2>



<p>One major area of struggle for enterprises is to figure out how to handle security and other related issues for when AI agents access data lakehouses.</p>



<p>In the past, <a href="https://www.cio.com/article/4046967/the-end-of-dashboards-genai-and-agentic-workflows-transform-business-intelligence.html?utm=hybrid_search">data went out to dashboards</a>, in which the security and access controls were programmed. Or the data went to data analysts, who worked within their own access privileges. The first use cases for AI involved RAG embeddings, which were easier to manage.</p>



<p>In a RAG embedding, traditional, deterministic software is used to pull in data and embed it into an LLM prompt for a particular workflow. The developers setting it up would handle the security aspects for each particular use case. With agentic AI and MCP servers, however, the AI can go and grab data autonomously, as needed.</p>



<p>According to Genpact’s Arellano, enterprises need to figure out how to manage the identities of AI agents, control access to data, create audit trails, and filter prompts and content.</p>



<p>“Agents need their own credentials,” he says. For example, AI agents might not have permissions to ever touch patient records. “And audit trails are important, with full observability of what the agent did.”</p>



<p>Some lakehouse vendors, including Databricks, offer this functionality, he says, and there are other tools that can be brought in like Okta, Palo Alto, or Zscaler.</p>



<h2 class="wp-block-heading">The new semantic frontier</h2>



<p>The next evolution of the lakehouse is the semantic layer, and <a href="https://www.gartner.com/en/newsroom/press-releases/2026-03-11-gartner-announces-top-predictions-for-data-and-analytics-in-2026" rel="nofollow">Gartner</a> estimates that universal semantic layers will be critical infrastructure by 2030.</p>



<p>“Developing a universal semantic layer is now a must‑do for data and analytics leaders either leading or supporting AI,” Gartner says. “It’s the only way to improve accuracy, manage costs, substantially cut AI debt, align multiagent systems, and stop costly inconsistencies before they spread.”</p>



<p>It’s one thing for an AI to have access to data, but entirely something else to understand what that data actually means to the business. The semantic layer is the business knowledge that’s not normally formalized in a structured database, such as, say, the knowledge that an order or a customer means different things in different systems.</p>



<p>“Before, the semantic layer was nice to have but not as necessary because data scientists know what data sources they want to query,” says Amit Kinha, board member of the FinOps Foundation and field CTO at DoiT International, a cloud consultancy.</p>



<p>But now, without it, an AI agent won’t know where to look for the data it needs, he says. “Or it’ll do a bad join, or do something that creates a cost explosion,” he adds. “The semantic layer is going to be critical for leveraging lakehouses effectively.”</p>



<p>This semantic layer can also become part of a feedback loop, where the agentic systems learn from experience, says Kevin Martelli, consulting AI solution development leader at EY Americas.</p>



<p>Say for example a company has a process where approvals are required for certain payments, and a CFO is required to sign off for payments over half a million. If the AI agent goes to a human for approval, he says, the human might say this is telling me to approve this invoice, but I know it’s over $500,000 and I need to get CFO approval on this. “Then it can be stored in the session and persisted back in the lakehouse as a procedural document or as a record of something that occurred,” says Martelli. “This is where it becomes more beneficial and aggregates over time with usage because you’re never going to get it perfect on day one.”</p>



<p>The semantic layer is still very much an evolving area, and different data lakehouse vendors handle it differently.</p>



<p>“There’s this great debate going on in the industry of how lakehouses converge with semantic layers and where they actually live,” says Matt Arellano, SVP of data and AI at digital transformation consultancy Genpact.</p>



<p><a href="https://www.cio.com/article/4160884/you-selected-the-right-vendors-now-govern-them-like-you-mean-it.html?utm=hybrid_search">Some vendors</a> are building semantic tools into their data lakehouse platforms, or acquiring additional firms to get the technology. In other cases, customers are using third-party tools instead.</p>



<p>“Clients are struggling with that,” Arellano says. “They’re all trying to figure out the different combinations and permutations of tools and processes.”</p>



<p>Steven Karan, VP of AI transformation for Capgemini Australia and New Zealand, says he sees the lakehouse as evolving into a central orchestration layer.</p>



<p>“Organizations are now less focused on analytics and reporting, and more on building AI-driven applications and agentic systems,” he says. “The most effective architectures I see today combine a lakehouse core with specialized serving layers.”</p>



<p>That includes vector databases for AI, streaming platforms for real-time data, and operational databases for low-latency applications. The lakehouse isn’t just for analytics anymore, he adds. It’s the foundation for enterprise data and AI. “Its role is now less about replacing all other systems, and more about unifying and governing them to accelerate innovation while maintaining control,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Valve upgraded the SteamOS installation image to the big SteamOS 3.8 release]]></title>
<description><![CDATA[If you're wanting to build your own SteamOS Linux device instead of using the pricey new Steam Machine - now it should be a lot easier.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3620500/linux-tipps/valve-upgraded-the-steamos-installation-image-to-the-big-steamos-38-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620500/linux-tipps/valve-upgraded-the-steamos-installation-image-to-the-big-steamos-38-release/</guid>
<pubDate>Wed, 24 Jun 2026 09:24:25 +0200</pubDate>
<content:encoded><![CDATA[If you're wanting to build your own SteamOS Linux device instead of using the pricey new Steam Machine - now it should be a lot easier.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/valve-upgraded-the-steamos-installation-image-to-the-big-steamos-3-8-release/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Agentic AI’ PCs? Not much new here, say analysts]]></title>
<description><![CDATA[Nvidia and Microsoft this month touted the reinvention of computers with a new class of “agentic AI PCs” that will “reinvent the way PCs work.” 



That’s how Nvidia CEO Jensen Huang described the computers at the recent Computex trade show. At the event, Nvidia introduced its first AI-focused PC...]]></description>
<link>https://tsecurity.de/de/3618182/it-nachrichten/agentic-ai-pcs-not-much-new-here-say-analysts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618182/it-nachrichten/agentic-ai-pcs-not-much-new-here-say-analysts/</guid>
<pubDate>Tue, 23 Jun 2026 14:03:36 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nvidia and Microsoft this month touted the reinvention of computers with a new class of “agentic AI PCs” that will “reinvent the way PCs work.” </p>



<p>That’s how Nvidia CEO Jensen Huang described the computers at the recent <a href="https://www.computextaipei.com.tw/en/index.html" data-type="link" data-id="https://www.computextaipei.com.tw/en/index.html" target="_blank" rel="noreferrer noopener">Computex trade show</a>. At the event, Nvidia introduced its first AI-focused PC chip called N1X, which has an integrated CPU and GPU and will be used in agentic AI PCs.</p>



<p>Nvidia’s new <a href="https://www.computerworld.com/article/4180451/rtx-spark-may-split-the-ai-pc-market-into-mainstream-laptops-and-premium-workstations.html" data-type="link" data-id="https://www.computerworld.com/article/4180451/rtx-spark-may-split-the-ai-pc-market-into-mainstream-laptops-and-premium-workstations.html">RTX Spark PCs</a> are the first in a major “PC reinvention for 40 years,” Huang said, likening them to AI phones. “You could talk to it, it could look at you. You could ask it to read files… [or] go help you do research.”</p>



<p>Not so fast, say analysts, who argue the computers are mostly <a href="https://www.computerworld.com/article/4047019/ai-pcs-to-surge-claiming-over-half-the-market-by-2026.html">repackaged AI PCs</a> that shouldn’t necessarily drive enterprise upgrades.</p>



<p>“Agentic AI PCs is a strange term that should probably be deemphasized,” said <a href="https://next-curve.com/thought-leaders/leonard-lee/" data-type="link" data-id="https://next-curve.com/thought-leaders/leonard-lee/" target="_blank" rel="noreferrer noopener">Leonard Lee</a>, principal analyst at neXt Curve. “Depending on use case, PCs of the last two generations are ‘agentic AI’-capable.”</p>



<p>Skeptical of the hype, analysts said many current PCs are already capable of running agents, such as those spun up on device by <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" data-type="link" data-id="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html">OpenClaw</a>. Those agents don’t need to communicate with AI models in the cloud.</p>



<p>In fact, Lee said, Apple has already shown that Windows isn’t needed to run agentic workloads, with the Mac Mini among the most talked-about device for hosting personal AI agents and OpenClaw.</p>



<p>Analysts said the definition of agentic AI PCs really comes down to the hardware inside, which largely defines their capabilities. Most are really just an evolution of earlier AI PCs, which arrived a few years ago amid similar hype.</p>



<p>AI PCs, specifically CoPilot+ PCs, were originally designed with neural processing units (NPUs) to support the requirements of Windows Recall. “Some argue agentic AI PCs need more GPU compute, but…Qualcomm and Microsoft would counter that agentic AI PCs have been around for a while,” Lee said.</p>



<p>To highlight the capabilities of the RTX Spark PC, a demonstration at Computex showed how an architectural design workflow could be split between the PC and the cloud. (An MCP server managed data exchange to facilitate the cloud-PC workflow.)</p>



<p>Adobe has reengineered Photoshop and Premiere for RTX Spark PCs, allowing the software to communicate with AI agents on PCs and tools to run twice as fast, Huang said.</p>



<p>And at the company’s recent <a href="https://build.microsoft.com/en-US/home" data-type="link" data-id="https://build.microsoft.com/en-US/home" target="_blank" rel="noreferrer noopener">Build conference</a>, Microsoft CEO Satya Nadella demonstrated the new Surface Laptop Ultra AI PC based on the RTX Spark design. He positioned agentic AI PCs as running a new execution layer that can act across files and devices, including generating and executing code. </p>



<p>While AI PCs with agents will be capable, they still lack applications, said <a href="https://tiriasresearch.com/team/jim-mcgregor/" data-type="link" data-id="https://tiriasresearch.com/team/jim-mcgregor/" target="_blank" rel="noreferrer noopener">Jim McGregor</a>, principal analyst at Tirias Research. “However, PCs — especially the small form factor PCs and workstations — are likely to be the home AI appliance,” he said.</p>



<p>For enterprises, upgrading to RTX Spark PCs at this point could pose problems. That’s because Nvidia’s N1X CPU is based on the Arm processor architecture and could run into compatibility issues with x86 applications designed for Intel and AMD chips.</p>



<p>“Despite Arm processors being available for a while, enterprise penetration stays small, since compatibility with all apps, drivers, and corporate systems is critical and requires extensive testing…, even though Microsoft has done a reasonably good job with Windows 11 on Arm,” said Jack Gold, principal analyst at <a href="https://jgoldassociates.com/" data-type="link" data-id="https://jgoldassociates.com" target="_blank" rel="noreferrer noopener">J. Gold Associates</a>.</p>



<p>Because Microsoft is moving to natively incorporate AI into Windows, those PCs will land in enterprises ultimately, Gold said.</p>



<p>Regardless of hype, it might be a good time for enterprises chasing an agentic AI agenda to upgrade laggard Windows 10 devices, Lee said. “Considering the considerable hype about agentic AI, early adopters will need to upgrade their fleets if they pursue a broad agentic AI agenda for their organizations,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building ‘idiot proof’ systems is not the answer]]></title>
<description><![CDATA[A group of academics recently asked me, “In the technology space, how much do you need to know today to be considered not ignorant?”



Both philosophers (the folks who study knowledge) and cognitive scientists (the folks who study the acquisition and application of knowledge) agree that the base...]]></description>
<link>https://tsecurity.de/de/3617778/it-security-nachrichten/building-idiot-proof-systems-is-not-the-answer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617778/it-security-nachrichten/building-idiot-proof-systems-is-not-the-answer/</guid>
<pubDate>Tue, 23 Jun 2026 11:37:51 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A group of academics recently asked me, “In the technology space, how much do you need to know today to be considered not ignorant?”</p>



<p>Both philosophers (the folks who study knowledge) and cognitive scientists (the folks who study the acquisition and application of knowledge) agree that the base of knowledge required to remain relevant in society is expanding. Wiley, which published my book <em><a href="https://www.amazon.com/New-Know-Innovation-Powered-Analytics/dp/0470461713" rel="nofollow">The New Know</a></em>, annually adds approximately 100 new books to its 2,500-title <em>For Dummies</em> series.</p>



<p>Knowledge is a moving target. There is new knowledge. There is bad knowledge — beliefs that were always flat out erroneous. There is no longer good knowledge — things that once were true but no longer are.</p>



<p>Like the Central Intelligence Agency, CIOs are tasked with supporting decision-makers with analyses of the current situation, with advisories regarding when those conditions are likely to change, and warning of risks inherent to the full spectrum of technology investment choices.</p>



<p>Historically, the 18 federal organizations that make up the US Intelligence Community will not make policy recommendations. They just provide the analysis. CIOs have to do more. The first Director of National Intelligence, John Negroponte, once noted, “Vigilance is not enough.”</p>



<p>Experience tells us that there is no such thing as an “idiot proof” system. It is not enough to deploy great systems. CIOs have to ensure that the stakeholders using these systems know enough to extract full value from the technology being provided.</p>



<p>Knowledge pumping — providing the baseline of facts necessary to make decisions — has to be accompanied by multi-constituent executive education. CIOs have to ensure that key stakeholders understand underlying technology conditions; have to be able forecast future conditions or outcomes; and test hypotheses or theories.</p>



<p>Ideally, this would involve portraying and communicating results using data visualization. Vince Kellen, CIO for The Texas A&amp;M University System, who is typically three or four standard deviations in front of the curve, refers to such illustrations as “anchor visuals.”</p>



<p>What anchor visuals are you using to keep your community of stakeholders moving in the right direction?</p>



<p>The level of satisfaction or dissatisfaction stakeholders have toward technology in general and artificial intelligence specifically are directly tied to the quality of the narrative surrounding the technology.</p>



<p>In <em><a href="https://yalebooks.yale.edu/book/9780300272871/ancient-wisdom-for-polarized-times/" rel="nofollow">Ancient Wisdom for Polarized Times: Why Humanity Needs Herodotus, the Man Who Invented History</a></em>, Emily Katz Anhalt insists “stories have a profound influence on who we are and who we become.”</p>



<p>Does your technology and AI messaging link to mission and the ability to solve a hard problem? If that story is couched solely in terms of monetary gains, you may have a problem.</p>



<p><a href="https://www.wired.com/story/sam-altman-meta-ai-talent-poaching-spree-leaked-messages/" target="_blank" rel="nofollow">In an internal memo</a>, OpenAI CEO Sam Altman opined that “[AI] missionaries will beat [AI] mercenaries.”</p>



<p>Currently an enormous amount of resource is being devoted to agentic AI with the objective of automating workflows. In <em><a href="https://www.amazon.com/Agentic-Artificial-Intelligence-Harnessing-Reinvent-ebook/dp/B0F1DS36YC" rel="nofollow">Agentic Artificial Intelligence: Harnessing AI Agents to Reinvent Business, Work and Life</a></em>, Pascal Bornet and Jochen Wirtz express concern that “We’re treating humans like robots and AI like creatives. It’s time to flip the equation.” It is ironic that we are spending huge amounts of money training models and very little educating the humans using these models.</p>



<p><a href="https://www.deloitte.com/US/EN/INSIGHTS/INDUSTRY/TELECOMMUNICATIONS/CONNECTIVITY-MOBILE-TRENDS-SURVEY.HTML" rel="nofollow">Deloitte’s 2025 Connected Consumer Survey</a><em> </em>observed, “Among those surveyed who are using gen AI for work, 40% say their companies provide training.” Does this mean that 60% of the economy is simply deploying the tools and hoping for the best?</p>



<p>The mainstream business press tells us that the tech ecosystem has moved from a phase of “move fast and break things” to an infrastructure groundwork focused on “moving slow and building things.” Experienced CIOs know at the essence of their beings that before moving they and their stakeholders have to “know things.”</p>



<p>By investing in muggle tech knowledge (knowledge pumping) we are increasing human agency and expanding our capacity for innovation.</p>



<p>Generally, people want to understand the technology that surrounds them. This willingness to know is tempered by what Keith E. Stanovich in <a href="https://www.amazon.com/Bias-That-Divides-Us-Politics/dp/0262045753" rel="nofollow"><em>The Bias That Divides Us: The Science and Politics of Myside Thinking</em></a>, refers to as “myside bias”: “we evaluate evidence, generate evidence, and test hypotheses in a manner biased toward our own prior beliefs, opinions, and attitudes.”</p>



<p>Effective knowledge pumping has to be individualized to the mental starting point of the stakeholder.</p>



<p>A switched-on, tech-savvy user base has been the White Whale of CIO Ahabs for decades.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.11 released to fix getting stuck on the Desktop Mode lock screen]]></title>
<description><![CDATA[With the huge SteamOS 3.8 update now out, a few hiccups were expected - but thankfully, they’ve already patched one of the major annoyances.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3613390/linux-tipps/steamos-3811-released-to-fix-getting-stuck-on-the-desktop-mode-lock-screen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613390/linux-tipps/steamos-3811-released-to-fix-getting-stuck-on-the-desktop-mode-lock-screen/</guid>
<pubDate>Sun, 21 Jun 2026 11:39:48 +0200</pubDate>
<content:encoded><![CDATA[With the huge SteamOS 3.8 update now out, a few hiccups were expected - but thankfully, they’ve already patched one of the major annoyances.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/steamos-3-8-11-released-to-fix-getting-stuck-on-the-desktop-mode-lock-screen/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Convoy co-founder Dan Lewis exits Microsoft to launch stealth startup aiming to reinvent AI supply chain]]></title>
<description><![CDATA[Dan Lewis, who led the Seattle freight marketplace Convoy before it shut down in 2023, has left Microsoft to start a stealth company focused on running AI models more efficiently, extending a career spent at the intersection of AI and logistics. Read More]]></description>
<link>https://tsecurity.de/de/3608331/it-nachrichten/convoy-co-founder-dan-lewis-exits-microsoft-to-launch-stealth-startup-aiming-to-reinvent-ai-supply-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608331/it-nachrichten/convoy-co-founder-dan-lewis-exits-microsoft-to-launch-stealth-startup-aiming-to-reinvent-ai-supply-chain/</guid>
<pubDate>Thu, 18 Jun 2026 18:05:29 +0200</pubDate>
<content:encoded><![CDATA[<img width="1260" height="840" src="https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD-1260x840.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD-1260x840.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD-768x512.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD-630x420.jpg 630w, https://cdn.geekwire.com/wp-content/uploads/2019/10/2663-Summit-20191008-DD.jpg 2048w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Dan Lewis, who led the Seattle freight marketplace Convoy before it shut down in 2023, has left Microsoft to start a stealth company focused on running AI models more efficiently, extending a career spent at the intersection of AI and logistics. <a href="https://www.geekwire.com/2026/convoy-co-founder-dan-lewis-exits-microsoft-to-launch-stealth-startup-aiming-to-reinvent-ai-supply-chain/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8 is out with initial Steam Machine support, Desktop Mode upgrades, new Graphics Drivers]]></title>
<description><![CDATA[Valve finally released the stable version of their Linux-powered SteamOS 3.8, bringing with it masses of changes making it one of the biggest upgrades yet.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3606939/linux-tipps/steamos-38-is-out-with-initial-steam-machine-support-desktop-mode-upgrades-new-graphics-drivers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606939/linux-tipps/steamos-38-is-out-with-initial-steam-machine-support-desktop-mode-upgrades-new-graphics-drivers/</guid>
<pubDate>Thu, 18 Jun 2026 09:25:10 +0200</pubDate>
<content:encoded><![CDATA[Valve finally released the stable version of their Linux-powered SteamOS 3.8, bringing with it masses of changes making it one of the biggest upgrades yet.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/steamos-3-8-is-out-with-initial-steam-machine-support-desktop-mode-upgrades-new-graphics-drivers/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google bets on Gemini to reinvent the smart home speaker]]></title>
<description><![CDATA[Google is betting generative AI can breathe new life into the smart speaker. The company's new $99.99 Google Home Speaker replaces the rigid commands of the Google Assistant era with more conversational Gemini interactions.]]></description>
<link>https://tsecurity.de/de/3605480/it-nachrichten/google-bets-on-gemini-to-reinvent-the-smart-home-speaker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605480/it-nachrichten/google-bets-on-gemini-to-reinvent-the-smart-home-speaker/</guid>
<pubDate>Wed, 17 Jun 2026 18:32:57 +0200</pubDate>
<content:encoded><![CDATA[Google is betting generative AI can breathe new life into the smart speaker. The company's new $99.99 Google Home Speaker replaces the rigid commands of the Google Assistant era with more conversational Gemini interactions.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Decade-Old Residual Connections Still Power All of AI (And Why That’s a Problem)]]></title>
<description><![CDATA[For nearly a decade, this part of neural networks barely changed. DeepSeek is trying to reinvent it.
The post Why Decade-Old Residual Connections Still Power All of AI (And Why That’s a Problem) appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3594092/ai-nachrichten/why-decade-old-residual-connections-still-power-all-of-ai-and-why-thats-a-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594092/ai-nachrichten/why-decade-old-residual-connections-still-power-all-of-ai-and-why-thats-a-problem/</guid>
<pubDate>Fri, 12 Jun 2026 18:53:32 +0200</pubDate>
<content:encoded><![CDATA[<p>For nearly a decade, this part of neural networks barely changed. DeepSeek is trying to reinvent it.</p>
<p>The post <a href="https://towardsdatascience.com/why-this-decade-old-idea-still-powers-all-of-ai-and-why-its-a-problem/">Why Decade-Old Residual Connections Still Power All of AI (And Why That’s a Problem)</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Penetration Test: Einmal im Jahr ist zu wenig]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Die Zeit der manuellen sowie zeitintensiven Security-Tests neigt sich dem Ende zu.Shutterstock – ArtemisDiana



Der alljährliche Penetrationstest (Pentest) stammt aus einer Zeit, die es in der IT-Welt so nicht mehr gibt. W...]]></description>
<link>https://tsecurity.de/de/3590918/it-security-nachrichten/penetration-test-einmal-im-jahr-ist-zu-wenig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590918/it-security-nachrichten/penetration-test-einmal-im-jahr-ist-zu-wenig/</guid>
<pubDate>Thu, 11 Jun 2026 16:39:59 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Die Zeit der manuellen sowie zeitintensiven Security-Tests neigt sich dem Ende zu.</figcaption></figure><p class="imageCredit">Shutterstock – ArtemisDiana</p></div>



<p>Der alljährliche Penetrationstest (Pentest) stammt aus einer Zeit, die es in der IT-Welt so nicht mehr gibt. Wenn Anwendungen, Cloud-Ressourcen, Konfigurationen und Schnittstellen sich laufend ändern, ist ein einzelner Prüftermin pro Jahr wie ein Selfie von vorgestern: schön anzuschauen, aber ganz schnell überholt. Als dominanter Bestandteil der IT-Security ist der Jahres-Pentest zu statisch – und im schlechtesten Fall sogar gefährlich trügerisch. Denn getestet wurde eine Realität, die kurz darauf bereits nicht mehr existiert. Hinzu kommt die antiquierte operative Realität klassischer Pentests als kosten- und zeitintensives Einzelprojekt: Scope definieren, Dienstleister auswählen, Termine abstimmen, testen, Bericht auswerten, Maßnahmen priorisieren. Das ist fachlich durchaus sinnvoll – skaliert aber schlecht. Jeder neue Testlauf erzeugt neue Koordination, neue interne Bindung und neue Reibung. Hinzu kommt ein weiteres Problem: Der Personalmangel. Laut der European Union Agency for Cybersecurity (<a href="https://www.enisa.europa.eu/sites/default/files/2025-12/NIS%20Investments%202025%20-%20Main%20report.pdf" target="_blank" rel="noreferrer noopener">ENISA</a>) haben die Unternehmen weiterhin erhebliche Schwierigkeiten, das erforderliche Cybersecurity-Personal zu finden.</p>



<p><a href="https://www.vornac.com/index_de.html" target="_blank" rel="noreferrer noopener">Mehr erfahren und VORNAC kennenlernen</a></p>



<h2 class="wp-block-heading">Security ist kein Projekt, sondern ein kontinuierlicher Prozess</h2>



<p>Als Lösung gilt allgemein der Einsatz von automatisierten Tools und Prozessen. Auch aus der Engineering-Perspektive ist dieser Wandel logisch. Das DevSecOps-Konzept fordert seit Jahren, Sicherheitsprüfungen stärker in Entwicklung und Betrieb zu integrieren – also früher, häufiger und enger am realen Lebenszyklus von Anwendungen und Infrastrukturen. Eine <a href="https://syssec.dpss.inesc-id.pt/papers/feio_eurospw24.pdf" target="_blank" rel="noreferrer noopener">Workshop-Arbeit</a> von IEEE EuroS&amp;P beschreibt DevSecOps ausdrücklich als Ansatz, der auf Continuous Security Testing setzt. Gartner fasst diesen Trend unter dem Begriff „Continuous Threat Exposure Management“ (<a href="https://www.gartner.com/en/documents/6884566" target="_blank" rel="noreferrer noopener">CTEM</a>) zusammen und meint damit ebenfalls einen systematischen Ansatz, um Angriffsfläche und Ausnutzbarkeit von Assets fortlaufend und weitgehend automatisch zu bewerten.</p>



<h2 class="wp-block-heading">Neue Anbieter sind gefragt</h2>



<p>Damit verschiebt sich der Maßstab für die Wahl eines Anbieters. Gefragt ist nicht mehr der Einzeltest, sondern ein Modell, das sich in den laufenden Betrieb einfügt: mit höherer Frequenz, weniger organisatorischer Reibung, nachvollziehbaren Ergebnissen und auditfähiger Dokumentation. Das Vertrauen in einen Anbieter entsteht in diesem Kontext nicht aus Zertifikaten oder großen Namen, sondern aus Verlässlichkeit im Alltag: klare Prozesse, reproduzierbare Ergebnisse und eine Lösung, die auch unter realen Betriebsbedingungen Bestand hat. In diesem Spannungsfeld positioniert sich der Pentest-Anbieter <a href="https://www.vornac.com/index_de.html" target="_blank" rel="noreferrer noopener">VORNAC</a>. Deren Ansatz: Pentesting nicht als gelegentliches Einmalprojekt mit langen Vorläufen, sondern als kontinuierlicher automatischer Prozess mit klar aufbereiteten Ergebnissen und auditierbaren Berichten. Laut VORNAC geht damit der Koordinationsaufwand um bis zu 90 Prozent zurück und auch die Zeiteinsparung kann bis zu 90 Prozent betragen. Bei den Tests begleitet ein zertifizierter Pentester das Projekt und hilft bei der Mitigierung und Interpretation der Findings. Außerdem kann dieser Experte anhand verschiedener Grey- und Black-Box-Tests einen validen Testplan erstellen. Was die VORNAC-Infrastruktur betrifft, so ist alles in Deutschland gehostet, denn gerade in regulierten oder sensiblen Bereichen gewinnt digitale Souveränität zunehmend an Bedeutung.</p>



<p><a href="https://www.vornac.com/index_de.html" target="_blank" rel="noreferrer noopener">Jetzt VORNAC testen</a></p>



<h2 class="wp-block-heading">Ergebnisse, die sich einordnen, priorisieren und praktisch nutzen lassen</h2>



<p>Wichtiger als das Versprechen von „mehr Automatisierung“ ist jedoch die Kombination aus technischer Anschlussfähigkeit und nachvollziehbarer Ergebnisqualität. “Mit unserem Ansatz haben wir eine weitaus höhere Coverage als bei den üblichen Pentests“, sagt VORNAC-Geschäftsführer Arthur Raess. „Wir liefern nicht nur Tool-Output, sondern Ergebnisse, die sich einordnen, priorisieren und praktisch nutzen lassen“, so Arthur Raess weiter. Das ist keine akademische Feinheit, sondern ganz entscheidend, denn zwischen einer Liste von Findings und einer belastbaren Sicherheitsbewertung liegt ein weiter Weg. Wer ihn verkürzen will, muss Ergebnisse so bereitstellen, dass sie direkt in den Sicherheits-, Audit- und Betriebsprozessen verwendet werden können.</p>



<h2 class="wp-block-heading">Referenz-Anwendung im Gesundheitswesen</h2>



<p>Wie das VORNAC-Modell in der Praxis funktioniert, zeigt das Beispiel des Referenzkunden <a href="https://mbits.info/" target="_blank" rel="noreferrer noopener">mbits</a>. Das Software-Unternehmen hat sich für VORNAC aus drei Gründen entschieden: kontinuierliche Sicherheitstests statt klassischer Einmalprojekte, klare Ergebnisse zur direkten Umsetzung und Transparenz über den eigenen Sicherheitsstatus. Gerade im Gesundheitswesen ist das mehr als ein Komfortgewinn. Es ist ein Nachweis dafür, dass Security im Alltag verlässlich, nachvollziehbar und belastbar organisiert werden kann. „Wir entwickeln Software für Krankenhäuser – da ist Sicherheit keine Option, sondern Pflicht. Unsere Partner müssen genauso hohe Ansprüche an Qualität und Verlässlichkeit haben wie wir selbst“, sagt mbits-CEO Michael Müller über die Zusammenarbeit mit VORNAC.</p>



<h2 class="wp-block-heading">Fazit</h2>



<p>Der Jahres-Pentest wird nicht von heute auf morgen verschwinden. Aber er verliert seinen Alleinanspruch. Wo die IT dynamischer, Sicherheitsressourcen knapper und Nachweise wichtiger werden, muss sich auch das Prüfmodell ändern. Aus dem jährlichen Pflichttermin wird schrittweise ein laufender Prozess moderner Sicherheitsarbeit. Neue Anbieter, wie VORNAC, die diesen Wandel in verlässliche, nachvollziehbare und betriebstaugliche Prozesse übersetzen können, positionieren sich inzwischen bei den Sicherheitsverantwortlichen als vertrauenswürdige Partner.</p>



<p><a href="https://www.vornac.com/index_de.html" target="_blank" rel="noreferrer noopener">Alles über VORNAC</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gemini LTI Update: Include your LMS sources when using NotebookLM in Powerschool Schoology]]></title>
<description><![CDATA[When creating a notebook in Powerschool Schoology, Gemini LTI users can now add content directly from their course as sources. This integration allows educators and students to seamlessly bridge their course materials with AI-powered research and analysis, and generate Studio artifacts like Audio...]]></description>
<link>https://tsecurity.de/de/3589221/web-tipps/gemini-lti-update-include-your-lms-sources-when-using-notebooklm-in-powerschool-schoology/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589221/web-tipps/gemini-lti-update-include-your-lms-sources-when-using-notebooklm-in-powerschool-schoology/</guid>
<pubDate>Thu, 11 Jun 2026 01:54:59 +0200</pubDate>
<content:encoded><![CDATA[When creating a notebook in Powerschool Schoology, Gemini LTI users can now add content directly from their course as sources. This integration allows educators and students to seamlessly bridge their course materials with AI-powered research and analysis, and generate Studio artifacts like Audio and Video Overviews, infographics, slide decks, and more based on their Schoology resources. By automating the import of Schoology course materials, users can quickly ground their notebooks in specific curriculum content without the need for manual file uploads.<div><br></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZPZaqQoQelv7pOdoeAr1N_WT4NBtHZkxrBV6P1lon4gdcm6vZxyaY6d_n4RYd0o41n2dAscalUwj06R0TEnjEkG0FGvX8dDq_JY0wKgAVmLWL6gbsBiP6iLYP7S0uOX2R5ianFkfHGVVvZSr3qi9eb9Ua1GZvw4zzCNVAArXeT-6mIfyiYaSRYaxAftw/s1728/Gemini%20LTI%20Update%20-%20Include%20your%20LMS%20sources%20when%20using%20NotebookLM%20in%20Powerschool%20Schoology.gif"><img border="0" data-original-height="994" data-original-width="1728" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZPZaqQoQelv7pOdoeAr1N_WT4NBtHZkxrBV6P1lon4gdcm6vZxyaY6d_n4RYd0o41n2dAscalUwj06R0TEnjEkG0FGvX8dDq_JY0wKgAVmLWL6gbsBiP6iLYP7S0uOX2R5ianFkfHGVVvZSr3qi9eb9Ua1GZvw4zzCNVAArXeT-6mIfyiYaSRYaxAftw/s16000/Gemini%20LTI%20Update%20-%20Include%20your%20LMS%20sources%20when%20using%20NotebookLM%20in%20Powerschool%20Schoology.gif"></a></div><h3>Getting started</h3><div><ul><li><b>Admins:</b></li><ul><li>In order for educators and students to access Gemini LTI™, you’ll need to <a href="https://support.google.com/edu/assignments/answer/14996805?hl=en" target="_blank">enable the Google Workspace LTI™ service in the Admin console</a> and <a href="https://support.google.com/a/answer/14571493?hl=en" target="_blank">enable the Gemini service in the Admin console</a>. Visit the Help Center to learn more about <a href="https://support.google.com/edu/assignments/answer/15672329" target="_blank">Gemini LTI in general</a>.</li><li>Learning Management Systems admins need to <a href="https://support.google.com/edu/assignments/answer/15672329" target="_blank">enable Gemini LTI™ in their LMS</a> as well. Visit the Help Center to learn more about <a href="https://support.google.com/edu/assignments/answer/15672142?hl=en" target="_blank">setting up Gemini LTI in Powerschool Schoology</a>.</li><li>For educators and students to use Schoology content as a source in NotebookLM, users must be in a group or OU with NotebookLM set to On. Visit the Help Center to learn more about <a href="https://support.google.com/a/answer/15239506" target="_blank">turning NotebookLM on or off for users</a>.</li></ul><li><b>End users:</b></li><ul><li>To add Schoology content notebook sources, open the Schoology homepage and select Google Gemini &gt; Manage notebooks &gt; Create new &gt; Enter a title &gt; Files &gt; Select file(s) &gt; Create notebook.</li><li>Visit the Help Center to learn more about <a href="https://support.google.com/edu/assignments/answer/15672329" target="_blank">Gemini LTI™</a>.</li></ul></ul><h3>Rollout pace</h3></div><div><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains:</a> Available now</li></ul></div><h3>Availability</h3><div><ul><li><b>Education:</b> Education Fundamentals, Standard, and Plus</li></ul></div><h3>Resources</h3><div><ul><li>Google Workspace Admin Help: <a href="https://support.google.com/edu/assignments/answer/14996805?hl=en" target="_blank">Learn how to turn on Google Workspace LTI™</a></li><li>Google Workspace Admin Help: <a href="https://support.google.com/edu/assignments/answer/15672142?hl=en" target="_blank">Set up Gemini LTI™ in PowerSchool Schoology Learning</a></li><li>Google Workspace Admin Help: <a href="https://knowledge.workspace.google.com/admin/gemini/turn-the-gemini-app-on-or-off?hl=en&amp;visit_id=639137709399432877-386770673&amp;rd=1" target="_blank">Turn the Gemini app on or off</a></li><li>Google Workspace Admin Help: <a href="http://google.com/url?q=https://support.google.com/a/answer/15239506&amp;sa=D&amp;source=docs&amp;ust=1778178576544156&amp;usg=AOvVaw12DjSgrOBTQEDNnaTBotib" target="_blank">Turn NotebookLM on or off for users</a></li><li>Google Help: <a href="https://support.google.com/edu/assignments/answer/15672329?hl=en" target="_blank">Learn about Gemini LTI</a></li></ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.8 Beta brings fixes for MSI Claw controls in Desktop Mode]]></title>
<description><![CDATA[We are hopefully (finally) getting close to the stable release of SteamOS 3.8 now, with another small Beta update with some needed fixes.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3587017/linux-tipps/steamos-388-beta-brings-fixes-for-msi-claw-controls-in-desktop-mode/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587017/linux-tipps/steamos-388-beta-brings-fixes-for-msi-claw-controls-in-desktop-mode/</guid>
<pubDate>Wed, 10 Jun 2026 10:41:52 +0200</pubDate>
<content:encoded><![CDATA[We are hopefully (finally) getting close to the stable release of SteamOS 3.8 now, with another small Beta update with some needed fixes.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/steamos-3-8-8-beta-brings-fixes-for-msi-claw-controls-in-desktop-mode/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jeff Bezos Is Funding a Wild Hunt for the Brain's 'Core Algorithm']]></title>
<description><![CDATA[Jeff Bezos is backing Flourish, a new "neuro AI" startup with $500 million in funding and a reported $2.5 billion valuation, that aims to reinvent AI by studying the brain's architecture and building systems that learn continuously while using far less power than today's large language models. Th...]]></description>
<link>https://tsecurity.de/de/3581843/it-security-nachrichten/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581843/it-security-nachrichten/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm/</guid>
<pubDate>Mon, 08 Jun 2026 17:07:13 +0200</pubDate>
<content:encoded><![CDATA[Jeff Bezos is backing Flourish, a new "neuro AI" startup with $500 million in funding and a reported $2.5 billion valuation, that aims to reinvent AI by studying the brain's architecture and building systems that learn continuously while using far less power than today's large language models. The company's long-term bet is that neuroscientists and AI researchers working together can uncover the brain's "core algorithm" and eventually create brain-inspired AI that runs on a tiny fraction of current compute. Wired reports: Rob Williams knows how to pitch Jeff Bezos: You write a press release as if your product has already been built. Bezos reads it and gives a thumbs up or down. Williams went through this process a lot as an executive on Amazon's "S-team," in charge of software products such as Alexa, until his departure last fall. But the pitch he made a few weeks later -- in December 2025 -- was different. Now he was collaborating with Thomas Reardon, a neuroscientist and repeat startup founder, and approaching Bezos as a funder, not a boss. Here's what Bezos, sitting on his yacht somewhere, read while Williams anxiously watched on Zoom: "Flourish is a neuro AI company that is solving the two most difficult problems facing AI today: power efficiency and continuous learning. We are building Cortex AI, the first synthetic intelligence system designed to match the computational capacity, learning efficiency, and power budget of the human brain."
 
A month later, I'm lunching with Reardon and Williams in the Flatiron neighborhood in New York City. Reardon gets right to the point. AI has dug itself into a hole, he says. Though increasingly powerful, large language models are greedy consumers of computer power and data. Though the inspiration for LLMs was rooted in biology, current frontier models have little in common with the human brain. A person uses about 20 watts of energy to process information; a single chip in an AI training cluster uses more than 30 times that amount. The hyperscalers require thousands of chips and gigawatts of energy, enough to power small cities. And those models need to suck up virtually all of what humans have written. Each new model requires more, more, more. For all of that, the models don't learn. Once you train them, they're stuck. The goal, Reardon tells me, is to build "a synthetic artificial intelligence brain that runs on 50 watts or less." It should adapt to its conditions, be as nimble as a human mind, and burn a tiny fraction of an LLM's compute power and energy. The proof of concept is thriving inside our skulls. "There's something fundamentally wrong with saying, "I need to basically read every book ever written 20 times over in order to learn English,'" Reardon says. "A human baby does it with a couple hundred thousand utterances."
 
Reardon and Williams haven't figured out yet how to build systems that match the magic of a human brain. What they have is a belief that an expert, well-resourced team -- of AI researchers and neuroscientists working essentially side by side -- can find the answer. The neuroscientists will conduct original wet lab experiments with some of the most advanced lab equipment available, to hunt for usable intel on the brain's architecture. They plan to release the models they're currently developing as near-term products on the path to a full reinvention of AI. The fuzziness of the proposal didn't bother Jeff Bezos. After reading Williams' two-pager, he chipped in $50 million. Other funding came from Lux Capital, Google Ventures, and Catalio, among others. Bezos then almost doubled his initial stake and told Reardon he'd have given more if they'd asked. Now with a war chest of $500 million and a reported valuation of $2.5 billion, Flourish just needs to invent a new way to do AI.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Jeff+Bezos+Is+Funding+a+Wild+Hunt+for+the+Brain's+'Core+Algorithm'%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F08%2F0418226%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F08%2F0418226%2Fjeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/06/08/0418226/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.7 Beta brings improvements for Intel handhelds, audio popping and other fixes]]></title>
<description><![CDATA[Valve released another update to the SteamOS 3.8 Beta bringing some great sounding improvements for upcoming Intel handhelds and other fixes.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3574634/linux-tipps/steamos-387-beta-brings-improvements-for-intel-handhelds-audio-popping-and-other-fixes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574634/linux-tipps/steamos-387-beta-brings-improvements-for-intel-handhelds-audio-popping-and-other-fixes/</guid>
<pubDate>Fri, 05 Jun 2026 09:24:32 +0200</pubDate>
<content:encoded><![CDATA[Valve released another update to the SteamOS 3.8 Beta bringing some great sounding improvements for upcoming Intel handhelds and other fixes.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/steamos-3-8-7-beta-brings-improvements-for-intel-handhelds-audio-popping-and-other-fixes/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jeff Bezos Is Funding a Wild Hunt for the Brain’s ‘Core Algorithm’]]></title>
<description><![CDATA[With $500 million in funding and a reported $2.5 billion valuation, Flourish wants to reinvent AI by putting real neurons under the microscope.]]></description>
<link>https://tsecurity.de/de/3572206/ai-nachrichten/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572206/ai-nachrichten/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm/</guid>
<pubDate>Thu, 04 Jun 2026 12:32:57 +0200</pubDate>
<content:encoded><![CDATA[With $500 million in funding and a reported $2.5 billion valuation, Flourish wants to reinvent AI by putting real neurons under the microscope.]]></content:encoded>
</item>
<item>
<title><![CDATA[The cloud strategy I helped build didn’t survive contact with AI. Here’s what we did next]]></title>
<description><![CDATA[I knew the plan was in trouble when a finance partner asked me a question I couldn’t answer cleanly.



“How much of this cloud spend is experimentation, and how much is now becoming the new normal?”



That should not have been a hard question. We had a mature cloud strategy. We had standards. W...]]></description>
<link>https://tsecurity.de/de/3562596/it-security-nachrichten/the-cloud-strategy-i-helped-build-didnt-survive-contact-with-ai-heres-what-we-did-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562596/it-security-nachrichten/the-cloud-strategy-i-helped-build-didnt-survive-contact-with-ai-heres-what-we-did-next/</guid>
<pubDate>Mon, 01 Jun 2026 12:06:44 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I knew the plan was in trouble when a finance partner asked me a question I couldn’t answer cleanly.</p>



<p>“How much of this cloud spend is experimentation, and how much is now becoming the new normal?”</p>



<p>That should not have been a hard question. We had a mature cloud strategy. We had standards. We had architecture reviews. We had cost controls, service patterns, reserved capacity, security gates and a decent story for the board. Nothing about it felt reckless. It felt grown-up. Ordered. Sensible.</p>



<p>Then AI walked in and started moving the furniture.</p>



<p>Silently. More like a slow shove. One use case here. One pilot there. A team testing copilots. Another team asking for more compute. Security was asking where the prompts were going. Legal is asking what data crossed which border. Finance stared at the bill like it had started speaking Latin.</p>



<p>Good strategies rarely die from stupidity. They die from drift. The world changes, but the logic stays parked in last year’s weather.</p>



<p>Our cloud strategy had been built for a world of applications, platforms, storage growth and ordinary bursts of demand. AI brought a different appetite. It wanted more power, faster decisions, looser experimentation, tighter controls and more adult supervision. It was like inviting a clever guest to dinner and discovering he’d also brought three wolves and an invoice.</p>



<h2 class="wp-block-heading">The strategy was sound for the game we were playing</h2>



<p>I want to be fair to the original plan because I helped build it, and because sneering at old decisions is one of the cheapest forms of hindsight.</p>



<p>The strategy solved real problems. We needed consistency across environments. We needed stronger resilience. We needed better cost discipline than the old “just move it and sort it out later” school of cloud migration. We wanted teams to build faster without having to reinvent their own religion each quarter. We wanted clearer guardrails and fewer exceptions that were hard to understand.</p>



<p>So, we created patterns. Standard hosting routes. Cost reviews. Architecture checkpoints. Shared controls. Approved services. Escalation paths. It worked. The business moved. The core platforms are held. We had enough orders to be useful and enough flexibility to avoid becoming the department of ceremonial no.</p>



<p>Underneath that plan sat a few quiet assumptions. Workloads would stay mostly familiar. Demand would rise, but in ways we could model. Costs would wobble, not convulse. Governance would keep pace with technology. Most exceptions would stay exceptional.</p>



<p>That set of assumptions was not foolish. It was built for a different climate.</p>



<h2 class="wp-block-heading">AI broke the assumptions first</h2>



<p>The mistake would be to say AI, “changed everything.” It didn’t. AI broke specific assumptions, and once those snapped, the strategy started falling apart.</p>



<ol class="wp-block-list">
<li><strong>The first break was compute.</strong> Traditional enterprise workloads usually behave like people with routines. They rise, fall and repeat. AI workloads behave more like teenagers with borrowed car keys. One experiment looks harmless. Then a model run chews through expensive resources. Then inference demand shows up in places nobody had forecast.</li>



<li><strong>The second break was data.</strong> Many firms say they have data ready for AI because they have data lakes, reports or analytics platforms. That is like saying you’re ready for surgery because you own a sharp knife. AI use depends on permission, lineage, quality, context, retention and movement. Data that seemed fine for dashboards became awkward, risky, or unusable once models were introduced.</li>



<li><strong>The third break was economics.</strong> Cloud costs had always needed watching, but AI added a new twist. You could spend real money before proving real value. Pilots looked small until they spread. A use case that seemed cheap in testing became costly when people used it. Finance hates mystery, and AI has a talent for turning cost models into abstract art.</li>



<li><strong>The fourth break was governance.</strong> Our existing controls had been built around systems, services, vendors and access. AI introduced different questions. Which prompts are being stored? Which data is being exposed? Who approved this model? What evidence supports this use case? What happens when teams adopt tools outside the approved stack because the approved stack moves too slowly?</li>
</ol>



<p>That was the point at which I stopped seeing AI as just another demand line on the platform roadmap. It had become a pressure test for our judgment.</p>



<h2 class="wp-block-heading">The trouble showed up in symptoms before it showed up in strategy decks</h2>



<p>Big strategy failures rarely arrive wearing a name badge. They come disguised as irritations.</p>



<p>First came cost surprises. Just a steady rise in bills nobody could explain with much confidence. Then came the awkward meetings. Finance wanted forecasts. Engineering wanted a room to test. Security wanted tighter control. Data teams wanted access. Everyone had a valid concern. Nobody was wrong. That almost made it worse.</p>



<p>Then came architecture drift.</p>



<p>Teams were trying to get work done. If the approved path took too long, they found another path. A hosted tool here. A side environment there. A vendor service that solved today’s problem and quietly created next quarter’s headache. You could feel the strategy starting to fragment at the edges.</p>



<p>Control gaps followed. Some teams knew exactly where their prompts went and what data they used. Others had a hazier picture. Logging varied. Review depth varied. Local workarounds multiplied. Policies still looked confident on paper, but paper is generous. Reality is less polite.</p>



<p>The hardest symptom to spot was decision fatigue. Meetings got longer. Ownership got fuzzier. People started using the same words to mean different things. “Low risk” to one group meant “good enough for a pilot.” To another, it meant “fit for regulated production.” Progress slowed. Shadow behavior grew in the dark space between demand and delay.</p>



<p>I remember one discussion about a simple internal assistant. The business wanted speed. The data team said the source material was manageable. Security asked a plain question about retention and auditability. Silence. Not hostile silence. The worst kind. The kind that tells you the room has just discovered it was working from several different maps.</p>



<p>That is when I knew we needed a reset instead of a patch.</p>



<h2 class="wp-block-heading">We changed the frame before we changed the plumbing</h2>



<p>Once you admit the plan no longer fits the conditions, pride becomes expensive.</p>



<p>Our first useful move was mental. We stopped asking, “How do we fit AI into the current cloud model?” That question trapped us. It assumed the existing model was the fixed point, and AI was the exception. In practice, AI was changing the operating conditions.</p>



<p>So, we asked a better question. What kinds of AI work are we dealing with, what do they need and what should run where, why and under which controls?</p>



<p>That shift saved us from one-size-fits-all thinking.</p>



<p>We split the workload space into clear groups. Experiments were not the same as production services. Internal assistants were not the same as high sensitivity use cases. Data-heavy model work was not the same as quick feature add-ons. Once we made those distinctions, better decisions followed. Some workloads could move fast with light review. Others needed tighter handling, clearer evidence and harder boundaries.</p>



<p>We also made trade-offs explicit.</p>



<p>Before that, teams argued in code. One side talked speed. Another talked about risk. Another cost. They were often debating values without naming them. So, we dragged the trade-offs into daylight. When do we pay more for control? When do we accept a delay for clearer evidence? When do we permit local freedom, and when do we insist on a common route?</p>



<p>As we couldn’t remove tension, we made it usable.</p>



<p>The other big shift was governance. We moved it closer to design. As working logic. Architecture, security, legal, finance and data leaders needed to shape decisions early, before file opinions after a team had already fallen in love with a tool.</p>



<h2 class="wp-block-heading">What we did next</h2>



<p>The reset became real when it changed weekly behavior.</p>



<p>We reclassified workloads using a few plain tests. How sensitive is the data? How heavy is the computing need? How much latency matters. How exposed is the use case to regulation, customer trust or public embarrassment? Each category had a preferred route. A clear one, before a perfect route.</p>



<p>We rebuilt cost visibility. Experimentation spend could no longer be hidden within general platform usage. We separated trial money from operating money. We pushed teams to tie spend to an intended outcome, beyond technical curiosity. Curiosity matters. So do receipts.</p>



<p>We tightened data pathways. We became stricter about what data could go where, under which terms and with what record. Less wandering. Fewer assumptions. Better memory.</p>



<p>We updated review thresholds. Not every use case needed a committee. Some did. The trick was to define that line before the pressure arrived. Teams need to know when they can move, when they must pause and who can break a tie.</p>



<p>We also created a regular decision forum across platform, security, data, finance and business leads. A place to resolve trade-offs fast and make decisions. That one change cut a lot of theatre. People no longer had to guess who owned the hard calls.</p>



<h2 class="wp-block-heading">What this taught me about cloud, AI and leadership</h2>



<p>I came out of this with less faith in neat architecture slides and more respect for decision design.</p>



<p>What AI did to our cloud strategy also affected leadership. It exposed paradoxes you can often keep apart in calmer times. In my CIO article, “<a href="https://www.cio.com/article/4022503/4-leadership-paradoxes-that-define-ai-adoption.html">4 leadership paradoxes that define AI adoption</a>,” I framed four tensions leaders now face: Speed and security, innovation and stability, talent and compliance, and ethics and efficiency. The piece argues that AI leadership is about learning to lead inside contradictions instead of resolving those once and for all. That is the part that stayed with me.</p>



<p>That is exactly what happened here.</p>



<p>We wanted teams to move quickly, but not so quickly that cloud spend became guesswork and controls became folklore. We wanted experimentation, but not at the price of production stability. We wanted strong technical people to explore, test and build, but not in ways that left legal, risk and security trying to reconstruct decisions after the fact. We wanted useful AI services, but not the kind that looked cheap and clever right up until they created a trust problem. No side debates. They became the work itself. The paradoxes were no longer theory. They were operating conditions.</p>



<p>That is why I no longer see cloud strategy as a platform conversation with some governance attached. It is a leadership discipline. You are not just choosing hosting patterns or cost controls. You are deciding how your organisation will behave under tension. Can you move with speed and still protect trust? Can you create room for experimentation without letting the estate drift into sprawl? Can you give talented teams the freedom they need without turning compliance into an afterthought? Can you chase efficiency without losing the ethical grip that keeps the whole thing defensible? That is the real burden of AI adoption. It pulls leadership into trade-offs that used to sit in separate meetings.</p>



<p>Boards should care more than they sometimes do. They shape spending, resilience, accountability and the company’s ability to adopt AI without behaving like a teenager left alone with a corporate card. That was the deeper lesson for me. The cloud strategy I helped build did not fail because the architecture was weak. It failed because AI changed the tensions leaders had to manage, and the old model was not built to carry that weight.</p>



<p>The cloud strategy I helped build did not survive contact with AI. I’m oddly grateful for that. It forced us to admit that a good strategy is not a monument. It is a living argument with reality.</p>



<p>The plan that survives is rarely the prettiest one, it is the one honest enough to change before the bill, the breach or the board meeting does it for you.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia's GTC Keynote in 12 Minutes video]]></title>
<description><![CDATA[Nvidia CEO Jensen Huang took the stage at GTC to unveil the new Vera Rubin AI computing platform, the Vera CPU, a new collaboration with Microsoft that promises to "reinvent" the PC and its new open source AI models.]]></description>
<link>https://tsecurity.de/de/3562319/it-nachrichten/nvidias-gtc-keynote-in-12-minutes-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562319/it-nachrichten/nvidias-gtc-keynote-in-12-minutes-video/</guid>
<pubDate>Mon, 01 Jun 2026 10:17:37 +0200</pubDate>
<content:encoded><![CDATA[Nvidia CEO Jensen Huang took the stage at GTC to unveil the new Vera Rubin AI computing platform, the Vera CPU, a new collaboration with Microsoft that promises to "reinvent" the PC and its new open source AI models.]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.6 Beta brings expanded handheld support, initial HDMI VRR for devices with native HDMI output]]></title>
<description><![CDATA[SteamOS 3.8.6 Beta is out now for testing, with some exciting additions for anyone wanting to see improved hardware support.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3559129/linux-tipps/steamos-386-beta-brings-expanded-handheld-support-initial-hdmi-vrr-for-devices-with-native-hdmi-output/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559129/linux-tipps/steamos-386-beta-brings-expanded-handheld-support-initial-hdmi-vrr-for-devices-with-native-hdmi-output/</guid>
<pubDate>Sat, 30 May 2026 15:39:30 +0200</pubDate>
<content:encoded><![CDATA[SteamOS 3.8.6 Beta is out now for testing, with some exciting additions for anyone wanting to see improved hardware support.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/05/steamos-3-8-6-beta-brings-expanded-handheld-support-initial-hdmi-vrr-for-devices-with-native-hdmi-output/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why machine-speed exploits demand autonomous defense]]></title>
<description><![CDATA[When Anthropic’s Mythos model unearthed a 27-year-old OpenBSD flaw in the time it takes to brew a coffee, the “AI Vulnerability Storm” stopped being a theoretical threat and became our new reality. For years, the security industry has debated when AI would truly disrupt the exploit market. That d...]]></description>
<link>https://tsecurity.de/de/3552555/it-nachrichten/why-machine-speed-exploits-demand-autonomous-defense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552555/it-nachrichten/why-machine-speed-exploits-demand-autonomous-defense/</guid>
<pubDate>Thu, 28 May 2026 00:32:25 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When Anthropic’s Mythos model unearthed a 27-year-old OpenBSD flaw in the time it takes to brew a coffee, the “AI Vulnerability Storm” stopped being a theoretical threat and became our new reality. For years, the security industry has debated when AI would truly disrupt the exploit market. That debate is over. We are now defending against an adversary that doesn’t sleep, doesn’t get bored, and scans code at industrialised speeds.</p>



<p><strong>The death of the grace period</strong></p>



<p>We used to have the luxury of time, which is easy to say in hindsight. The traditional defensive playbook was a predictable rhythm: a CVE is released, you grab a coffee, raise some tickets, and your team spends the next few weeks “prioritising” the patch. I have worked in vulnerability management, and I know that is a huge oversimplification, but in comparison, that’s how it feels. You relied on the grace period between a vulnerability being announced and a reliable exploit hitting the wild.</p>



<p>Mythos just set that playbook on fire. </p>



<p>When a frontier model can scan your entire external attack surface and draft a working exploit in minutes, your 14-day or 30-day patching cycle isn’t a strategy, it’s a liability. The Australian Cyber Security Centre’s (ACSC) recent findings confirm this: while AI isn’t yet a “sentient hacker” capable of complex, end-to-end strategic takeovers, it is terrifyingly good at the “boring” parts of the tradecraft, such as reconnaissance, code analysis, and rapid prototyping.</p>



<p>Currently, the real threat isn’t an AI brain; the threat is the machine-speed collapse of the exploit window.</p>



<p><strong>System design is the real vulnerability</strong></p>



<p>I’ve realised a hard truth recently: If your entire security posture fails because of a single unpatched vulnerability, patching isn’t your problem. Your system design is.</p>



<p>Brittle systems rely on the absence of flaws. They are houses of cards waiting for the next CVE to blow them over. Resilient systems assume flaws are inevitable. We have to move past a defensive posture and start building a Modern Defensible Architecture (MDA).</p>



<p>This isn’t just my opinion. The Cloud Security Alliance (CSA) recently issued 11 Priority Actions for a “Mythos-ready” world, and they align perfectly with the ACSC’s direction on MDA. The message is clear: Security is no longer about fixing a bug. It is an architectural mandate to ensure that no single failure leads to a catastrophe.</p>



<p><strong>The counter-move: Turning speed against the machine</strong></p>



<p>If we can’t out-patch the machine, we have to out-architect it. A Modern Defensible Architecture relies on Zero Trust as the floor, but it uses Deception as the walls. This is where it gets interesting. Under CSA Priority Action #9, there is a clear push to move toward active defense (90-day clock in fact). In a traditional network, a compromised server is a foothold. In a defensible architecture, that server is surrounded by honeypots, tokens, and decoy pathways. </p>



<p>When an AI-driven tool like Mythos scans your environment, it doesn’t just see your assets; it sees a hall of mirrors. Because the AI moves at machine speed, it is actually more likely to trip a deception element than a human attacker would. </p>



<p>This creates what we call a “High-Fidelity Signal”. A touch on a decoy isn’t a “maybe” alert; it’s a definitive indicator of intent. This allows for Action #10: Automated Containment. When seconds count, you can’t wait for a human analyst to get to this in their queue and verify an alert. You need the architecture to recognise the threat and shut down the endpoint/segment automatically.</p>



<p><strong>The shift</strong></p>



<p>To move from reactive patching to a Modern Defensible Architecture, organisations must first focus on eradicating the external attack surface by moving applications behind a Zero Trust framework. By making internal assets invisible to the public internet and eliminating open “listeners,” you effectively deprive models like Mythos of the reconnaissance data they need to draft an exploit. This aligns with CSA Priority Actions #1 and #5, shifting the goal from “patching everything” to “hiding everything” so that a vulnerability cannot be reached in the first place.</p>



<p>Second, we must saturate the environment with active deception, deploying honeypots, tokens, and decoy pathways that turn an AI’s industrialised scanning speed into its own undoing. As outlined in CSA Action #9, a defensible architecture should function like a hall of mirrors. Because an AI probes at machine speed, it is statistically far more likely to interact with a decoy than a human attacker would. This creates the “High-Fidelity Signal” necessary to distinguish a legitimate system failure from a targeted, machine-led intrusion.</p>



<p>Finally, organisations must mandate automated containment to counter the total collapse of the exploit window. In a world where Mythos can weaponize a flaw in minutes, manual triage is a legacy process we can no longer afford. Following CSA Action #10, the architecture must be empowered to instantly isolate endpoints or revoke sessions the moment a high-confidence threat is detected. By moving from “Human-in-the-loop” to “Human-over-the-loop” for containment, we ensure that our defensive response finally matches the velocity of the adversary.</p>



<p><strong>The clock is ticking</strong></p>



<p>The Mythos era doesn’t require us to reinvent security, but it does require us to stop pretending that faster patching is a sustainable path forward. Nobody is saying patching doesn’t matter, but if it’s the foundation that the system is built on, you’re already behind.</p>



<p>Organisations need to get off the endless treadmill of CVE remediation and start building Modern Defensible Architectures. By combining Zero Trust with active Deception, we create systems that don’t just resist attacks, they defend against them autonomously.</p>



<p>The goal isn’t to build a ship that never leaks. The goal is to build a ship so well-compartmentalised that even when a hull plate fails, the mission continues. The CSA gave us the blueprint. Mythos gave us the deadline. It’s time to stop fighting the storm and start building better ships.</p>



<p>To learn more, visit us <a href="https://www.zscaler.com/?utm_source=google&amp;utm_medium=cpc&amp;utm_term=b-zscaler&amp;utm_campaign=194372733" target="_blank" rel="sponsored">here</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11: Fehler blockiert seit Monaten alle Updates, Nutzer hängen fest]]></title>
<description><![CDATA[Probleme mit Windows-Updates sind an sich nichts Neues und können immer wieder auftreten. Aktuell plagt ein ärgerlicher Bug aber bestimmte Windows-11-Nutzer, die seit Monaten gar keine Patches mehr erhalten.



Wie die Seite Bleepingcomputer berichtet, trat der Fehler nach der Installation des Ja...]]></description>
<link>https://tsecurity.de/de/3535989/it-nachrichten/windows-11-fehler-blockiert-seit-monaten-alle-updates-nutzer-haengen-fest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535989/it-nachrichten/windows-11-fehler-blockiert-seit-monaten-alle-updates-nutzer-haengen-fest/</guid>
<pubDate>Thu, 21 May 2026 12:47:29 +0200</pubDate>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Probleme mit Windows-Updates sind an sich nichts Neues und können immer wieder auftreten. Aktuell plagt ein ärgerlicher Bug aber bestimmte Windows-11-Nutzer, die seit Monaten gar keine Patches mehr erhalten.</p>



<p>Wie die Seite <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-patching-issues-in-restricted-windows-networks/" target="_blank" rel="noreferrer noopener">Bleepingcomputer</a> berichtet, trat der Fehler nach der Installation des Januar-Preview-Updates auf. Das bedeutet, dass Betroffene seit Februar<strong> kein einziges</strong> Windows-Update erhalten haben. Auch die monatlichen Sicherheitspatches erhielten sie nicht, was ein großes Risiko darstellt.</p>



<p>Damit einher geht noch ein weiteres Problem, <a href="https://www.pcwelt.de/article/3033338/wichtige-windows-11-zertifikate-laufen-ab-so-pruefen-sie-secure-boot.html" target="_blank" rel="noreferrer noopener">denn aktuell verteilt Microsoft über die Windows-Updates auch wichtige Secure-Boot-Zertifikate</a>, die bis allerspätestens Juni auf allen Rechnern vorhanden sein müssen, die den sicheren Systemstart nutzen wollen. <a href="https://www.pcwelt.de/article/3059801/alarm-ihr-windows-pc-bekommt-ab-sommer-echte-probleme-secure-boot-zertifikate.html" target="_blank" rel="noreferrer noopener">Ansonsten kann es zu ernsten Problemen kommen.</a></p>



<h2 class="wp-block-heading">So erkennen Sie das Problem</h2>



<p>Microsoft informiert aktuell über das Windows-Admin-Portal über die Probleme. Laut Bleepingcomputer werden neue verfügbare Patches zwar über Windows Update angezeigt, können aber nicht erfolgreich heruntergeladen werden. Beim Update-Vorgang brechen betroffene PCs ständig ab und zeigen den Fehlercode 0x80010002 an.</p>



<p>Sie können außerdem über die Einstellungen unter dem Punkt <em>Windows Update</em> und dann <em>Updateverlauf anzeigen</em> nachsehen, welche Windows-Updates zuletzt installiert wurden. Wenn alle Updates seit Januar fehlen und Sie nicht selbst eingestellt haben, <a href="https://www.pcwelt.de/article/3030606/deaktivieren-sie-windows-updates-um-ihren-pc-genauer-zu-kontrollieren.html" target="_blank" rel="noreferrer noopener">dass Windows Updates pausiert werden sollen</a>, gibt es ein Problem.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=4-0-3140667-1-0-0-0-0?x-source=4-0-3142190-1-0-0-0-0?x-source=4-0-3143341-1-0-0-0-0?x-source=4-0-3144175-1-0-0-0-0?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading">Das können Sie tun</h2>



<p>Microsoft arbeitet aktuell noch an einer übergreifenden Lösung für das Problem, hat aber immerhin erkannt, dass der Fehler offenbar mit veränderten Anforderungen bei der Zeitüberschreitung von Downloads zusammenhängt. Auch zu strenge Firewall-Regeln können dafür sorgen, dass die betroffenen PCs nicht mehr geupdatet werden können, da die Kommunikation mit den Download-Servern unterbrochen wird.</p>



<p>Aktuell können Betroffene nur einen Known-Issue-Rollback durchführen, um das Problem zu lösen. Damit verhindern Sie, dass der Fehler erneut auftritt. Verfügbar sind ein Known-Issue-Rollback für Windows 11 26H1 (<a href="https://download.microsoft.com/download/2b881d89-8630-4d6f-a316-b100094b07aa/Windows%2011%2026H1%20KB5083806%20260513_22071%20Known%20Issue%20Rollback.msi" target="_blank" rel="noreferrer noopener"><strong>KB5083806</strong></a>) und einer für Windows 11 24H2, 25H2 und Windows Server 2025 (<a href="https://download.microsoft.com/download/4c6b9e6e-5760-435f-b5ef-0ceaafc14520/Windows%2011%2024H2%2C%20Windows%2011%2025H2%20and%20Windows%20Server%202025%20KB5083631%20260513_22072%20Known%20Issue%20Rollback.msi" target="_blank" rel="noreferrer noopener"><strong>KB5083631</strong></a>).</p>



<p>Dieser Schritt ist vor allem für IT-Administratoren gedacht. Private Anwender können auch zunächst versuchen, das fehlerhafte Preview-Update von Januar zu entfernen. <a href="https://www.pcwelt.de/article/2232724/defektes-fehlerhaftes-windows-update-ruckgangig-machen.html" target="_blank" rel="noreferrer noopener">Wie Sie ein fehlerhaftes Windows-Update rückgängig machen, erklären wir hier.</a></p>



<p><a href="https://www.pcwelt.de/article/1141520/windows-update-funktioniert-nicht-so-reparieren-sie-fast-jeden-fehler.html" target="_blank" rel="noreferrer noopener">Windows-Update funktioniert nicht? So reparieren Sie (fast) jeden Fehler</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.25 and 3.8.5 Beta released - bug fixes and better dGPU video memory management]]></title>
<description><![CDATA[Valve released the latest small stable update to their Linux distro with SteamOS 3.7.25, along with SteamOS 3.8.5 Beta bringing extra fixes and enhancements.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3535476/linux-tipps/steamos-3725-and-385-beta-released-bug-fixes-and-better-dgpu-video-memory-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535476/linux-tipps/steamos-3725-and-385-beta-released-bug-fixes-and-better-dgpu-video-memory-management/</guid>
<pubDate>Thu, 21 May 2026 09:39:57 +0200</pubDate>
<content:encoded><![CDATA[Valve released the latest small stable update to their Linux distro with SteamOS 3.7.25, along with SteamOS 3.8.5 Beta bringing extra fixes and enhancements.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/05/steamos-3-7-25-and-3-8-5-beta-released-bug-fixes-and-better-dgpu-video-memory-management/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nintendo keeps finding new ways to reinvent platformers]]></title>
<description><![CDATA[In most platforming games, you're fighting against the world around you. You're trying to beat a level, nail a seemingly impossible series of jumps, or defeat a powerful boss. But even though Yoshi and the Mysterious Book uses familiar gameplay - you traverse the world by jumping, climbing, and, ...]]></description>
<link>https://tsecurity.de/de/3529194/it-nachrichten/nintendo-keeps-finding-new-ways-to-reinvent-platformers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529194/it-nachrichten/nintendo-keeps-finding-new-ways-to-reinvent-platformers/</guid>
<pubDate>Tue, 19 May 2026 15:03:14 +0200</pubDate>
<content:encoded><![CDATA[In most platforming games, you're fighting against the world around you. You're trying to beat a level, nail a seemingly impossible series of jumps, or defeat a powerful boss. But even though Yoshi and the Mysterious Book uses familiar gameplay - you traverse the world by jumping, climbing, and, uh, eating - it reframes your […]]]></content:encoded>
</item>
<item>
<title><![CDATA[CEOs’ top priorities for IT leaders today]]></title>
<description><![CDATA[For nearly every CIO, implementing AI is their No. 1 task — that’s the directive they’re getting from the corner office.



CEOs have pegged researching and implementing AI at the top of their priority lists for their CIOs, according to CIO.com’s 2026 State of the CIO Survey. That finding mirrors...]]></description>
<link>https://tsecurity.de/de/3525558/it-nachrichten/ceos-top-priorities-for-it-leaders-today/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525558/it-nachrichten/ceos-top-priorities-for-it-leaders-today/</guid>
<pubDate>Mon, 18 May 2026 12:17:45 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For nearly every CIO, implementing AI is their No. 1 task — that’s the directive they’re getting from the corner office.</p>



<p>CEOs have pegged researching and implementing AI at the top of their priority lists for their CIOs, according to <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">CIO.com’s 2026 State of the CIO Survey</a>. That finding mirrors the results in multiple other surveys and echoes CIO.com’s 2025 survey, which also found AI implementations as the top CEO priority for IT.</p>



<p>CEOs, however, have indicated that they’re no longer interested in AI experiments and proofs of concepts. They’re looking for AI initiatives that <a href="https://www.cio.com/article/4114010/2026-the-year-ai-roi-gets-real.html">deliver quantifiable value</a>. The most strategic CEOs are going further, seeking to leverage AI in transforming how their organizations work and what products and services they offer. And they expect their CIOs to create those opportunities and not merely collaborate on seizing them.</p>



<p>“CEOs want CIOs to stand up and lead on how to unlock the real value of AI, to shift from productivity gains to different value propositions,” says <a href="https://www.tcs.com/insights/authors/sankaranarayanan-shanky-viswanathan" rel="nofollow">Shanky Viswanathan</a>, head of business innovation at Tata Consultancy Services. “There’s a real opportunity for CIOs to show how AI can be used in the business.”</p>



<p>That, though, is a tall order — one that many CIOs and C-suites more broadly aren’t yet fulfilling.</p>



<p>“A lot of CIOs still struggle with identifying use cases across the enterprise where AI can make them so much better, and they still struggle with identifying the workstreams and processes and the pain points and how they can reinvent how the organization operates with AI,” says <a href="https://www.gartner.com/en/experts/jennifer-carter" rel="nofollow">Jennifer Carter</a>, a senior principal analyst in the CIO and executive leadership practice at research firm Gartner.</p>



<p>She adds: “There are limitless possibilities, but many CIOs are caught doing some catch-up in understanding the full potential of AI even as CEOs are looking at them and asking, ‘What can we do with this?’”</p>



<h2 class="wp-block-heading">What CEOs want from AI</h2>



<p>The CEO mandate to capitalize on AI is not new this year. It has been a high-level goal at many organizations since generative AI muscled its way into the enterprise with the November 2022 release of ChatGPT.</p>



<p>What’s relatively new this year is the CEO requirement for CIOs to deliver tangible ROI for the organization’s AI investments. In fact, CEOs listed “establish AI policies and ROI metrics” as a top 10 priority for CIOs this year, according to the State of the CIO Survey.</p>



<p>Viswanathan says CEOs have become frustrated that “the amount of money they spend on AI is far, far bigger than the returns. Yes, they’re getting some productivity gains. but it’s been quite fragmented.”</p>



<p>Now, after years of AI investments, CEOs have a sense of urgency to use AI to drive revenue, he and others assert. That directive aligns with other CEO priorities for IT identified in the State of the CIO survey, including help in reaching revenue growth targets and leading innovation, at No. 6 and 7 respectively.</p>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF005646" rel="nofollow">Daniel Saroff</a>, group vice president of end-user research and consulting at IDC, says his firm’s research also shows chief executives pushing IT to use AI not just for productivity gains but to drive revenue growth.</p>



<p>IDC’s C-Suite Tech Survey found over half of CIOs and CTOs globally cite AI and automation as their primary business objective.</p>



<p>“Organizations are under real pressure to change how they compete, how they develop products, and how they deliver services to customers,” Saroff says.</p>



<p>To deliver on that priority, CIOs need to move beyond the experimentation they have been doing and instead design initiatives that can be implementated at scale.</p>



<p>“It’s a more deliberate effort where we link [AI initiatives] to business outcomes,” he says. Organizations “have struggled getting from experimentation and pilots to something that actually runs in production and delivers measurable value. The transition turns out to be harder than it initially looked.”</p>



<p>There are various reasons for those struggles, Saroff says. Problems with the data that fuels AI is one. <a href="https://www.cio.com/article/4162306/data-debt-ai-value-killer.html">Technical debt</a> and <a href="https://www.cio.com/article/4022454/applying-agentic-ai-to-legacy-systems-prepare-for-these-4-challenges.html">legacy environments</a> also slow innovation and make it more expensive than anticipated. Budget pressures <a href="https://www.cio.com/article/4137661/cios-cut-it-corners-to-manufacture-budget-for-ai.html">compound the challenges</a>.</p>



<p>Additionally, he says, IT still struggles to be a business strategy partner in some organizations.</p>



<h2 class="wp-block-heading">Opportunities for the CIO</h2>



<p>Gartner research has identified similar trends in what chief executives want from IT, with technology being a top 3 strategy priority for CEOs, coming in just behind growth at No. 1 and finance (e.g., expense management) at No. 2.</p>



<p>“When we say they’re prioritizing technology, we find according to CEOs it’s about AI,” Carter says.</p>



<p>Carter, like others, says CEOs aren’t yet seeing IT deliver transformative AI initiatives. She puts some of that on CEOs, though, saying that they still think about AI in terms of productivity gains and optimization. She points to research showing that nearly all CEOs use AI to save time while only 2% are using AI for tasks, such as decision support, that drive growth.</p>



<p>This creates an opportunity for CIOs, Carter says. By identifying where AI can remake how the organization operates and what it produces, CIOs will help their CEOs win in the market.</p>



<p>“CIOs should double down on the story of the technology that will fuel high-impact, high-spotlight initiatives,” she says. “As tech execs, they have the responsibility to raise awareness on what the technology will do and to build the needed tech literacy. It’s important for CIOs to remember that they’re in the biggest wave of opportunity the role has ever seen.”</p>



<p>Some CIOs are, indeed, delivering on this, Viswanathan says.</p>



<p>“There are some tech leaders who show how AI is not a means unto itself, and they’re able to unravel the opportunities,” he says. “They’re asking, ‘Can AI unlock value for me in areas where I struggled in the past, like responding to customer demands in a different way, or rethinking how supply chain management can happen, in reimagining products?’ These technology leaders are responding to those questions with AI front and center.”</p>



<h2 class="wp-block-heading">Securing the enterprise</h2>



<p>The corporate priorities handed down to <a href="https://www.linkedin.com/in/ajaysabhlok/" target="_blank" rel="nofollow">Ajay Sabhlok</a>, CIO and CDO at tech company Rubrik, reflect the findings from CIO.com’s State of the CIO Survey.</p>



<p>“Our CEO’s goal is to reduce and eliminate the business operations bottleneck,” Sabhlok says. And the CEO’s goal for IT is “to help Rubrik gain efficiency and productivity across all business processes.”</p>



<p>IT took that message to heart, says Sabhlok, explaining that the IT team itself is the first “to pivot over to an AI first organization. The pivot means that we must adopt an AI mindset in all of our IT processes and personal productivity improvement, with the goal of achieving resource optimization.”</p>



<p>Like some CIOs who are <a href="https://www.cio.com/article/4163373/cios-bring-ai-transformation-home-to-it-workflows.html">bringing AI to IT</a>, Sabhlok is establishing AI-powered processes across engineering, architecture, FinOps, business self-service, DevOps, and user support. “That includes rolling out core AI platforms and enabling users to use them effectively in partnership with IT AI engineering for complex use cases,” he adds.</p>



<p>Another key CEO objective for Sabhlock is strengthening Rubrik’s security posture, something he’s doing in part by ensuring “efficient resolution of all identified risks and vulnerabilities” and transforming the “infrastructure across data center, cloud, and network with embedded security.”</p>



<p>Many CEOs share that agenda, as the State of the CIO Survey’s No. 2 CEO priority for IT is upgrading IT and data security to reduce corporate risk. CIOs, IT advisers, and other researchers aren’t surprised that cybersecurity is so high on CEOs’ lists, given the financial, legal, and reputational risk associated with a data breach or cyber incident.</p>



<p>“CEOs are prioritizing a strong foundation of trust, resilience, and security, especially as AI adoption increases the importance of data integrity, governance, and risk management,” says <a href="https://www.strategyand.pwc.com/gx/en/unique-solutions/capabilities-driven-strategy/speakers-corner/paul-leinwand.html" rel="nofollow">Paul Leinwand</a>, principal of enterprise and functional strategy at PwC US.</p>



<p>Viswanathan likewise has seen cybersecurity remain a top priority for CEOs.</p>



<h2 class="wp-block-heading">Priorities beyond AI and security</h2>



<p>Next-wave innovations such as quantum computing are also making appearances on some CEO priority lists, particularly among chief executives in banking, life sciences, and logistics — industries where quantum computing is already making an impact, Viswanathan says. “Those CEOs are looking for IT to talk about the potential opportunities with quantum,” he notes.</p>



<p>And he sees CEOs asking CIOs to prioritize optimization and modernization “because that gives them a significant opportunity to funnel [savings from those moves] into emerging tech.”</p>



<p>Rounding out the top five CEO priorities for IT from the State of the CIO Survey are strengthening IT and business collaboration; improving customer experience, and leading digital business/digital transformation initiatives.</p>



<p>Leinwand says those mirror what he’s seeing.</p>



<p>“[CEOs] want IT to enable enterprisewide transformation of the operating model by connecting data, workflows, and decision-making across the organization rather than operating in functional silos — and doing this in core operations and processes, not just running pilots,” he says.</p>



<p>A fundamental shift in how companies compete is what is driving these CEO priorities, as are the challenges that CEOs face in generating sustainable growth, he notes.</p>



<p>“CEOs are expecting technology to be a big enabler of expanding customer engagement, better insight development, clearer innovation programs, and to open up new revenue-creating channels through technology,” Leinwand adds.</p>



<p>CIOs are increasingly judged in their ability to deliver on all this, according to IDC’s Saroff. He points to IDC data showing that in just one year revenue generation jumped from sixth to third place as a top CIO success metric.</p>



<p>“So some CIOs are starting to be measured — or measure themselves — on business outcomes rather than just operational performance,” he adds.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OnePlus Nord CE 6 Lite First Impressions]]></title>
<description><![CDATA[At first glance, the OnePlus Nord CE 6 Lite appears to focus on practicality over flashy gimmicks, much like the Nord CE 6. There are meaningful on-paper upgrades. The design may not reinvent the wheel, but the refined matte finish and solid in-hand feel could potentially help it stand out in the...]]></description>
<link>https://tsecurity.de/de/3518341/it-nachrichten/oneplus-nord-ce-6-lite-first-impressions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3518341/it-nachrichten/oneplus-nord-ce-6-lite-first-impressions/</guid>
<pubDate>Fri, 15 May 2026 05:47:29 +0200</pubDate>
<content:encoded><![CDATA[At first glance, the OnePlus Nord CE 6 Lite appears to focus on practicality over flashy gimmicks, much like the Nord CE 6. There are meaningful on-paper upgrades. The design may not reinvent the wheel, but the refined matte finish and solid in-hand feel could potentially help it stand out in the crowded lower mid-range segment. However, can the OnePlus Nord CE 6 Lite...]]></content:encoded>
</item>
<item>
<title><![CDATA[WWDC: From NeXTStep for Apple to Apple’s next step for AI]]></title>
<description><![CDATA[As Apple heads toward next month’s Worldwide Developer Conference (WWDC), cast your mind back almost 30 years. That’s when something happened that arguably put events in motion that led to Apple becoming the company it is today. That was when Apple co-founder Steve Jobs returned to the top job at...]]></description>
<link>https://tsecurity.de/de/3511031/it-nachrichten/wwdc-from-nextstep-for-apple-to-apples-next-step-for-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3511031/it-nachrichten/wwdc-from-nextstep-for-apple-to-apples-next-step-for-ai/</guid>
<pubDate>Tue, 12 May 2026 18:17:24 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As Apple heads toward next month’s <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">Worldwide Developer Conference</a> (WWDC), cast your mind back almost 30 years. That’s when something happened that arguably put events in motion that led to Apple becoming the company it is today. That was when Apple co-founder Steve Jobs returned to the top job at WWDC 1997 — the first such event after Apple acquired NeXT.</p>



<h2 class="wp-block-heading"><strong>The big debt to NS</strong></h2>



<p>It took until 2000 to fully realize what the NeXT purchase meant; that’s when the Mac OS X Public Beta was released. The operating system has seen many twists and turns since then, but the NeXTStep OS acquisition forms the basis on which the Apple software ecosystem has been built. Mac, iPhone, iPad – even Apple Watch and Vision Pro – all share elements of it.</p>



<p>You can see its traces each time you use an application that makes use of a macOS API that uses the NS — ‘NeXTStep’ prefix. That means you’re using NeXT when you work in SwiftUI, use Apple’s core frameworks, or write code for use across different platforms in the current ecosystem. Despite the many names for Apple’s platforms, they all have a little NeXT in common.</p>



<p>The need for a new, modern operating system was critical at the time to Apple. The company had fallen into the doldrums with its classic Mac OS operating system and competitors had forged ahead, at least in marketshare. Among others, Michael Dell, Time Magazine, and almost everyone else expected the company to collapse. NeXT was the salvation, Jobs the icon, and history the prize.</p>



<h2 class="wp-block-heading"><strong>The next challenge now</strong></h2>



<p>Today’s Apple faces a fresh existential challenge, and while much of it feels media-driven, the company does need to introduce an intelligence layer around and upon its platforms, alongside the tools developers need to exploit AI within their applications. </p>



<p>Apple knows this, too, which is why it already offers Apple Intelligence APIs to developers to use in their apps. The company also knows they need a way to market those software ideas and get them into the hands of end users; that’s what the App Store provides.</p>



<p>When Apple wove NeXT into its operating system, it somehow managed to provide developers with better tools, modern, enduring foundations, frameworks and everything else needed to build an ecosystem that extends across multiple product families at a range of prices and technological advancement — from the $499 MacBook Neo to the $3,499 Vision Pro. You can build applications for any or all of these platforms using components Apple provides, along with what you bring yourself. To a great extent, all of this potential was unlocked by the acquisition of NeXTStep and its use in OS X at the turn of the century. </p>



<h2 class="wp-block-heading"><strong>Telling stories</strong></h2>



<p>No doubt, developers are eager to discover the extent to which Apple has managed to join the circle of AI development on its platforms. They surely hope for powerful new APIs to enhance their products with a new intelligence layer, even while Apple itself needs to offer developers the same thing to keep them loyal to its platforms. </p>



<p>If you squint just a little bit, the same challenges that haunted Apple in the late ‘90s echo again today. Apple wants to reinvent itself for AI without sacrificing all the benefits of its existing ecosystem. It wants to do so while making sure its developer community buys into its chosen direction. To help achieve this, it can lean heavily into its inherent hardware advantage: Not only can its products run the apps developers build, but they are also fantastic platforms to build on in the first place. All the same, it needs to convince them with a narrative that resonates, which means that while WWDC in 1997 was all about NeXTStep, WWDC 2026 is all about <a href="https://www.applemust.com/apple-announces-important-wwdc-conference-begins-june-8/" target="_blank" rel="noreferrer noopener">which steps Apple takes next</a>. </p>



<p><em>You can follow me on social media! Join me on </em><a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener"><em>BlueSky</em></a><em>,  </em><a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener"><em>LinkedIn</em></a><em>, and </em><a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener"><em>Mastodon</em></a><em>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Opinion: The AI capex conundrum]]></title>
<description><![CDATA[The AI capex debate hinges on whether AWS and other hyperscalers will see demand grow fast enough to justify massive spending — and the data to settle that argument is still about a year away. Read More]]></description>
<link>https://tsecurity.de/de/3496733/it-nachrichten/opinion-the-ai-capex-conundrum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496733/it-nachrichten/opinion-the-ai-capex-conundrum/</guid>
<pubDate>Thu, 07 May 2026 18:16:53 +0200</pubDate>
<content:encoded><![CDATA[<img width="1260" height="841" src="https://cdn.geekwire.com/wp-content/uploads/2025/06/jassy-reinvent-new-1260x841.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2025/06/jassy-reinvent-new-1260x841.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2025/06/jassy-reinvent-new-768x513.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2025/06/jassy-reinvent-new-1536x1025.jpg 1536w, https://cdn.geekwire.com/wp-content/uploads/2025/06/jassy-reinvent-new-2048x1367.jpg 2048w, https://cdn.geekwire.com/wp-content/uploads/2025/06/jassy-reinvent-new-630x421.jpg 630w" sizes="(max-width: 1260px) 100vw, 1260px"><br>The AI capex debate hinges on whether AWS and other hyperscalers will see demand grow fast enough to justify massive spending — and the data to settle that argument is still about a year away. <a href="https://www.geekwire.com/2026/opinion-the-ai-capex-conundrum/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple settlement will pay out $250 million over delayed Siri AI  — how to claim yours]]></title>
<description><![CDATA[The Apple settlement over delayed Siri AI totals a whopping $250 million. Here's how to claim your little piece of that pie. 
(via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)]]></description>
<link>https://tsecurity.de/de/3493161/ios-mac-os/apple-settlement-will-pay-out-250-million-over-delayed-siri-ai-how-to-claim-yours/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3493161/ios-mac-os/apple-settlement-will-pay-out-250-million-over-delayed-siri-ai-how-to-claim-yours/</guid>
<pubDate>Wed, 06 May 2026 17:10:41 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="780" height="439" src="https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot.jpg" class="attachment-large size-large wp-post-image" alt="Apple may reinvent Siri as a conversational AI in iOS 27" decoding="async" fetchpriority="high" srcset="https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot.jpg.webp 1365w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-400x225.jpg 400w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-350x197.jpg 350w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-768x432.jpg.webp 768w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-1020x574.jpg.webp 1020w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-400x225@2x.jpg 800w" sizes="(max-width: 780px) 100vw, 780px"></div>
<p>The Apple settlement over delayed Siri AI totals a whopping $250 million. Here's how to claim your little piece of that pie. </p>
<p>(via <a href="https://www.cultofmac.com/">Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.3 Beta gets ready for the Steam Machine and Steam Controller]]></title>
<description><![CDATA[Valve released SteamOS 3.8.3 Beta which includes a bunch of bug fixes, along with more prep work for the upcoming Steam Machine and Steam Controller.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3479801/linux-tipps/steamos-383-beta-gets-ready-for-the-steam-machine-and-steam-controller/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3479801/linux-tipps/steamos-383-beta-gets-ready-for-the-steam-machine-and-steam-controller/</guid>
<pubDate>Fri, 01 May 2026 09:53:12 +0200</pubDate>
<content:encoded><![CDATA[Valve released SteamOS 3.8.3 Beta which includes a bunch of bug fixes, along with more prep work for the upcoming Steam Machine and Steam Controller.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/05/steamos-3-8-3-beta-gets-ready-for-the-steam-machine-and-steam-controller/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Netomi raises $110 million as Accenture and Adobe bet on AI for customer service]]></title>
<description><![CDATA[Netomi, the San Francisco-based startup building AI systems for enterprise customer service, said Thursday that it has raised $110 million in new funding in a round led by Accenture Ventures, with participation from Adobe Ventures, WndrCo, Silver Lake Waterman, NAVER Ventures, Metis Strategy and ...]]></description>
<link>https://tsecurity.de/de/3477507/it-nachrichten/netomi-raises-110-million-as-accenture-and-adobe-bet-on-ai-for-customer-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477507/it-nachrichten/netomi-raises-110-million-as-accenture-and-adobe-bet-on-ai-for-customer-service/</guid>
<pubDate>Thu, 30 Apr 2026 14:18:46 +0200</pubDate>
<content:encoded><![CDATA[<p><a href="https://www.netomi.com/">Netomi</a>, the San Francisco-based startup building AI systems for enterprise customer service, said Thursday that it has raised $110 million in new funding in a round led by <a href="https://www.accenture.com/us-en/about/accenture-innovation">Accenture Ventures</a>, with participation from <a href="https://www.adobe.com/ventures.html">Adobe Ventures</a>, <a href="https://www.wndrco.com/">WndrCo</a>, <a href="https://www.slw.vc/">Silver Lake Waterman</a>, <a href="https://www.prnewswire.com/news-releases/naver-expands-startup-investments-in-silicon-valley-with-the-planned-establishment-of-naver-ventures-302475919.html">NAVER Ventures</a>, <a href="https://www.metisstrategy.com/">Metis Strategy</a> and <a href="https://fin.capital/">Fin Capital</a>. Jeffrey Katzenberg, managing partner of WndrCo and co-founder of DreamWorks, has joined the company's board. The round builds on early backing from a roster of AI luminaries that includes OpenAI co-founder Greg Brockman, Google DeepMind co-founder Demis Hassabis and Microsoft AI CEO Mustafa Suleyman.</p><p>On its face, the financing is another large AI round in a market still awash in capital. But the deal is more revealing than that. It suggests that a new line is being drawn inside enterprise AI — not between companies that have a chatbot and companies that do not, but between companies that can show AI works in the messy, brittle, heavily governed environments where large businesses actually operate, and those that still mostly shine in demos.</p><p>The market around Netomi makes the stakes clear. <a href="https://sierra.ai/">Sierra</a>, the AI agent startup led by former Salesforce co-CEO Bret Taylor, <a href="https://techcrunch.com/2025/09/04/bret-taylors-sierra-raises-350m-at-a-10b-valuation/">raised $350 million</a> at a $10 billion valuation in September 2025 and has since made three acquisitions in 2026 alone. <a href="https://www.bloomberg.com/news/articles/2026-01-28/ai-customer-support-startup-decagon-valued-at-4-5-billion">Decagon tripled its valuation</a> to $4.5 billion in January 2026 with a $250 million Series D. Salesforce, ServiceNow and Intercom are all racing to embed AI agents into their existing platforms; Intercom's Fin AI agent reportedly crossed <a href="https://thegtmnewsletter.substack.com/p/gtm-178-intercom-ai-agent-outcome-based-pricing-archana-agrawal">$100 million in annual recurring revenue</a> at $0.99 per resolution. Gartner predicts that <a href="https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025">40 percent of enterprise applications</a> will include task-specific AI agents by the end of 2026, up from less than 5 percent in 2025.</p><p>Against that backdrop, Netomi's $110 million round is not the largest in the category, but it may be the most strategically constructed. The combination of Accenture's enterprise consulting network, Adobe's dominance in digital experience management and Netomi's track record in production deployments represents a coordinated play to embed AI not as a chatbot layer on top of websites, but as the fundamental intelligence governing how entire digital experiences behave.</p><p>The company did not disclose its valuation, and in an interview tied to the announcement, Netomi executives declined to provide revenue or profitability figures. Instead, Chief Executive <a href="https://www.netomi.com/about">Puneet Mehta</a> pointed to customer economics, saying a typical large deployment can generate at least tens of millions of dollars in impact, with some customers on a path to hundreds of millions.</p><p>For technical decision-makers, though, the more important part of Thursday's news may be the partnerships attached to the money.</p><h2><b>Why Accenture and Adobe turned a venture deal into a global distribution play</b></h2><p>The structure of the deal reads like a map of how enterprise AI gets bought in 2026.</p><p>Alongside the investment, <a href="https://www.accenture.com/us-en">Accenture</a> has entered a global alliance with <a href="https://www.netomi.com/">Netomi</a> to bring the platform to its <a href="https://www.accenture.com/us-en/services/ecosystem-partners">Fortune 100 client base</a> worldwide. The alliance will involve hundreds of Accenture team members receiving training on Netomi's platform — a meaningful commitment from the world's largest consulting firm and a distribution channel that few AI startups can match. Adobe Ventures' participation comes with plans to integrate Netomi into <a href="https://business.adobe.com/products/brand-concierge.html">Adobe's Brand Concierge</a> agentic ecosystem, giving Netomi a path into the software layer many large brands already use to manage websites, content and digital journeys. <a href="https://www.metisstrategy.com/">Metis Strategy</a> brings access to CIO advisory channels. Ndidi Oteh, CEO of <a href="https://www.accenture.com/us-en/about/accenture-song-index">Accenture Song</a>, said in the press release that the partnership is designed to help clients "reinvent how they serve their customers — seamlessly, responsibly and at scale."</p><p>The result is not just more cash. It is a distribution network wrapped around a thesis.</p><p><a href="https://www.wndrco.com/team/justin-wexler">Justin Wexler</a>, a partner at WndrCo who led the firm's Series B investment in Netomi in 2021, said most companies in the customer experience space are simply swapping a human for an AI. "That's the extent of what they're building," Wexler said. "What we're doing at Netomi, particularly with the Adobe partnership, is leapfrogging that altogether — merging the two layers. You don't have a 'How can I help you?' chatbot. This is anticipating the issue and eliminating the ticket altogether."</p><p>The distinction matters because it describes a fundamentally different kind of product. Most customer service AI still sits downstream. A customer encounters a problem, opens a chat window, explains the issue and waits for a response. Even when AI speeds up that exchange, the friction has already happened. Netomi wants to move upstream, into the experience before the ticket exists.</p><p>Mehta described the idea in blunt economic terms. "Why are there so many customer service tickets? Why is $500 billion spent on human labor answering customer service phone calls, emails and chats?" he asked. "What we realized is that the world's largest companies wait for a problem to happen and then jump on it to solve it — but by that time, they've already created a lot of frustration, and it's very expensive to do that."</p><p>The answer, in Mehta's view, is not to make downstream customer service faster with AI. It is to prevent the service ticket from being created in the first place. That logic sits behind almost every strategic decision the company has made — including <a href="https://news.adobe.com/news/2026/04/adobe-expands-partner-ecosystem">the Adobe partnership</a>.</p><p>"Most important websites run on Adobe Experience Manager," Mehta said. "So we're saying, what if we bring that kind of context and awareness upstream — capturing that a customer might be affected before it even turns into a customer service ticket."</p><h2><b>The Wall Street trading floor origins behind Netomi's AI architecture</b></h2><p>To understand what Netomi is building, you have to understand where its founder came from.</p><p>Mehta, who spent his early career constructing automated trading engines on Wall Street, told VentureBeat that the founding thesis was deceptively simple. "When we started Netomi, the core thesis was that AI is going to become the new customer interface," he said. "The Transformers [paper] did not exist, so we had literally stitched together a set of different models to create the same end result."</p><p>That background in low-latency finance is not incidental. It is the intellectual architecture that undergirds everything Netomi builds. When asked what connects trading systems to customer experience platforms, Mehta drew a direct line.</p><p>"If you think about the low-latency trading world, that was the first technology application to use situational awareness and a variety of different signals at scale," he said. "There was not one signal that it was making decisions on. You needed market data feeds. You needed situational awareness. You needed news. You needed awareness of your own book of business. You needed your own risk assessment."</p><p>That multi-signal architecture, Mehta argued, translates directly to what enterprise customer experience demands. Rather than waiting passively for a customer to describe a problem — the way traditional chatbots and even most current AI agents operate — Netomi's system attempts to reconstruct the full situation before it acts. The request itself is only part of the story.</p><p>"What the customer tells you is very important, but the situation the customer is in is sometimes even more important," Mehta said. "What if we borrowed that design pattern we built for low-latency trading? Because we can probably know why the customer is calling us. And if we can know that, we could maybe even reach out to them before they reach out to us and solve the problem."</p><p>He summarized the philosophical distinction this way: "What large language models by themselves did was they essentially democratized just raw intelligence. We are democratizing context, and that changes everything."</p><p>That is a sharp line, and also a revealing one. Netomi is effectively betting that the defensible layer in enterprise AI will not be the foundation model alone. It will be the orchestration layer that turns general model capability into governed, auditable, domain-specific action.</p><p>That governed approach extends to how the platform handles risk. Netomi uses what it calls an AI authority matrix — a real-time system that defines what the AI can do autonomously and when it must escalate to a human. "It's a little bit like autonomous driving," Mehta said. The AI knows when it's approaching a boundary and pulls a human in. For regulated industries, specific endpoints can be locked to deterministic, rules-based flows while the agentic layer handles broader orchestration — and all of it is version-controlled and traceable, with metadata saved for seven years.</p><h2><b>Inside the AI system that rearranges websites and retail stores in real time</b></h2><p>The most technically ambitious element of Netomi's vision — and the one that most sharply distinguishes it from competitors — is what the company calls <a href="https://www.netomi.com/platform-overview">AI-embedded customer experience orchestration</a>. Rather than placing a chatbot in the corner of a website, Netomi's system can rearrange the website itself based on what the AI infers about each individual customer's situation.</p><p>Wexler demonstrated a live example during the interview. "As we see most deployments, companies that want to deploy AI on their websites, they throw a chatbot on the corner," he said. "If you embed agentic capabilities into the digital layer itself — and again, Adobe Experience Manager is the leading digital layer of enterprise — then you could do really unique things."</p><p>Wexler described what this looks like in practice. In a typical deployment, he said, the AI doesn't just answer questions — it reshapes the page. Based on a customer's browsing behavior, purchase history and inferred intent, the system can reorganize a product page in real time: surfacing warnings one customer needs but another doesn't, prompting a sample order at the moment of hesitation, or flagging a compatibility issue before checkout. Two customers looking at the same product might see fundamentally different pages — not because a marketing team built two versions, but because the AI is composing the experience on the fly.</p><p>"The AI is playing the role of arranging the elements of the website to cater to me and my needs," Wexler said. "It's anticipating my needs."</p><p>The implication is a shift from static web pages to something closer to generative websites — pages that reconstruct themselves around each visitor the way a good salesperson adjusts a pitch mid-conversation. It is a fundamentally different model from bolting a chat widget onto a page that otherwise looks the same for everyone.</p><p>"The AI is playing the role of arranging the elements of the website to cater to me and my needs," Wexler said. "It's anticipating my needs."</p><p>That vision already extends beyond screens. Mehta revealed that <a href="https://www.coach.com/">Coach</a>, the handbag company owned by <a href="https://www.tapestry.com/">Tapestry</a>, deployed Netomi's platform in a physical flagship store during the holiday season to help customers navigate the retail space and is now rolling it out chainwide.</p><p>The numbers Netomi is putting behind its production claims are equally ambitious. At <a href="https://www.draftkings.com/">DraftKings</a>, the company said its platform can handle traffic surging to more than 40,000 concurrent customer requests per second during major sporting events, while delivering sub-three-second response times and 98 percent intent classification accuracy. At <a href="https://www.paramount.com/">Paramount</a>, the company said it deployed across chat and voice in two weeks and then scaled through a weekend that included a major <a href="https://www.ufc.com/events">UFC event</a> and the <a href="https://www.nfl.com/playoffs/">AFC Championship</a>.</p><p>Those are company-reported numbers, and they are hard to benchmark against competitors because the industry lacks standard public reporting. But they illustrate the kind of problem Netomi wants buyers to think about. At that scale, an AI support product stops looking like a smarter FAQ bot and starts looking like a distributed systems challenge. You are not just asking whether a model can answer a question. You are asking whether an entire system can make decisions quickly, safely and consistently while traffic spikes and business rules collide.</p><h2><b>The $110 million question: can invisible AI beat the chatbot industrial complex?</b></h2><p>Whether Netomi can deliver on the full scope of its ambition — transforming from an AI customer service platform into an ambient intelligence layer that reshapes digital and physical experiences in real time — remains an open question. The company faces competitors with far larger war chests, deeper platform footprints and, in Sierra's case, a founder-level relationship with OpenAI.</p><p>But Netomi's bet is fundamentally different from what much of the field is building. While <a href="https://sierra.ai/">Sierra</a> and <a href="https://decagon.ai/">Decagon</a> race to replace human agents with AI concierges, measuring success in conversations handled, Netomi is wagering that the highest form of customer service is the interaction that never needs to happen at all.</p><p>"There are new startups trying to convince enterprises that if every customer gets a 'concierge,' if there's 'an agent for every moment,' then loyalty follows," Mehta said. "But most relationships with brands are functional. Customers don't want a conversational relationship with their airline or their bank. They want things to work — seamlessly, invisibly, without friction."</p><p>In his closing comments during the interview, Mehta warned that many companies still underestimate the operational risk of deploying immature AI into sensitive customer environments. "What large companies adopting AI don't fully realize yet is what kind of risk are they taking by adopting those platforms that are not really field tested for this kind of scale and situations," he said.</p><p>That may be the most important line in the whole announcement. Because beneath the funding round, beneath the partner logos and beneath the talk of agents and orchestration, the real question in enterprise AI remains old-fashioned: which systems can be trusted when the environment gets ugly?</p><p>"We have built this technology more like how automated trading got built, or how autonomous driving got built, compared to coming at this from just a customer service lens," Mehta said.</p><p>It is a fitting frame for a company whose founder left Wall Street to fix customer service. On the trading floor, the best systems were never the ones that made the most trades. They were the ones that knew, with precision, when not to act — and the ones nobody noticed until something went wrong and they held. Netomi's new investors are betting $110 million that the same principle applies when the person on the other end of the system is not a trader, but a customer who just wants their floor not to leak.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6 Hacks to Make Nest and Google Devices the Most Useful Things in Your Home]]></title>
<description><![CDATA[These tricks and settings tips helped reinvent how I used my Google devices. Here's how they could help you, too.]]></description>
<link>https://tsecurity.de/de/3474385/it-nachrichten/6-hacks-to-make-nest-and-google-devices-the-most-useful-things-in-your-home/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474385/it-nachrichten/6-hacks-to-make-nest-and-google-devices-the-most-useful-things-in-your-home/</guid>
<pubDate>Wed, 29 Apr 2026 14:17:40 +0200</pubDate>
<content:encoded><![CDATA[These tricks and settings tips helped reinvent how I used my Google devices. Here's how they could help you, too.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple bets on AI to reinvent iPhone photo editing in iOS 27]]></title>
<description><![CDATA[iOS 27 could use AI to make your photographs look better after you take them. It might be a highlight of the iPhone operating system upgrade.
(via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)]]></description>
<link>https://tsecurity.de/de/3472432/ios-mac-os/apple-bets-on-ai-to-reinvent-iphone-photo-editing-in-ios-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3472432/ios-mac-os/apple-bets-on-ai-to-reinvent-iphone-photo-editing-in-ios-27/</guid>
<pubDate>Tue, 28 Apr 2026 21:37:59 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="780" height="439" src="https://www.cultofmac.com/wp-content/uploads/2026/04/iPhone-photography-1440x810.jpg.webp" class="attachment-large size-large wp-post-image" alt="iOS 27 could add AI features to expand and enhance images" decoding="async" fetchpriority="high" srcset="https://www.cultofmac.com/wp-content/uploads/2026/04/iPhone-photography-1440x810.jpg.webp 1440w, https://www.cultofmac.com/wp-content/uploads/2026/04/iPhone-photography-400x225.jpg 400w, https://www.cultofmac.com/wp-content/uploads/2026/04/iPhone-photography-768x432@2x.jpg.webp 1536w, https://www.cultofmac.com/wp-content/uploads/2026/04/iPhone-photography-350x197.jpg 350w, https://www.cultofmac.com/wp-content/uploads/2026/04/iPhone-photography-768x432.jpg.webp 768w, https://www.cultofmac.com/wp-content/uploads/2026/04/iPhone-photography-1020x574.jpg.webp 1020w, https://www.cultofmac.com/wp-content/uploads/2026/04/iPhone-photography.jpg.webp 1600w, https://www.cultofmac.com/wp-content/uploads/2026/04/iPhone-photography-400x225@2x.jpg 800w" sizes="(max-width: 780px) 100vw, 780px"></div>
<p>iOS 27 could use AI to make your photographs look better after you take them. It might be a highlight of the iPhone operating system upgrade.</p>
<p>(via <a href="https://www.cultofmac.com/">Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[칼럼 | AI ROI의 진짜 변수는 기술 아닌 ‘조직 설계’]]></title>
<description><![CDATA[AI에 가장 많은 투자를 하는 조직일수록 오히려 창출하는 가치는 가장 적은 경우가 많다. 이 같은 역설은 AI가 실제로 가치를 만들어내는지에 대한 논쟁을 키우고 있다. 그러나 이는 본질적인 질문이 아니다. 업무 단위에서는 이미 충분한 근거가 축적돼 있다. 코딩, 글쓰기, 분석, 고객 지원 등 다양한 영역에서 AI가 측정 가능한 생산성 향상을 만들어낸다는 사실이 반복적으로 입증되고 있다.



다만 이러한 성과가 기업 전체의 재무 성과로 이어지지 않는 것이 문제다. MIT 연구에 따르면 전체 AI 파일럿 프로젝트의 95%가 초기...]]></description>
<link>https://tsecurity.de/de/3459870/it-security-nachrichten/ai-roi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3459870/it-security-nachrichten/ai-roi/</guid>
<pubDate>Fri, 24 Apr 2026 04:20:38 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI에 가장 많은 투자를 하는 조직일수록 오히려 창출하는 가치는 가장 적은 경우가 많다. 이 같은 역설은 AI가 실제로 가치를 만들어내는지에 대한 논쟁을 키우고 있다. 그러나 이는 본질적인 질문이 아니다. 업무 단위에서는 이미 충분한 근거가 축적돼 있다. 코딩, 글쓰기, 분석, 고객 지원 등 다양한 영역에서 AI가 측정 가능한 생산성 향상을 만들어낸다는 사실이 반복적으로 입증되고 있다.</p>



<p>다만 이러한 성과가 기업 전체의 재무 성과로 이어지지 않는 것이 문제다. <a href="https://www.artificialintelligence-news.com/wp-content/uploads/2025/08/ai_report_2025.pdf" target="_blank" rel="nofollow">MIT 연구에 따르면</a> 전체 AI 파일럿 프로젝트의 95%가 초기 단계에서 손익계산서(P&amp;L)에 의미 있는 영향을 주지 못한 것으로 나타났다. <a href="https://www.mckinsey.com/~/media/mckinsey/business%20functions/quantumblack/our%20insights/the%20state%20of%20ai/november%202025/the-state-of-ai-in-2025.pdf?shouldIndex=false" target="_blank" rel="nofollow">맥킨지</a> 역시 전체 응답 기업 가운데 약 6%에 해당하는 고성과 기업만이 AI를 통해 EBIT의 5% 이상을 창출했다고 분석했다. <a href="https://media-publications.bcg.com/The-Widening-AI-Value-Gap-Sept-2025.pdf" target="_blank" rel="nofollow">보스턴컨설팅그룹(BCG)은</a> AI 전환 프로젝트의 약 60%가 제한적이거나 실질적인 가치 창출에 실패했다고 분석했다.</p>



<p>결국 공통된 흐름은 분명하다. 파일럿 단계에서는 성과가 확인되지만, 이를 조직 전체로 확장하는 과정에서 가치가 제대로 이어지지 않는다.</p>



<p>한편 대기업과 중소기업 간 AI 도입 격차는 빠르게 좁혀지고 있다. <a href="https://advocacy.sba.gov/wp-content/uploads/2025/09/Research-Spotlight-AI-in-Business-Small-Firms-Closing-In_-092425.pdf" target="_blank" rel="nofollow">미국 중소기업청(SBA) 데이터에 따르면</a> 2023년 11월부터 2025년 8월까지 AI 도입률은 양측 모두에서 꾸준히 증가했다. 대기업은 6% 미만에서 12% 이상으로, 중소기업은 약 4%에서 8% 이상으로 상승했다. 여전히 대기업이 높은 수준을 유지하고 있지만, 중소기업의 도입 속도가 빨라지면서 격차는 점차 축소되는 추세다.</p>



<h2 class="wp-block-heading">‘엣지’에선 작동, ‘코어’에선 정체되는 AI</h2>



<p>대기업에서 AI 도입률이 빠르게 높아지고 있음에도 불구하고, 실제 운영 환경에 들어간 AI는 쉽게 자리 잡지 못한다. 수십 년간 축적된 시스템과 규제 체계, 다층적인 거버넌스, 그리고 부서 간 복잡한 의존성이 얽혀 있기 때문이다. AI는 도입 이후 보안 검토, 구매 절차, 법률 심사, 아키텍처 위원회 검토, 레거시 시스템 연동 제약 등 다양한 관문을 통과해야 한다. 각각의 절차는 필요에 의해 존재하지만, 이들이 결합되면 변화 속도를 늦추고 효과를 분산시키는 요인이 된다.</p>



<p>특정 부서 단위에서는 AI 파일럿이 성과를 보일 수 있다. 그러나 이를 조직 전체로 확장하려는 순간 기존 운영 모델과 충돌한다. 데이터 소유권, 책임 구조, 의사결정 권한이 명확하지 않을 경우 확장 비용은 더욱 커진다. 결국 제한된 환경에서 효과를 보였던 AI는 조직 단위로 확장되는 과정에서 멈춰 서고, 기대했던 가치는 규모화 과정에서 사라진다.</p>



<p>중소기업 역시 나름의 어려움을 안고 있다. 자금 흐름 제약, 제한된 인력, 고객 리스크 등이 대표적이다. 다만 의사결정 과정에서의 ‘거부 지점’은 상대적으로 적다. 예를 들어 창업자가 AI 기반 견적 자동화나 후속 고객 응대 시스템을 실험하기 위해 별도의 범부서 위원회를 구성하는 경우는 드물다.</p>



<p>의사결정은 빠르게 이뤄지고, 피드백도 짧은 주기로 반복된다. 직원 한 명이 전체 생산성에서 차지하는 비중이 크기 때문에 변화의 효과도 즉각적으로 드러난다. 5명 규모 기업이 행정 업무의 20%를 자동화하면, 그 성과는 곧바로 측정 가능하다.</p>



<p>이들의 구조적 강점은 ‘단순함’이다. 레거시 시스템이 적고 의사결정 경로가 짧으며, 다층적인 거버넌스가 상대적으로 덜하다. SaaS 기반 솔루션도 빠르게 도입하고 큰 마찰 없이 통합할 수 있다. 이러한 특성이 더 나은 의사결정을 보장하는 것은 아니지만, 실행 속도를 높이는 데는 분명한 이점으로 작용한다.</p>



<h2 class="wp-block-heading">AI ROI의 본질은 ‘조직의 준비 상태’</h2>



<p>반대로 대기업은 높은 수준의 시스템 통합 요구와 정교한 거버넌스, 분산된 책임 구조를 갖추고 있다. 이는 운영 리스크를 줄이는 데는 효과적이지만, 새로운 기술 역량을 실제 재무 성과로 전환하는 속도를 늦추는 요인이 된다. AI 파일럿이 기술적으로는 충분한 가능성을 입증하더라도, 기업 전체의 경제적 성과를 끌어올리는 데는 실패하는 이유다.</p>



<p>이 때문에 경영진은 본질적인 선택에 직면하게 된다. 그러나 많은 경우 이를 회피하려 한다. AI ROI를 단순한 기술 문제로 규정하면 IT 조직이나 데이터 팀, 혁신 부서에 위임할 수 있기 때문이다. 반면 조직 설계의 문제로 접근하면 이야기가 달라진다. 이는 전사적인 변화 없이는 해결할 수 없다.</p>



<p>AI는 구조적 문제를 해소하기보다 오히려 증폭시키는 성격을 갖는다. 의사결정 권한이 불명확하면 그 문제가 더욱 선명해지고, 데이터 거버넌스가 취약하면 리스크는 확대된다. 보상 체계가 어긋나 있다면 그 불균형 역시 더 빠르게 심화된다. 결국 업무 단위에서의 생산성 향상이 기업 전체의 수익성 개선으로 자동 연결되지 않는 이유가 여기에 있다.</p>



<p>이 같은 현상은 새로운 것이 아니다. 인터넷 도입 초기에도 유사한 흐름이 나타났다. 기술 자체는 정상적으로 작동했지만, 기존 구조 위에 이를 덧붙인 기업이 아니라 조직을 재설계한 기업이 더 큰 성과를 거뒀다.</p>



<p>현재 AI 역시 같은 패턴을 보이고 있다. ROI를 제한하는 요인은 모델 성능이 아니라, 변화를 수용하고 확장할 수 있는 조직의 준비 상태다.</p>



<p>따라서 질문은 “AI가 왜 ROI를 만들지 못하는가”가 아니다. ROI는 AI가 아니라 조직이 만들어내는 것이기 때문이다. 진짜 질문은 조직이 일하는 방식과 의사결정 구조, 거버넌스, 성과 측정 방식을 재설계할 준비가 되어 있는가에 있다.</p>



<p>이러한 변화가 없다면 AI는 주변 업무의 생산성을 높이는 도구에 머무를 가능성이 크다. 반대로 조직이 이를 수용할 수 있다면, AI는 지속 가능한 경제적 가치를 창출하는 핵심 동력으로 자리 잡게 된다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tim Cook’s legacy: a successful CEO who stumbled over AI]]></title>
<description><![CDATA[Apple’s Tim Cook was viewed as a worthy successor to Steve Jobs when he took over as CEO in August 2011, two months before Jobs’ death. 



Apple products became successful (and profitable) in many ways due to his success as COO, where he whipped company operations and supply chains into shape. C...]]></description>
<link>https://tsecurity.de/de/3457115/it-nachrichten/tim-cooks-legacy-a-successful-ceo-who-stumbled-over-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457115/it-nachrichten/tim-cooks-legacy-a-successful-ceo-who-stumbled-over-ai/</guid>
<pubDate>Thu, 23 Apr 2026 09:16:32 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple’s Tim Cook was viewed as a worthy successor to Steve Jobs when he took over as CEO in August 2011, two months before Jobs’ death. </p>



<p>Apple products became successful (and profitable) in many ways due to his success as COO, where he whipped company operations and supply chains into shape. Cook expanded the company’s product portfolio into new devices such as the Vision Pro and Apple Watch, rolled out a plethora of profitable services, and cut off failed projects like the rumored Apple car.</p>



<p>But Cook, who announced this week he will step down as CEO on Sept. 1 to become executive chairman, has one major blemish on his legacy. He missed perhaps one of the most important moments in computing history — the AI revolution. </p>



<p>Apple could still win AI war, and it now falls on incoming CEO John Ternus, formerly Apple’s senior vice president of hardware engineering, to play catch-up with AI rivals Google, Microsoft and OpenAI. </p>



<p>When ChatGPT took the world by storm in late 2022, Apple was years behind in the AI race and had to scramble to catch up. Cook’s failure is mostly attributable to Apple believing it could always go it alone when it comes to technology, said Jack Gold, principal analyst at J. Gold Associates</p>



<p>“They have a bias to doing everything in house,” Gold said.</p>



<p>The company did not believe in AI until ChatGPT emerged to take the tech industry by storm, according to a 2025 <a href="https://www.bloomberg.com/news/newsletters/2025-03-02/apple-siri-compared-with-alexa-m4-macbook-air-and-ipad-air-2025-coming-soon-m7rn2k2y">Bloomberg news report</a>, and Cook did not provide the resources needed in-house to develop an AI-powered Siri. Apple was forced in early 2025 to look at <a href="https://www.computerworld.com/article/4015667/apple-reaches-out-to-openai-anthropic-to-build-out-siri-technology.html">partnering with Anthropic and OpenAI</a> to push Siri into the AI era; in finally settled on working with Google’s Gemini.</p>



<p>The stumble was even more apparent since Apple was onto the AI trend early on, when it introduced <a href="https://machinelearning.apple.com/research/neural-engine-transformers">neural chips for AI in iPhones</a> as early as 2017. (Qualcomm introduced AI chips in its smartphone chips around the same time.)</p>



<p>At the time, the neural engine was hailed as a revolutionary development for developers to <a href="https://www.computerworld.com/article/1713122/the-latest-iphones-show-why-ai-is-the-new-electricity.html">plug AI into applications</a>. Apple wanted to use the neural chip’s matrix computing features to accelerate image and video processing, and users loved the results. </p>



<p>Then in 2024, <a href="https://www.apple.com/in/newsroom/2024/06/introducing-apple-intelligence-for-iphone-ipad-and-mac/">Apple introduced Apple Intelligence</a> to much fanfare, hoping to bring AI technology across its devices and platforms. The AI layer was based on homegrown foundation models. </p>



<p>Though it arrived nearly two years after ChatGPT, Apple Intelligence at the time offered truly innovative features. It had better OS and app integration and privacy features that kept user data secure — in part because of <a href="https://www.computerworld.com/article/2142244/wwdc-apples-private-cloud-compute-is-what-all-cloud-services-should-be.html">Private Cloud Compute</a>. Other AI providers at the time were harvesting user data to improve their AI models.</p>



<p>Behind the scenes, however, Apple leadership and technological challenges slowed the development of Apple Intelligence. Apple in 2018 had <a href="https://www.computerworld.com/article/1718116/apples-siri-the-only-search-engine-youll-need.html">hired former Google executive John Giannandrea</a> to bring AI to Apple products. Giannandrea’s leadership was largely seen as ineffective and he retired last December. In early 2026, Apple turned to former Microsoft AI leader Amar Subramanya to lead the company’s AI efforts.</p>



<p>As a result, many of the main <a href="https://www.computerworld.com/article/3842236/is-apple-intelligence-the-new-apple-maps.html">Apple Intelligence features were delayed</a>, with hopes they  would finally arrive in 2026.</p>



<p>Then in January came the partnership with Google: “The next generation of Apple Foundation Models will be based on Google’s Gemini models and cloud technology,” <a href="https://blog.google/company-news/inside-google/company-announcements/joint-statement-google-apple/">the companies said in a joint statement</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/Apple-John-Ternus-Tim-Cook.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Tim Cook and John Ternus" class="wp-image-4161378" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Incoming Apple CEO John Ternus and current CEO Tim Cook.</p></figcaption></figure><a href="http://www.apple.com/" target="_blank" class="imageCredit" rel="noopener">Apple</a></div>



<p>Now, the work for Apple’s soon-to-be CEO Ternus is clear: bring the company fully into  the AI age. “Unlike previous market inflections and transitions, Apple can’t afford to come in late to the party this time around,” said Jim McGregor, principal analyst at Tirias Research.</p>



<p>With its experience in devices and talent, Apple is well equipped to build AI into a personal experience, McGregor said. “Apple has to chart a path to reinvent the personal experience, which will drastically change devices and how we use them,” he said.</p>



<p>To succeed, Ternus will have to look at more partnerships and drop Apple’s reliance on in-house development, analysts said.</p>



<p>“When AI is moving at such a fast pace, no one company like Apple can really move fast enough to keep up,” Gold said.</p>



<p>The Google partnership is a solid step in that direction, as finding the expertise to hire the right people is a major hurdle, given the compensation package that others are offering, Gold said.</p>



<p>Whether the company has finally righted the AI ship should become clear in a little over a month at its annual Worldwide Developers Conference — the last one of the Cook era.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple is about to reinvent Siri at WWDC this year — and it might finally feel like ChatGPT]]></title>
<description><![CDATA[Apple is preparing a major Siri overhaul that brings conversational AI, a new interface, and deeper system integration to finally modernize its assistant]]></description>
<link>https://tsecurity.de/de/3454723/it-nachrichten/apple-is-about-to-reinvent-siri-at-wwdc-this-year-and-it-might-finally-feel-like-chatgpt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454723/it-nachrichten/apple-is-about-to-reinvent-siri-at-wwdc-this-year-and-it-might-finally-feel-like-chatgpt/</guid>
<pubDate>Wed, 22 Apr 2026 14:03:59 +0200</pubDate>
<content:encoded><![CDATA[Apple is preparing a major Siri overhaul that brings conversational AI, a new interface, and deeper system integration to finally modernize its assistant]]></content:encoded>
</item>
<item>
<title><![CDATA[Ways CIOs can prove to boards that AI projects will deliver]]></title>
<description><![CDATA[There’s been a wake-up call for CIOs. All the talk about perceived productivity boosts that have previously dominated conversations about AI has been replaced with a demand for measurable value from investments in emerging tech.



As MIT states that project failure rates are as high as 95%, exec...]]></description>
<link>https://tsecurity.de/de/3454331/it-security-nachrichten/ways-cios-can-prove-to-boards-that-ai-projects-will-deliver/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454331/it-security-nachrichten/ways-cios-can-prove-to-boards-that-ai-projects-will-deliver/</guid>
<pubDate>Wed, 22 Apr 2026 12:08:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There’s been a wake-up call for CIOs. All the talk about perceived productivity boosts that have previously dominated conversations about AI has been replaced with a demand for measurable value from investments in emerging tech.</p>



<p>As <a href="https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf" rel="nofollow">MIT states that project failure rates are as high as 95%</a>, executive boards are starting to question when AI will pay dividends. <a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html" rel="nofollow">PWC’s Global CEO Survey</a> shows that more than half of companies have seen neither higher revenues nor lower costs from AI, and only one in eight have achieved positive outcomes.</p>



<p>While <a href="https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026" rel="nofollow">Gartner predicts significant growth in AI spending this year</a>, John-David Lovelock, distinguished VP analyst at the research firm, says the lack of tangible returns means digital leaders are changing tack. Rather than hoping their AI explorations will produce returns, CIOs are switching to more targeted initiatives.</p>



<p>“The projects growing quickly are the ones doing business, and those initiatives include AI,” he says. “CIOs are starting to de-emphasize AI and re-emphasize business. These projects are about AI enhancing existing work and moving away from moonshot transformational projects.”</p>



<p>Lenovo’s CIO Playbook for 2026, produced with tech analyst IDC, also suggests enterprises will get serious about AI deployments this year, with explorations replaced by production-level services that drive business transformation. With boards exerting pressure for measurable returns, Ewa Zborowska, research director at IDC, says more digital leaders want to use AI to enhance, innovate, and reinvent their organizations.</p>



<p>“CIOs aren’t just considering AI out of curiosity, they want to see what they can get out of it to grow the business,” she says. “AI adoption is much more about doing new things or taking a fresh approach to creating value rather than becoming more efficient at cost-cutting.”</p>



<p>Such is the clamor for value that Richard Corbridge, CIO at property specialist Segro, suggests that <a href="https://www.cio.com/article/4137420/5-metrics-to-drive-successful-ai-outcomes.html?utm=hybrid_search">returns from AI</a> are a main digital leadership priority: “If you discover, for example, that everyone in the organization used Copilot 10 times today, that might mean they’ve been more efficient,” he says. “But what have they actually done with the time they saved? How has saving time created value?”</p>



<p>CIOs will grapple with these questions during the next 12 months. With CEOs and boards becoming impatient for returns, digital leaders are working more with their bosses to define value. Successful CIOs fine-tune their arguments to ensure their projects are backed, and then demonstrate the value of their AI initiatives to the board.</p>



<h2 class="wp-block-heading">Defining a valuable AI project</h2>



<p>What’s clear is CIOs can’t deliver outputs from AI projects without input from their enterprise peers. IDC’s Zborowska says tighter cooperation across project ownership and KPIs ensure emerging technology investments are targeted at the right places.</p>



<p>This increased interaction between digital and business leaders also changes project aims. As <a href="https://www.cio.com/article/4077477/3-key-stakeholder-questions-for-delivering-technical-change.html?utm=hybrid_search">stakeholders work closely together to generate value</a> from AI, Zborowska expects executives to seek KPIs that stretch across operational concerns.</p>



<p>“I’d bet we see more non-financial aims over the next few years,” she says. “Executives will consider things such as are employees more engaged, has their work improved in any way, are AI implementations impacting customer experiences, and are internal decisions being made more efficiently.”</p>



<p>Martin Hardy, cyber portfolio and architecture director at the UK’s Royal Mail, agrees that defining valuable AI projects is all about finding the right focus. Effective deployments target processes in distinct areas, and business stakeholders must be part of the value-defining process.</p>



<p>“If we’re making decisions about legal documentation, AI is probably not there yet,” he says. “But if we can use AI to approve holidays, for instance, that might be something because if you have rules that say no more than two people off at a time, you could use AI to check about booking holidays without having to ask everyone in the office.”</p>



<p>For CIOs seeking value-generating use cases, Gartner’s Lovelock suggests AI can deliver results in key business areas such as boosting revenue, supporting decision-making, engaging staff, and improving experiences. He says the right path to AI exploitation correlates with Gartner’s <a href="https://www.gartner.com/en/documents/6887066" rel="nofollow">enterprise technology adoption profiles</a>, which group companies into a range of categories.</p>



<p>“The folks who are furthest forward, what we call the agile leaders in technology, are much more likely to drive AI to change the business,” he says. “The laggards on the other side are more likely to take on the technology that’s given to them by incumbent software providers, and use it in a prescriptive manner.”</p>



<h2 class="wp-block-heading">Fine-tuning the use case</h2>



<p>The challenge now is for digital leaders to work with their business peers to determine a more refined approach to AI deployment. For some CIOs, the value of AI is clear but the potential risks must be considered.</p>



<p>Take Dan Keyworth, executive director of performance technology and systems at McLaren Racing, whose focus is operational stability and race-day reliability. While he says being aware of developments in generative and agentic AI is crucial, the priority is tried-and-tested technologies rather than innovations that put performance at risk.</p>



<p>“Formula One is grounded in traditional machine learning and simulation,” he says. “Developing models has been a big part of our performance journey, and since the engine already existed, gen AI is the turbo that’s bolted on with more investment in AI.”</p>



<p>For other digital leaders, like Barry Panayi, group chief data officer at insurance firm Howden, success depends on keeping the human in the loop. Yes, automation can improve customer service, but rather than replacing staff, he wants to use AI to ensure Howden’s professionals have the right insight when they interact with clients.</p>



<p>“There’s absolutely no desire to use data to drive productivity by automating what we do with our customers,” he says. “This is a business where people speak to people. Our brokers need information that can give them an edge, and prove to their clients they understand the risks and can give them the best deals.”</p>



<p>Nick Pearson, CIO at technology specialist Ricoh Europe, adds that the use case for AI at his firm is two-fold: boosting operational productivity and improving customer processes. So he’s established a tri-party AI council with the head of service operations and the commercial manager in Spain. This council explores opportunities to buy, build, and reuse emerging tech.</p>



<p>“We’ve got a strategy that looks at where AI matters, which means exploring the technology we already have to boost internal productivity,” he says. “We’ve got a lot of people who know how to code and build things in Copilot Studio and other platforms, so let’s use that to increase productivity.”</p>



<h2 class="wp-block-heading">Showing returns to the board</h2>



<p>For Gartner’s Lovelock, the key lesson for CIOs eager to generate value from AI is to work with their peers and set desired outcomes before investing. “Most people start with the idea that more is more, and if you do that, you won’t get to the idea of quality,” he says.</p>



<p>That sentiment resonates with Segro’s Corbridge, who encourages digital leaders to start conversations with other professionals by focusing on value. Ask people how investing in an AI implementation will create value for them personally, for the wider business, and the customers the organization serves.</p>



<p>He says CIOs shouldn’t try to prove that AI works, but rather concentrate on how emerging tech adds value. That definition is so critical to Segro’s way of working that the organization uses the phrase proof of value rather than <a href="https://www.cio.com/article/3965387/cios-increasingly-dump-in-house-pocs-for-commercial-ai.html?utm=hybrid_search">proof of concept</a>.</p>



<p>“Most things work, but they might be more expensive,” he says. “For example, you might be able to use AI to transform how the organization uses spreadsheets, but that project might cost you $300,000. And if you’re currently paying someone $40,000 to do that work, and they’re happy doing it, then you have to question the value.”</p>



<p>Lessons are being learned, says IDC’s Zborowska, whose firm’s research suggests that half of AI POCs now transition into production. While some people might think this success rate isn’t impressive, the quantity a year ago was 10%. After several years of AI exploration, it appears CIOs and their businesses are now firmly focused on real returns.</p>



<p>“These numbers speak to the fact that companies are being more mature and mindful in how they allocate budgets,” she says. “They also support the main theme that we’re on a journey to transformation and a maturing market for AI adoption.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond the ‘25 reasons projects fail’: Why algorithmic, continuous scenario planning addresses the root causes]]></title>
<description><![CDATA[A widely shared Template22 graphic on why projects fail prompted this article. I am using that chart as a prompt, not as evidence. The more useful question is not whether the familiar causes of failure are real. They are. The more useful question is why they keep repeating across programs, portfo...]]></description>
<link>https://tsecurity.de/de/3450849/it-security-nachrichten/beyond-the-25-reasons-projects-fail-why-algorithmic-continuous-scenario-planning-addresses-the-root-causes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3450849/it-security-nachrichten/beyond-the-25-reasons-projects-fail-why-algorithmic-continuous-scenario-planning-addresses-the-root-causes/</guid>
<pubDate>Tue, 21 Apr 2026 11:07:27 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A widely shared <a href="https://template22.com/" rel="nofollow">Template22</a> graphic on why projects fail prompted this article. I am using that chart as a prompt, not as evidence. The more useful question is not whether the familiar causes of failure are real. They are. The more useful question is why they keep repeating across programs, portfolios and enterprise transformations, even after years of investment in methods, PMOs, digital tools and AI.</p>



<p>The answer, in many cases, is not a lack of effort. It is a lack of decision logic. Enterprises still launch, govern and defend large initiatives without a planning discipline capable of calculating trade-offs, exposing constraints, modeling dependencies and recalculating the impact of change quickly enough to support real governance.</p>



<h2 class="wp-block-heading">The pattern under the pattern</h2>



<p>Most discussions of project failure start with visible symptoms, unclear scope, weak requirements, scope creep, poor communication, resource shortages, unrealistic deadlines, weak sponsorship and poor change control. Those symptoms matter, but when they recur at scale, they usually point to a deeper problem in the planning system itself. In <a href="https://www.pmi.org/about/press-media/2025/new-pmi-research-reveals-strategy-execution-gap-is-undermining-transformation-and-how-to-close-it" rel="nofollow">PMI’s 2025 research on the strategy execution gap</a>, PMI President and CEO Pierre Le Manh argued that AI will create value only when organizations can translate bold ideas into executed initiatives. In most enterprises, the gap is not ambition. The gap is conversion. Strategy is declared, portfolios are funded, work begins, yet leaders still cannot calculate trade-offs, expose constraints, model dependencies or replan fast enough when conditions change.</p>



<p>The scale of the issue is hard to dismiss. <a href="https://www.bcg.com/publications/2024/most-large-scale-tech-programs-fail-how-to-succeed" rel="nofollow">BCG’s 2024 study of large-scale technology programs</a> found that more than two-thirds are not expected to be delivered on time, within budget and within scope, and that only 30% fully meet expectations on those three dimensions. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-10-22-gartner-survey-reveals-that-only-48-percent-of-digital-initiatives-meet-or-exceed-their-business-outcome-targets" rel="nofollow">Gartner’s 2024 survey</a> found that only 48% of digital initiatives across the enterprise meet or exceed their business outcome targets. Those are not isolated execution misses. They are signs of systemic underperformance in how organizations prioritize, fund, sequence and govern change.</p>



<p>Other firms sharpen the diagnosis from different directions. <a href="https://www.mckinsey.com/capabilities/people-and-organizational-performance/our-insights/successful-transformations" rel="nofollow">McKinsey’s work on successful transformations</a> found that among companies whose transformations failed to engage line managers and frontline employees, only 3% reported success. <a href="https://www.bain.com/insights/red-is-good/" rel="nofollow">Bain’s David Michels</a> argues that “red is good,” meaning organizations perform better when risk is surfaced early rather than hidden behind reassuring dashboards. <a href="https://www.deloitte.com/us/en/insights/topics/digital-transformation/digital-acceleration-in-a-changing-world.html" rel="nofollow">Deloitte’s research on digital acceleration and strategy</a> makes the strategic requirement explicit: Digital possibilities must shape strategy, and strategy must shape digital priorities. Put together, those findings point to one conclusion. Large programs rarely fail because a single team misses a task. They fail because the enterprise cannot see the interaction of priorities, constraints, dependencies and consequences early enough to respond intelligently.</p>



<h2 class="wp-block-heading">Why this is a planning problem, not just a delivery problem</h2>



<p>At the portfolio level, failure begins when organizations select too much work, fund the wrong work or fund the right work without a realistic view of capacity, technical debt and delivery interdependencies. <a href="https://www.bcg.com/publications/2024/most-large-scale-tech-programs-fail-how-to-succeed" rel="nofollow">BCG ties poor outcomes directly</a> to inaccurate timeline and resource planning, weak end-to-end roadmaps and ineffective management of interdependencies. That is not simply a delivery problem. It is a portfolio design problem. <a href="https://www.forrester.com/blogs/transform-your-organization-with-strategic-operating-model-change/" rel="nofollow">Forrester’s 2025 work on operating model change</a> adds a related warning: Fewer than half of IT leaders say their organizations prioritize operating model adaptation, leaving strategy to collide with structures that are not built to absorb change.</p>



<p>At the governance level, failure shows up as a value problem. Traditional oversight mechanisms can collect status, enforce templates and schedule reviews, yet still fail to answer the executive question that matters most: What happens if a key dependency slips, a budget is reduced or a shared team becomes overcommitted? Bain’s “red is good” matters here because watermelon reporting, green on the outside and red underneath, is usually a sign that governance is reporting milestones instead of modeling consequences. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-10-22-gartner-survey-reveals-that-only-48-percent-of-digital-initiatives-meet-or-exceed-their-business-outcome-targets" rel="nofollow">Gartner’s survey of Digital Vanguard organizations</a> reinforces the point. The highest performing digital organizations do better when business and technology leaders are more aligned on execution and outcome ownership.</p>



<p>At the execution level, the familiar problems remain, but they look different when viewed through a planning lens. <a href="https://www.pmi.org/learning/library/en-2013-pulse-high-cost-low-performance-13512" rel="nofollow">PMI’s communications research</a> found that one out of five projects is unsuccessful due to ineffective communication, and <a href="https://www.pmi.org/learning/library/communication-method-content-in-project-9937" rel="nofollow">PMI’s later analysis of communication failures</a> linked poor communication to more than half of the projects that fail to meet business goals. The important nuance is that communication is not merely a soft skill problem. It is often a failure to express the implications of planning decisions in a form that the business can act on. An unclear scope can be a weak scenario definition. Poor requirements can reflect commitments made before constraints were visible. Scope creep is often an unmanaged consequence. Weak sponsorship often reflects weak evidence. Poor change control often means the organization can log a change but cannot calculate its ripple effects.</p>



<h2 class="wp-block-heading">Why algorithmic planning is now a governance requirement</h2>



<p>This is where the conversation needs to become more precise. Continuous scenario planning is valuable, but it only becomes decision-grade when it is supported by algorithmic planning. In large programs and portfolios, governance cannot rely on static reporting, intuition or periodic review alone. It must be able to calculate the impact of change quickly, expose hard constraints clearly and place dependencies, capacity limits, sequencing conflicts and trade-off consequences where they belong, at the center of decision-making. Without that discipline, governance is mostly a matter of interpretation. With it, governance becomes evidence-based control. That conclusion follows directly from the documented failure patterns of <a href="https://www.pmi.org/about/press-media/2025/new-pmi-research-reveals-strategy-execution-gap-is-undermining-transformation-and-how-to-close-it" rel="nofollow">PMI</a>, <a href="https://www.bcg.com/publications/2024/most-large-scale-tech-programs-fail-how-to-succeed" rel="nofollow">BCG</a>, <a href="https://www.mckinsey.com/capabilities/people-and-organizational-performance/our-insights/successful-transformations" rel="nofollow">McKinsey</a>, <a href="https://www.bain.com/insights/red-is-good/" rel="nofollow">Bain</a>, <a href="https://www.deloitte.com/us/en/insights/topics/digital-transformation/digital-acceleration-in-a-changing-world.html" rel="nofollow">Deloitte</a> and <a href="https://www.gartner.com/en/newsroom/press-releases/2024-10-22-gartner-survey-reveals-that-only-48-percent-of-digital-initiatives-meet-or-exceed-their-business-outcome-targets" rel="nofollow">Gartner</a>.</p>



<p>AI makes this requirement even more important. Used well, AI can be a powerful interface for senior leaders, helping them interrogate scenarios, surface anomalies, summarize risks and engage more directly with the planning environment. Used badly, it can do the opposite. If AI is not tightly coupled to mathematically sound planning data, explicit constraints, dependency logic and algorithmic calculations, it can turn supposition into false confidence. That is dangerous in portfolio and program governance, where plausible-sounding answers are not the same as decision-grade answers. The sequence matters. First, the organization needs a locked down, calculation based planning model with clear borders. Then AI can sit on top of that model as an accelerator, interpreter and executive interface. Without those boundaries, AI can easily magnify weak assumptions rather than expose them. This caution is consistent with <a href="https://www.pmi.org/about/press-media/2025/new-pmi-research-reveals-strategy-execution-gap-is-undermining-transformation-and-how-to-close-it" rel="nofollow">PMI’s strategy execution framing</a> and with <a href="https://www.ey.com/en_gl/ceo/ceo-outlook-global-report" rel="nofollow">EY’s 2026 CEO Outlook</a> and <a href="https://www.accenture.com/us-en/insights/accenture-invest-3-billion-ai-accelerate-clients-reinvention" rel="nofollow">Accenture’s AI reinvention thesis</a>, both of which insist that AI must be scaled with discipline and strong foundations.</p>



<p>Strategic intent is inherently directional. Governance must be exacting. The bridge between the two is algorithmic planning. It is the mechanism that translates ambition into modeled consequences by testing scenarios, exposing constraints, mapping dependencies and recalculating trade-offs as conditions change. Without that bridge, governance becomes subjective. With it, leadership can distinguish between what is desirable, what is feasible and what is now at risk. That is why constraints, dependencies and capacity should not be treated as soft considerations. They are the black-and-white rules of execution.</p>



<p>AI is most valuable when it explains a sound planning model, not when it improvises one.</p>



<h2 class="wp-block-heading">Why continuous scenario planning matters</h2>



<p>Continuous scenario planning becomes strategically important when it gives leaders a way to compare options side by side, test trade-offs before they commit, expose bottlenecks early, map dependency cascades and continuously recalculate what changes when budgets, priorities or constraints shift. That directly addresses many of the structural drivers identified above. It does not solve every reason projects fail. It does attack a large share of the root causes beneath them.</p>



<p>Seen this way, many of the familiar 25 reasons collapse into a smaller set of systemic failures. An unclear scope often results in a weak scenario definition. Poor requirements are often commitments made before constraints and dependencies were visible. Scope creep is often an unmanaged consequence. Poor communication often reflects fragmented planning logic, with business, finance and delivery working from different maps. Resource shortages are often hidden by overcommitment. Weak sponsorship often reflects weak evidence. Poor change control usually means the organization can record changes but cannot model impact. At the project level, teams can sometimes survive these problems through heroic effort. At the portfolio level, heroics stop working. Constraints win. Bottlenecks win. The question is whether leadership can see them early enough to respond intelligently.</p>



<p>PMI’s newer <a href="https://www.pmi.org/blog/project-success-vision" rel="nofollow">M.O.R.E. framework</a> supports this shift. PMI argues that project outcomes improve materially when organizations manage perceptions, own success, relentlessly reassess and expand perspective. Two of those ideas matter especially here. Relentlessly reassess describes a discipline of continuous adjustment as conditions shift. Managing perceptions requires communicating value and risk in ways stakeholders can act on. That is remarkably close to what mature continuous scenario planning should do at scale.</p>



<h2 class="wp-block-heading">Why the urgency is rising</h2>



<p>The pressure on CIOs is increasing, not falling. <a href="https://www.ey.com/en_gl/ceo/ceo-outlook-global-report" rel="nofollow">EY’s 2026 CEO Outlook</a> says leaders are pursuing growth and adaptability through bold AI transformation, with 2026 becoming a turning point as organizations move from pilots to scaled enterprise use. <a href="https://www.accenture.com/us-en/insights/accenture-invest-3-billion-ai-accelerate-clients-reinvention" rel="nofollow">Accenture</a> makes a similar point from a different angle, arguing that organizations that build strong AI foundations will be better positioned to reinvent, compete and achieve new levels of performance. Those are reasonable claims, but they do not reduce the need for disciplined planning. Faster change increases the premium on a planning system that can calculate consequences quickly and credibly. AI can accelerate analysis, summarize scenarios and improve executive access to planning insight. It cannot replace the need to govern trade offs across budgets, capacity, architecture, timing and risk. In fact, AI is only trustworthy in this context when it is tightly coupled to mathematically sound planning data, explicit constraints, dependency logic and algorithmic calculations. Otherwise, it risks producing plausible but unsupported answers.</p>



<h2 class="wp-block-heading">What CIOs should demand</h2>



<p>For CIOs, this leads to a more useful conclusion than simply restating the 25 reasons projects fail. Large programs usually fail because the enterprise cannot see and govern the interaction of those reasons in time. A modern control system for change, therefore, needs at least six capabilities: A unified planning model across priorities, budgets and capacity; side-by-side scenario comparison; interdependency mapping; early visibility into bottlenecks; continuous recalculation as conditions shift; and executive-facing summaries that turn data into decisions. Those are the capabilities that make continuous scenario planning strategically important. The question is no longer whether planning happens. It already does. The real question is whether planning remains static, fragmented and largely narrative, or whether it becomes dynamic, scenario-based and decision-grade.</p>



<p>That is the real fix hidden beneath the 25 symptoms.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Allbirds' Move To AI Has Echoes of the Dot-Com Frenzy]]></title>
<description><![CDATA[An anonymous reader quotes a report from Bloomberg, written by writer Austin Carr: Allbirds is pivoting to artificial intelligence. The San Francisco brand, whose wool running shoes were once the sneaker du jour among the tech crowd, announced last week that it was expanding into AI computing inf...]]></description>
<link>https://tsecurity.de/de/3449136/it-security-nachrichten/allbirds-move-to-ai-has-echoes-of-the-dot-com-frenzy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3449136/it-security-nachrichten/allbirds-move-to-ai-has-echoes-of-the-dot-com-frenzy/</guid>
<pubDate>Mon, 20 Apr 2026 19:22:35 +0200</pubDate>
<content:encoded><![CDATA[An anonymous reader quotes a report from Bloomberg, written by writer Austin Carr: Allbirds is pivoting to artificial intelligence. The San Francisco brand, whose wool running shoes were once the sneaker du jour among the tech crowd, announced last week that it was expanding into AI computing infrastructure. The bizarre strategic shift was immediately greeted with a surprising frenzy on Wall Street, where shares of Allbirds soared 582% last Wednesday before dropping the next day. [...] Of course, the absurdity of Allbirds' situation echoed familiar Silicon Valley tropes -- from the endless startup pivots of the 2010s to the more recent boom-and-bust cycles of arbitrarily valued crypto coins. But it immediately reminded me of the marketing ploys of the dot-com crash. After all, some of the more iconic fails ended up being retailers such as Pets.com, Webvan, etc., riding the web wave with little to show for it beyond terrible margins.
 
One particular comparison from that period stands out as relevant to Allbirds: Zap.com. The holding company behind it, Zapata Corp., had a long and convoluted history, but was essentially selling fish-oil products by the time it decided to reinvent itself as an internet portal. It amassed a variety of web properties -- in media, e-commerce, gaming and so on -- and even once tried to acquire the search engine Excite. Spoiler alert: Zap flopped. Jen Heck, then a young employee at one of Zap's up-and-coming portfolio entities, remembers how quickly the hype of that web 1.0 turned to hell. As absurd as Zapata's pivot sounds today, it seemed feasible during the excitement of the internet revolution. "We went from like, 'Wow, this life thing is just so easy,' to it all ending so suddenly," Heck recalls. The ones who survived that tech bubble, she says, actually had differentiated products and the right creative thinkers building them -- and weren't just cynically jumping on the latest hot trend. "'Internet' was the magic word then, and 'AI' is the magic word now," Heck says.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Allbirds'+Move+To+AI+Has+Echoes+of+the+Dot-Com+Frenzy%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F04%2F20%2F1647258%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F04%2F20%2F1647258%2Fallbirds-move-to-ai-has-echoes-of-the-dot-com-frenzy%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/04/20/1647258/allbirds-move-to-ai-has-echoes-of-the-dot-com-frenzy?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI doesn’t create ROI. Organizations do.]]></title>
<description><![CDATA[Organizations that invest the most in AI often capture the least value from it. That paradox is driving a growing debate about whether AI delivers value. But that’s the wrong debate. At the task level, the evidence is clear with studies consistently showing measurable productivity gains in coding...]]></description>
<link>https://tsecurity.de/de/3447875/it-security-nachrichten/ai-doesnt-create-roi-organizations-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447875/it-security-nachrichten/ai-doesnt-create-roi-organizations-do/</guid>
<pubDate>Mon, 20 Apr 2026 12:07:41 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Organizations that invest the most in AI often capture the least value from it. That paradox is driving a growing debate about whether AI delivers value. But that’s the wrong debate. At the task level, the evidence is clear with studies consistently showing measurable productivity gains in coding, writing, analysis, and customer support.</p>



<p>MIT researchers have found that <a href="https://www.artificialintelligence-news.com/wp-content/uploads/2025/08/ai_report_2025.pdf" rel="nofollow">95% of AI pilots fail to generate measurable P&amp;L</a> impact at the pilot stage. <a href="https://www.mckinsey.com/~/media/mckinsey/business%20functions/quantumblack/our%20insights/the%20state%20of%20ai/november%202025/the-state-of-ai-in-2025.pdf?shouldIndex=false" rel="nofollow">McKinsey also reports</a> only the high performers, about 6% of respondents, attribute 5% or more of EBIT to AI. And <a href="https://media-publications.bcg.com/The-Widening-AI-Value-Gap-Sept-2025.pdf" rel="nofollow">BCG</a> estimates that roughly 60% of AI transformation efforts deliver limited or no material value. The pattern is consistent: pilots succeed locally, but value rarely scales systemically.</p>



<p>Meanwhile, the adoption gap between large enterprises and SMBs has narrowed sharply. <a href="https://advocacy.sba.gov/wp-content/uploads/2025/09/Research-Spotlight-AI-in-Business-Small-Firms-Closing-In_-092425.pdf" rel="nofollow">US Small Business Administration</a> data shows that between November 2023 and August 2025, AI adoption rose steadily across both, with larger firms increasing from under 6% to over 12%, and smaller ones from about 4% to over 8%, signalling that while the former still lead, the adoption gap is narrowing as the latter accelerates adoption.</p>



<h2 class="wp-block-heading">AI works at the edge, but struggles at the core</h2>



<p>Despite rising adoption rates among large enterprises, AI doesn’t simply deploy when it enters this environment, with their decades of accumulated systems, compliance layers, governance checkpoints, and cross-functional dependencies. Once in, AI must negotiate with security reviews, procurement cycles, legal assessments, architecture boards, and <a href="https://www.cio.com/article/4085411/the-hidden-risk-of-legacy-tech-it-owning-the-inevitable-fallout.html?utm=hybrid_search">legacy integration constraints</a>. And while each layer exists for a reason, together, they slow adaptation and dilute impact.</p>



<p>Inside a function, an AI pilot may show promise, but when it attempts to scale, it encounters the operating model. Unclear data ownership, accountability, and decision rights further increase scaling costs. So what worked in a contained environment stalls in aggregation, and the value disappears at scale.</p>



<p><a href="https://www.cio.com/article/4089762/smbs-face-unique-it-roadmaps-that-ai-can-further-confound.html?utm=hybrid_search">SMBs have their own challenges</a>. They face cash flow constraints, limited staff, and customer risk, but fewer veto points. Furthermore, a founder doesn’t convene a cross-functional steering committee to experiment with AI-assisted quoting or automated follow-ups. Decisions move faster and feedback loops are shorter. Impact is visible quickly because each employee represents a meaningful percentage of total capacity. When a five-person firm automates 20% of its administrative workload, the effect is immediate and measurable.</p>



<p>Simplicity is their structural advantage and with fewer legacy systems, shorter decision paths, and less layered governance, they can adopt SaaS solutions quickly and integrate them with minimal friction. While this doesn’t guarantee better decisions, it increases speed.</p>



<h2 class="wp-block-heading">The bigger picture</h2>



<p>On the flip side, large enterprises have deep integration requirements, <a href="https://www.cio.com/article/4128980/the-struggle-for-good-ai-governance-is-real.html?utm=hybrid_search">formalized governance</a>, and distributed accountability, which reduce operational risk but also slow the conversion of new capabilities into financial outcomes. AI pilots can demonstrate technical feasibility but still fail to move the needle on enterprise economics.</p>



<p>Leadership teams, therefore, face a design choice they often prefer to avoid. As long as AI ROI is framed as a tech problem, it can be delegated to IT, data teams, or innovation labs. But an organizational design problem can’t. AI, after all, amplifies structural friction rather than eliminates it. If decision rights are unclear, AI exposes it. If data governance is weak, AI magnifies it. If incentives are misaligned, AI accelerates the misalignment. Productivity gains at the task level don’t automatically translate into margin expansion at the enterprise level.</p>



<p>This isn’t new. Early internet investments followed a similar pattern where the technology functioned, but the internet rewarded companies that reorganized around it, not those that layered it on top of existing structures.</p>



<p>The evidence today suggests a similar pattern. AI ROI isn’t constrained by model capability but by organizational readiness to absorb and scale change. So the question shouldn’t be where’s the AI ROI since organizations create ROI, not AI. The real question is can we redesign how we work, and decide, govern, and measure performance to capture it. Without that transformation, AI remains a productivity tool at the margins. With it, though, AI becomes a source of durable economic return.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Curity looks to reinvent IAM with runtime authorization for AI agents]]></title>
<description><![CDATA[In 2026, enterprise developers are building and deploying the first generation of powerful, increasingly autonomous AI agents at incredible speed. Now comes the hard part: working out how to secure them.



Vendors in the space are facing multiple challenges. To begin with, traditional identity a...]]></description>
<link>https://tsecurity.de/de/3433969/it-nachrichten/curity-looks-to-reinvent-iam-with-runtime-authorization-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433969/it-nachrichten/curity-looks-to-reinvent-iam-with-runtime-authorization-for-ai-agents/</guid>
<pubDate>Wed, 15 Apr 2026 06:02:35 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In 2026, enterprise developers are building and deploying the first generation of powerful, increasingly autonomous AI agents at incredible speed. Now comes the hard part: working out how to secure them.</p>



<p>Vendors in the space are facing multiple challenges. To begin with, traditional identity and access management (IAM) tools were never designed to secure anything as complex as agentic AI. In addition, the number of agents, both those sanctioned by the enterprise and the undocumented ‘shadow’ agents created by a new generation of powerful tools that barely existed a year ago, is increasing at unprecedented speed. And now it has started to dawn on organizations that this risks leaving yawning governance and security gaps whose weaknesses could one day return to haunt their creators.</p>



<p>While a growing list of companies, including large cloud platforms such as Okta, Ping Identity, and Microsoft’s Entra ID, is vying to fill the vacuum, a smaller competitor, Sweden’s Curity, argues that agents can’t be secured using traditional IAM. Instead, it is offering a different approach to the problem: This week, it announced <a href="https://curity.io/product/access-intelligence/" target="_blank" rel="noreferrer noopener">Access Intelligence</a>, an extension to its existing API identity and access management (IAM) platform, Identity Server.</p>



<p>The problem it addresses is that traditional IAM tools assume that applications are being accessed by human users or machine identities, governed by a one-time authentication process. But agents, which assume long chains of actions conducted at incredible speed, don’t work like this. Instead, access becomes ephemeral, complex, and non-deterministic, which is to say, hugely unpredictable. Lock them down too much and they stop working; let them run free, and weak security follows in their wake.</p>



<h2 class="wp-block-heading">Runtime enforcement</h2>



<p>Curity’s approach is to treat agents as a special type of application. Like applications, agents call APIs, MCP servers, and each other, and are credentialed using OAuth tokens. Through a feature called Token Intelligence, Curity extends the role of OAuth tokens to not simply permit access, but to carry information on the agent’s purpose and intent. In Curity’s scheme, an agent can only access resources based on that purpose.</p>



<p>Instead of using static, pre-granted permissions, agent access is granted at runtime, on-the-fly. Each requested action generates a separate token that describes the access it needs. When an agent starts a new task, it needs a new token specifying a new set of permissions. If necessary, human authorization can be required when an agent is trying to perform a high-risk action such as transferring funds.</p>



<p>“Curity has always been application-centric,” said Cofounder and CTO <a href="https://www.linkedin.com/in/ideskog/?originalSubdomain=se" target="_blank" rel="noreferrer noopener">Jacob Ideskog</a>. “Our focus has always been on how we broker access.”</p>



<h2 class="wp-block-heading">Multiple approaches to agent security</h2>



<p>Today, agent security falls into one of several camps, which include increasingly inadequate inline approaches such as API gateways and web application firewalls (WAFs), and out-of-band analysis systems that infer intent by analyzing agent behavior against a baseline.</p>



<p>Curity’s Access Intelligence, by contrast, is a self-hosted microservice that acts as a glorified IAM layer through which every agent request must pass. “Because we let an agent do something now doesn’t mean we should be allowing it to do this a minute later,” Ideskog explained.</p>



<p>Access Intelligence also uses Identity Server’s centralized token validation to ensure that developers can fire up agents or APIs without registering them. If they lack this validation, agents are isolated from real-world actions.</p>



<h2 class="wp-block-heading">Nothing does the whole job</h2>



<p>The appearance of systems such as Access Intelligence is good news for enterprises. It indicates that vendors are starting to address the problem of agent security, often by extending existing API security platforms. But that still leaves open the question of which approach to take.</p>



<p>Ideskog believes it would be a mistake to see the different approaches as mutually exclusive. Curity’s Access Intelligence can be used in combination with other layers of agent security, he emphasized. In short, no one solution can do the whole job.</p>



<p>“Up to this point, the IAM industry has focused on the identity part. But the real question is the access. Enterprises are asking their privilege access management (PAM) vendors how they’re going to deal with this [agent security] and I don’t think the PAM vendors have good answers yet,” he said.</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4158847/curity-looks-to-reinvent-iam-with-runtime-authorization-for-ai-agents.html" target="_blank">CSOonline</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Curity looks to reinvent IAM with runtime authorization for AI agents]]></title>
<description><![CDATA[In 2026, enterprise developers are building and deploying the first generation of powerful, increasingly autonomous AI agents at incredible speed. Now comes the hard part: working out how to secure them.



Vendors in the space are facing multiple challenges. To begin with, traditional identity a...]]></description>
<link>https://tsecurity.de/de/3433948/it-security-nachrichten/curity-looks-to-reinvent-iam-with-runtime-authorization-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433948/it-security-nachrichten/curity-looks-to-reinvent-iam-with-runtime-authorization-for-ai-agents/</guid>
<pubDate>Wed, 15 Apr 2026 05:37:11 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In 2026, enterprise developers are building and deploying the first generation of powerful, increasingly autonomous AI agents at incredible speed. Now comes the hard part: working out how to secure them.</p>



<p>Vendors in the space are facing multiple challenges. To begin with, traditional identity and access management (IAM) tools were never designed to secure anything as complex as agentic AI. In addition, the number of agents, both those sanctioned by the enterprise and the undocumented ‘shadow’ agents created by a new generation of powerful tools that barely existed a year ago, is increasing at unprecedented speed. And now it has started to dawn on organizations that this risks leaving yawning governance and security gaps whose weaknesses could one day return to haunt their creators.</p>



<p>While a growing list of companies, including large cloud platforms such as Okta, Ping Identity, and Microsoft’s Entra ID, is vying to fill the vacuum, a smaller competitor, Sweden’s Curity, argues that agents can’t be secured using traditional IAM. Instead, it is offering a different approach to the problem: This week, it announced <a href="https://curity.io/product/access-intelligence/" target="_blank" rel="noreferrer noopener">Access Intelligence</a>, an extension to its existing API identity and access management (IAM) platform, Identity Server.</p>



<p>The problem it addresses is that traditional IAM tools assume that applications are being accessed by human users or machine identities, governed by a one-time authentication process. But agents, which assume long chains of actions conducted at incredible speed, don’t work like this. Instead, access becomes ephemeral, complex, and non-deterministic, which is to say, hugely unpredictable. Lock them down too much and they stop working; let them run free, and weak security follows in their wake.</p>



<h2 class="wp-block-heading">Runtime enforcement</h2>



<p>Curity’s approach is to treat agents as a special type of application. Like applications, agents call APIs, MCP servers, and each other, and are credentialed using OAuth tokens. Through a feature called Token Intelligence, Curity extends the role of OAuth tokens to not simply permit access, but to carry information on the agent’s purpose and intent. In Curity’s scheme, an agent can only access resources based on that purpose.</p>



<p>Instead of using static, pre-granted permissions, agent access is granted at runtime, on-the-fly. Each requested action generates a separate token that describes the access it needs. When an agent starts a new task, it needs a new token specifying a new set of permissions. If necessary, human authorization can be required when an agent is trying to perform a high-risk action such as transferring funds.</p>



<p>“Curity has always been application-centric,” said Cofounder and CTO <a href="https://www.linkedin.com/in/ideskog/?originalSubdomain=se" target="_blank" rel="noreferrer noopener">Jacob Ideskog</a>. “Our focus has always been on how we broker access.”</p>



<h2 class="wp-block-heading">Multiple approaches to agent security</h2>



<p>Today, agent security falls into one of several camps, which include increasingly inadequate inline approaches such as API gateways and web application firewalls (WAFs), and out-of-band analysis systems that infer intent by analyzing agent behavior against a baseline.</p>



<p>Curity’s Access Intelligence, by contrast, is a self-hosted microservice that acts as a glorified IAM layer through which every agent request must pass. “Because we let an agent do something now doesn’t mean we should be allowing it to do this a minute later,” Ideskog explained.</p>



<p>Access Intelligence also uses Identity Server’s centralized token validation to ensure that developers can fire up agents or APIs without registering them. If they lack this validation, agents are isolated from real-world actions.</p>



<h2 class="wp-block-heading">Nothing does the whole job</h2>



<p>The appearance of systems such as Access Intelligence is good news for enterprises. It indicates that vendors are starting to address the problem of agent security, often by extending existing API security platforms. But that still leaves open the question of which approach to take.</p>



<p>Ideskog believes it would be a mistake to see the different approaches as mutually exclusive. Curity’s Access Intelligence can be used in combination with other layers of agent security, he emphasized. In short, no one solution can do the whole job.</p>



<p>“Up to this point, the IAM industry has focused on the identity part. But the real question is the access. Enterprises are asking their privilege access management (PAM) vendors how they’re going to deal with this [agent security] and I don’t think the PAM vendors have good answers yet,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Curity looks to reinvent IAM with runtime authorization for AI agents]]></title>
<description><![CDATA[In 2026, enterprise developers are building and deploying the first generation of powerful, increasingly autonomous AI agents at incredible speed. Now comes the hard part: working out how to secure them.



Vendors in the space are facing multiple challenges. To begin with, traditional identity a...]]></description>
<link>https://tsecurity.de/de/3433945/ai-nachrichten/curity-looks-to-reinvent-iam-with-runtime-authorization-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3433945/ai-nachrichten/curity-looks-to-reinvent-iam-with-runtime-authorization-for-ai-agents/</guid>
<pubDate>Wed, 15 Apr 2026 05:33:37 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In 2026, enterprise developers are building and deploying the first generation of powerful, increasingly autonomous AI agents at incredible speed. Now comes the hard part: working out how to secure them.</p>



<p>Vendors in the space are facing multiple challenges. To begin with, traditional identity and access management (IAM) tools were never designed to secure anything as complex as agentic AI. In addition, the number of agents, both those sanctioned by the enterprise and the undocumented ‘shadow’ agents created by a new generation of powerful tools that barely existed a year ago, is increasing at unprecedented speed. And now it has started to dawn on organizations that this risks leaving yawning governance and security gaps whose weaknesses could one day return to haunt their creators.</p>



<p>While a growing list of companies, including large cloud platforms such as Okta, Ping Identity, and Microsoft’s Entra ID, is vying to fill the vacuum, a smaller competitor, Sweden’s Curity, argues that agents can’t be secured using traditional IAM. Instead, it is offering a different approach to the problem: This week, it announced <a href="https://curity.io/product/access-intelligence/" target="_blank" rel="noreferrer noopener">Access Intelligence</a>, an extension to its existing API identity and access management (IAM) platform, Identity Server.</p>



<p>The problem it addresses is that traditional IAM tools assume that applications are being accessed by human users or machine identities, governed by a one-time authentication process. But agents, which assume long chains of actions conducted at incredible speed, don’t work like this. Instead, access becomes ephemeral, complex, and non-deterministic, which is to say, hugely unpredictable. Lock them down too much and they stop working; let them run free, and weak security follows in their wake.</p>



<h2 class="wp-block-heading">Runtime enforcement</h2>



<p>Curity’s approach is to treat agents as a special type of application. Like applications, agents call APIs, MCP servers, and each other, and are credentialed using OAuth tokens. Through a feature called Token Intelligence, Curity extends the role of OAuth tokens to not simply permit access, but to carry information on the agent’s purpose and intent. In Curity’s scheme, an agent can only access resources based on that purpose.</p>



<p>Instead of using static, pre-granted permissions, agent access is granted at runtime, on-the-fly. Each requested action generates a separate token that describes the access it needs. When an agent starts a new task, it needs a new token specifying a new set of permissions. If necessary, human authorization can be required when an agent is trying to perform a high-risk action such as transferring funds.</p>



<p>“Curity has always been application-centric,” said Cofounder and CTO <a href="https://www.linkedin.com/in/ideskog/?originalSubdomain=se" target="_blank" rel="noreferrer noopener">Jacob Ideskog</a>. “Our focus has always been on how we broker access.”</p>



<h2 class="wp-block-heading">Multiple approaches to agent security</h2>



<p>Today, agent security falls into one of several camps, which include increasingly inadequate inline approaches such as API gateways and web application firewalls (WAFs), and out-of-band analysis systems that infer intent by analyzing agent behavior against a baseline.</p>



<p>Curity’s Access Intelligence, by contrast, is a self-hosted microservice that acts as a glorified IAM layer through which every agent request must pass. “Because we let an agent do something now doesn’t mean we should be allowing it to do this a minute later,” Ideskog explained.</p>



<p>Access Intelligence also uses Identity Server’s centralized token validation to ensure that developers can fire up agents or APIs without registering them. If they lack this validation, agents are isolated from real-world actions.</p>



<h2 class="wp-block-heading">Nothing does the whole job</h2>



<p>The appearance of systems such as Access Intelligence is good news for enterprises. It indicates that vendors are starting to address the problem of agent security, often by extending existing API security platforms. But that still leaves open the question of which approach to take.</p>



<p>Ideskog believes it would be a mistake to see the different approaches as mutually exclusive. Curity’s Access Intelligence can be used in combination with other layers of agent security, he emphasized. In short, no one solution can do the whole job.</p>



<p>“Up to this point, the IAM industry has focused on the identity part. But the real question is the access. Enterprises are asking their privilege access management (PAM) vendors how they’re going to deal with this [agent security] and I don’t think the PAM vendors have good answers yet,” he said.</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4158847/curity-looks-to-reinvent-iam-with-runtime-authorization-for-ai-agents.html" target="_blank">CSOonline</a>.</em></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.2 Beta brings fixes for security issues, trackpad on Legion Go and Borderlands 2]]></title>
<description><![CDATA[We're hopefully closing in on the next big stable update for SteamOS, with Valve releasing SteamOS 3.8.2 Beta.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3431148/linux-tipps/steamos-382-beta-brings-fixes-for-security-issues-trackpad-on-legion-go-and-borderlands-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3431148/linux-tipps/steamos-382-beta-brings-fixes-for-security-issues-trackpad-on-legion-go-and-borderlands-2/</guid>
<pubDate>Tue, 14 Apr 2026 10:24:24 +0200</pubDate>
<content:encoded><![CDATA[We're hopefully closing in on the next big stable update for SteamOS, with Valve releasing SteamOS 3.8.2 Beta.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/04/steamos-3-8-2-beta-brings-fixes-for-security-issues-trackpad-on-legion-go-and-borderlands-2/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can Puck reinvent the news business for the influencer age?]]></title>
<description><![CDATA[Today, I’m talking with Sarah Personette, CEO of Puck, which is a fancy new media company that’s been around for just about five years now. Puck hires big stars and gives them newsletters that are all mostly part of a subscription bundle. These newsletters are often must-reads in their categories...]]></description>
<link>https://tsecurity.de/de/3429104/it-nachrichten/can-puck-reinvent-the-news-business-for-the-influencer-age/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3429104/it-nachrichten/can-puck-reinvent-the-news-business-for-the-influencer-age/</guid>
<pubDate>Mon, 13 Apr 2026 16:03:12 +0200</pubDate>
<content:encoded><![CDATA[Today, I’m talking with Sarah Personette, CEO of Puck, which is a fancy new media company that’s been around for just about five years now. Puck hires big stars and gives them newsletters that are all mostly part of a subscription bundle. These newsletters are often must-reads in their categories — everyone in Hollywood reads […]]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.1 now in Beta for more gamers to test new features]]></title>
<description><![CDATA[Valve have bumped SteamOS 3.8.1 from Preview to Beta, as it's now ready for more people to get testing to find any issues.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3423269/linux-tipps/steamos-381-now-in-beta-for-more-gamers-to-test-new-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3423269/linux-tipps/steamos-381-now-in-beta-for-more-gamers-to-test-new-features/</guid>
<pubDate>Fri, 10 Apr 2026 12:23:53 +0200</pubDate>
<content:encoded><![CDATA[Valve have bumped SteamOS 3.8.1 from Preview to Beta, as it's now ready for more people to get testing to find any issues.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/04/steamos-3-8-1-now-in-beta-for-more-gamers-to-test-new-features/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Terraform scaling problem: When infrastructure-as-code becomes infrastructure-as-complexity]]></title>
<description><![CDATA[Terraform promised us a better world. Define your infrastructure in code, version it, review it, and deploy it with confidence. For small teams running a handful of services, that promise holds up beautifully.



Then your organization grows. Teams multiply. Modules branch and fork. State files b...]]></description>
<link>https://tsecurity.de/de/3414087/ai-nachrichten/the-terraform-scaling-problem-when-infrastructure-as-code-becomes-infrastructure-as-complexity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3414087/ai-nachrichten/the-terraform-scaling-problem-when-infrastructure-as-code-becomes-infrastructure-as-complexity/</guid>
<pubDate>Tue, 07 Apr 2026 15:03:34 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Terraform promised us a better world. Define your infrastructure in code, version it, review it, and deploy it with confidence. For small teams running a handful of services, that promise holds up beautifully.</p>



<p>Then your organization grows. Teams multiply. Modules branch and fork. State files balloon. And suddenly, that clean declarative vision starts looking a lot like a sprawling monolith that nobody fully understands and everyone is afraid to touch.</p>



<p>If you’ve ever watched a Terraform plan run for 20 minutes, encountered a corrupted state file at 2 a.m. or inherited a Terraform codebase where half the resources are undocumented and a quarter are unmanaged, you know exactly what we’re talking about. This is the Terraform scaling problem, and it’s affecting engineering organizations of every size.</p>



<p>The numbers confirm it isn’t a niche concern. The<a href="https://thenewstack.io/terraform-providers-and-the-rise-of-infrastructure-as-a-service/"> </a><a href="https://thenewstack.io/terraform-providers-and-the-rise-of-infrastructure-as-a-service/">2023 State of IaC Report</a> found that 90% of cloud users are already using infrastructure-as-code, with Terraform commanding 76% market share according to the<a href="https://www.cncf.io/reports/cncf-annual-survey-2024/"> </a><a href="https://www.cncf.io/reports/cncf-annual-survey-2024/">CNCF 2024 Annual Survey</a>. Yet the<a href="https://www.hashicorp.com/state-of-the-cloud"> </a><a href="https://www.hashicorp.com/state-of-the-cloud">HashiCorp State of Cloud Strategy Survey 2024</a> showed that 64% of organizations report a shortage of skilled cloud and automation staff, creating a dangerous gap between Terraform’s adoption and the expertise required to operate it well at scale.</p>



<p>In this post, we break down where Terraform breaks down, why traditional solutions fall short, and how AI-assisted IaC management is offering a credible path forward.</p>



<h2 class="wp-block-heading"><a></a>The root causes of Terraform complexity at scale</h2>



<p>Terraform’s design philosophy is fundamentally sound: Declarative infrastructure, idempotent operations and a provider ecosystem that covers nearly every cloud service imaginable. The problem isn’t the tool; it’s the gap between how Terraform was designed to work and how large engineering organizations actually operate.</p>



<h3 class="wp-block-heading"><a></a>State management becomes a full-time job</h3>



<p>Terraform’s state file is both its greatest strength and its biggest liability at scale. State gives Terraform the ability to track what it has deployed and calculate diffs — but as infrastructure grows, that state file becomes a critical shared resource with no native support for distributed access patterns.</p>



<p>Teams running a monolithic state end up with a single point of contention. Engineers queue up to run plans and apply. Locking mechanisms in backends like S3 with DynamoDB help, but they don’t solve the underlying architectural issue: Everyone is competing for the same resource.</p>



<p>The<a href="https://www.hashicorp.com/state-of-the-cloud"> </a><a href="https://www.hashicorp.com/state-of-the-cloud">HashiCorp State of Cloud Strategy Survey</a> consistently places state management issues, corruption, drift and locking failures among the top pain points for Terraform users in organizations with more than 50 engineers. When a state file gets corrupted mid-apply, recovery can take hours and require deep expertise. The problem compounds as infrastructure grows: Organizations running more than 500 managed resources in a single workspace routinely report 15–30 minute plan times, turning what should be a fast feedback loop into a deployment bottleneck.</p>



<h3 class="wp-block-heading"><a></a>Module sprawl and dependency hell</h3>



<p>Terraform modules are the right answer to code reuse. They’re also the source of some of the most painful debugging sessions in platform engineering.</p>



<p>As organizations scale, module libraries grow organically. Teams fork modules to meet specific requirements. Version pinning gets inconsistent. A security patch in a root module requires coordinated updates across dozens of dependent modules — a task that sounds simple until you’re dealing with circular dependencies, incompatible provider versions and module registries that weren’t designed for enterprise governance.</p>



<p>Adopting semantic versioning for Terraform modules has a measurable impact: According to a<a href="https://moldstud.com/articles/p-achieving-infrastructure-as-code-a-comprehensive-case-study-on-terraform-usage"> Moldstud IaC case study (June 2025)</a>, approximately 60% of organizations that enforce semantic versioning on module releases report a decrease in deployment failures over six months. Yet most teams don’t adopt this practice until after they’ve experienced the failure modes firsthand. The same research found that teams using peer reviews for Terraform code experience a 30% improvement in code quality but this requires process investment that most fast-moving platform teams skip in the early stages.</p>



<p>The pattern is consistent: What starts as a tidy module hierarchy becomes a tangled dependency graph that requires tribal knowledge to navigate.</p>



<h3 class="wp-block-heading"><a></a>Plan times and blast radius</h3>



<p>At a certain scale, the Terraform plan stops being a quick feedback loop and starts being a liability. Teams managing thousands of resources in a single workspace can wait 15–30 minutes for a plan to complete. More critically, the blast radius of a single application expands proportionally.</p>



<p>A misconfigured security group rule in a small workspace affects a handful of resources. The same mistake in a large monolithic workspace can cascade across hundreds of resources before anyone can intervene. Terraform’s own declarative model means that configuration errors can trigger resource destruction, a risk that grows with workspace size. This reality pushes teams toward increasingly conservative change management processes, which defeats the core value proposition of IaC in the first place.</p>



<p>There’s a meaningful ROI case for solving this. The<a href="https://moldstud.com/articles/p-achieving-infrastructure-as-code-a-comprehensive-case-study-on-terraform-usage"> </a><a href="https://moldstud.com/articles/p-achieving-infrastructure-as-code-a-comprehensive-case-study-on-terraform-usage">Moldstud IaC case study</a> indicates that implementing automated IaC solutions can lead to a 70% reduction in deployment times. But capturing that return requires architectural decisions that prevent plan-time bottlenecks before they compound.</p>



<h3 class="wp-block-heading"><a></a>Drift: The silent killer</h3>



<p>Infrastructure drift — where the actual state of your cloud environment diverges from what Terraform believes it to be — is among the most insidious challenges at scale. It accumulates slowly, through emergency console changes, partially applied runs and resources created outside of Terraform entirely.</p>



<p>The causes are well-documented: An on-call engineer hotfixes a security group at 3 a.m. and forgets to update the code; an autoscaling event modifies a resource configuration that Terraform manages; a third-party integration quietly changes a setting that Terraform has no visibility into. Each of these is a small divergence. Collectively, they erode the reliability of your entire IaC foundation.<a href="https://spacelift.io/blog/terraform-drift-detection"> </a><a href="https://spacelift.io/blog/terraform-drift-detection">Terraform Drift Detection Guide</a> documents how teams across industries are consistently caught off guard by drift accumulation in environments they believed were fully under IaC control.</p>



<p>By the time drift becomes visible, it’s often embedded deep enough to make remediation genuinely risky. The<a href="https://dora.dev/research/2023/"> </a><a href="https://dora.dev/research/2023/">DORA 2023 State of DevOps Report</a> found that teams dealing with frequent configuration drift had 2.3× higher change failure rates than teams maintaining consistent IaC hygiene. The compounding effect is significant: Drift erodes confidence in your IaC, which leads to more manual changes, which causes more drift.</p>



<h2 class="wp-block-heading"><a></a>Why traditional approaches fall short</h2>



<p>The conventional responses to Terraform scaling challenges are well-documented: Workspace decomposition, remote state backends, CI/CD pipelines with policy enforcement and module registries with semantic versioning. These are all necessary practices. They’re also insufficient on their own.</p>



<ul class="wp-block-list">
<li><strong>Workspace decomposition</strong> reduces blast radius but multiplies operational overhead. You’re trading one large problem for many smaller ones, each requiring its own state management, access controls and pipeline configuration. Managing 200 workspaces is a full-time engineering effort.</li>



<li><strong>CI/CD enforcement</strong> catches policy violations after the fact. By the time a plan hits your pipeline, an engineer has already spent time writing code that may get rejected. Feedback loops are slow, and the root cause — the complexity of authoring correct IaC at scale — remains unsolved.</li>



<li><strong>Manual code reviews</strong> don’t scale. Platform teams can become bottlenecks when every Terraform change requires expert review to validate correctness, security posture and compliance. The cognitive load required to review infrastructure changes accurately is substantial, and reviewers burn out. This bottleneck is only sharpened by the talent shortage: With<a href="https://www.hashicorp.com/state-of-the-cloud"> </a><a href="https://www.hashicorp.com/state-of-the-cloud">64% of organizations reporting a shortage of skilled cloud and automation staff</a>, the supply of qualified reviewers isn’t growing fast enough to match Terraform’s adoption curve.</li>
</ul>



<p>The honest assessment: These solutions manage Terraform complexity rather than resolving it. They require ongoing investment in tooling, process and expertise that many organizations struggle to maintain.</p>



<p>This is exactly the friction that<a href="https://stackgen.com/platform"> </a><a href="https://stackgen.com/platform">StackGen’s Intent-to-Infrastructure Platform</a> was designed to address. Rather than adding more manual process overhead, it introduces an intelligent layer that helps teams author, validate and govern Terraform configurations from the point of intent before complexity accumulates.</p>



<h2 class="wp-block-heading"><a></a>Emerging solutions: Where the industry is moving</h2>



<p>The Terraform ecosystem is evolving rapidly in response to these challenges. The global IaC market reflects this urgency: Valued at $847 million in 2023, it’s projected to reach $3.76 billion by 2030 at a 24.4% compound annual growth rate, according to<a href="https://www.grandviewresearch.com/industry-analysis/infrastructure-as-code-market-report"> </a><a href="https://www.grandviewresearch.com/industry-analysis/infrastructure-as-code-market-report">Grand View Research’s IaC Market Report</a>. That growth isn’t just adoption — it’s investment in solving the complexity problems that widespread adoption creates.</p>



<h3 class="wp-block-heading"><a></a>Workspace automation and orchestration</h3>



<p>Tools like Atlantis, Stackgen, Terraform Cloud, are moving toward intelligent workspace orchestration, automatically managing dependencies between workspaces, ordering applies correctly and providing better visibility into cross-workspace impact. This reduces the manual coordination overhead that plagues large-scale Terraform operations.</p>



<p>The key shift is treating your collection of workspaces as a managed system rather than a set of independent units. When a shared networking module changes, an orchestration layer should automatically identify affected workspaces, calculate the propagation order and manage the apply sequence — rather than requiring a human to track and coordinate each dependency manually.</p>



<h3 class="wp-block-heading"><a></a>Policy-as-code with earlier enforcement</h3>



<p><a href="https://www.openpolicyagent.org/">Open Policy Agent (OPA)</a> and<a href="https://developer.hashicorp.com/sentinel"> </a><a href="https://developer.hashicorp.com/sentinel">HashiCorp Sentinel</a> have matured significantly. More importantly, teams are learning to push policy enforcement left — validating Terraform plans against organizational policies before they hit a CI/CD pipeline, and ideally before they’re even submitted for review.</p>



<p>HashiCorp has reported that teams using Sentinel with pre-plan validation see a 45% reduction in policy violation-related build failures compared to teams running post-plan enforcement only. Earlier feedback means faster iteration and lower engineer frustration.</p>



<h3 class="wp-block-heading"><a></a>AI-assisted IaC management: The emerging frontier</h3>



<p>This is where the most significant innovation is happening. AI-assisted infrastructure management addresses the problems that automation alone can’t solve: The cognitive complexity of understanding large IaC codebases, identifying drift patterns before they become critical and translating high-level intent into correct, compliant Terraform code.</p>



<p>Platforms like<a href="https://stackgen.com/platform"> </a><a href="https://stackgen.com/platform">StackGen’s Intent-to-Infrastructure Platform</a> represent a new paradigm here. Rather than requiring platform engineers to manually author and review every Terraform resource definition, StackGen interprets infrastructure intent — expressed in natural language or high-level policy- and generates compliant Terraform configurations, validates them against organizational standards and surfaces potential issues before they reach production. This directly addresses the bottleneck where expert review becomes a constraint on velocity.</p>



<p>The practical applications are concrete:</p>



<ul class="wp-block-list">
<li><strong>Drift detection and remediation</strong>: AI models trained on infrastructure patterns can identify anomalous drift, distinguishing between expected configuration changes and unauthorized modifications, and surface remediation recommendations with context about impact and risk. This is particularly powerful for teams managing hundreds of workspaces where manual drift monitoring isn’t practical.</li>



<li><strong>Intelligent module recommendations</strong>: Rather than requiring engineers to navigate sprawling module registries manually, AI-assisted tooling can analyse an infrastructure request, identify the most appropriate existing modules and flag where new module development is needed. This reduces the “reinvent the wheel” pattern that causes module sprawl.</li>



<li><strong>Natural language to IaC</strong>: For platform teams managing self-service infrastructure portals, AI translation layers allow development teams to request infrastructure in natural language and receive validated Terraform configurations that conform to organizational standards — without requiring deep Terraform expertise from every team consuming platform services.</li>



<li><strong>Proactive complexity warnings</strong>: AI analysis of Terraform codebases can identify emerging complexity patterns before they become critical — detecting circular dependencies forming, state files approaching problematic size thresholds or module versioning patterns that suggest future compatibility issues.</li>
</ul>



<p><a href="https://www.gartner.com/en/infrastructure-and-it-operations-leaders">Gartner predicts</a> that by 2026, more than 40% of organizations will be using AI-augmented IaC tooling for some portion of their infrastructure management workflow — up from under 10% in 2023. The trajectory is clear, and the window for early-mover advantage is still open.</p>



<h2 class="wp-block-heading"><a></a>Practical guidance: Scaling terraform without losing your mind</h2>



<p>While AI-assisted tooling continues to mature, there are concrete architectural and process changes your team can adopt today.</p>



<ul class="wp-block-list">
<li><strong>Decompose by domain, not by team.</strong> Workspace boundaries should reflect infrastructure domains (networking, compute, data) rather than organizational team boundaries. Teams change; infrastructure domains are more stable. This reduces the reorganization tax you pay when teams restructure.</li>



<li><strong>Treat state as infrastructure.</strong> Your state backend deserves the same reliability engineering as production systems. Remote state with versioning, automated backup verification and clear recovery runbooks should be non-negotiable before you’re managing more than a few dozen resources. The<a href="https://www.hashicorp.com/state-of-the-cloud"> </a><a href="https://www.hashicorp.com/state-of-the-cloud">HashiCorp State of Cloud Strategy Survey</a> shows that over 80% of enterprises already integrate IaC into their CI/CD pipelines — but pipeline integration doesn’t substitute for state backend reliability.</li>



<li><strong>Invest in a private module registry early.</strong> Whether you use Terraform Cloud’s built-in registry, a self-hosted solution or a structured module registry with enforced semantic versioning pays compounding dividends as your module library grows. The cost of retrofitting governance onto an ungoverned module library is significantly higher than building in governance from the start.</li>



<li><strong>Automate drift detection, not just drift remediation.</strong> Drift remediation is expensive; drift detection is cheap. Scheduled Terraform plan runs in CI/CD, combined with alerting on detected drift, give you an early warning system that prevents drift from compounding silently. For teams managing large environments where manual detection becomes impractical, automated drift tooling, whether native to<a href="https://developer.hashicorp.com/terraform/cloud-docs"> HCP Terraform</a> or third-party solutions, becomes essential infrastructure in its own right.</li>



<li><strong>Build a paved road for Terraform consumers.</strong> If every application team needs to become a Terraform expert to consume platform services, your platform won’t scale. Build opinionated, simplified interfaces, whether that’s a service catalogue, a self-service portal or an AI-assisted request layer that allows development teams to get the infrastructure they need without requiring deep IaC expertise.</li>
</ul>



<p>The strategic inflection point</p>



<p>We’re at an inflection point in how the industry thinks about infrastructure-as-code. The original vision of IaC infrastructure defined, versioned and managed like software was correct. The execution, for large-scale organizations, has accumulated significant complexity debt.</p>



<p>The next wave of IaC tooling isn’t about replacing Terraform. Terraform’s declarative model, provider ecosystem and community are genuine strengths that won’t be supplanted quickly. The opportunity is in the layer above Terraform: Intelligent orchestration, AI-assisted authoring, proactive complexity management and intent-driven infrastructure interfaces that make IaC accessible to the full organization rather than just a specialized subset of platform engineers.</p>



<p>Teams that invest in this layer now, whether through emerging platforms, internal tooling or AI-assisted workflows, will build a meaningful operational advantage. Teams that continue fighting Terraform complexity with more Terraform will find themselves spending an increasing proportion of engineering capacity on infrastructure maintenance rather than product development.</p>



<p>The<a href="https://www.grandviewresearch.com/industry-analysis/infrastructure-as-code-market-report"> </a><a href="https://www.grandviewresearch.com/industry-analysis/infrastructure-as-code-market-report">IaC market’s 24.4% CAGR</a> reflects growing awareness that the tools and processes managing this complexity need to evolve as fast as the infrastructure they govern.</p>



<h2 class="wp-block-heading"><a></a>Key takeaways</h2>



<p>The Terraform scaling problem is real, but it’s solvable. The path forward involves three parallel tracks: Architectural decisions that manage blast radius and reduce state contention; process investments in policy-as-code and module governance; and tooling that uses AI to address the cognitive complexity that has always been the hardest part of IaC at scale.</p>



<p>Your infrastructure code should accelerate your engineering organization, not constrain it. If it’s doing the latter, the problem isn’t your engineers; it’s the layer of tooling and process sitting between intent and deployed infrastructure.</p>



<p>Ready to explore how AI-assisted IaC management can reduce the complexity overhead in your Terraform workflows?<a href="https://stackgen.com/platform"></a></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.infoworld.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Best Notch Apps for Your MacBook in 2026: Making the Most of an Underlooked Feature]]></title>
<description><![CDATA[Those that own a MacBook are likely all too familiar with the notch on their display: that little black space in your menu bar that houses your camera. While some may not mind it, others can find it to be far too distracting. However, users should know that there are options available to transfor...]]></description>
<link>https://tsecurity.de/de/3410247/ios-mac-os/the-best-notch-apps-for-your-macbook-in-2026-making-the-most-of-an-underlooked-feature/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410247/ios-mac-os/the-best-notch-apps-for-your-macbook-in-2026-making-the-most-of-an-underlooked-feature/</guid>
<pubDate>Mon, 06 Apr 2026 06:52:44 +0200</pubDate>
<content:encoded><![CDATA[Those that own a MacBook are likely all too familiar with the notch on their display: that little black space in your menu bar that houses your camera. While some may not mind it, others can find it to be far too distracting. However, users should know that there are options available to transform the notch on your Mac into something more. 



We’re taking a look at some of the best notch apps available for your MacBook. Some of the apps on this list have a focus on productivity, whereas others have a focus on expanding the capabilities of macOS. Each of them has something to offer, but one stands out above the rest as the best MacBook notch app. 



1. NotchNook







If you’re looking for a solid app for the notch on your MacBook, then NotchNook stands out as the best MacBook notch app that transforms that little space in your menu bar into a rather helpful productivity hub. Rather than just focusing on animations and presentation, NotchNook integrates practical features that can harmonize your workflow. 



Featuring support for drag-and-drop file handling, NotchNook can make the space on your Mac a holding area for links, documents, and images -- speeding up your multitasking significantly. You can also access widgets like your calendar, notes, and even media controls without the need for switching between apps. 



What’s really great is how NotchNook is able to fit so naturally within macOS. It doesn’t feel like an add-on, but rather an extension of the operating system. Even better, users can use the code MACOBSERVER30 to get an exclusive 30% discount. This means a lifetime subscription for $16.80 over the usual $24, or a monthly subscription for just $2.10 vs the typical $3/mo. There’s also a free trial for those who want to give it a shot, but the company also provides a 7-day money-back guarantee that’s absolutely risk-free.



If you’re looking for the best MacBook notch app, Download NotchNook today and see how expanding the capabilities of your notch can make a difference. Just apply the code and start saving time on your Mac immediately.



2. LookieLoo







LookieLoo takes a simple approach to your MacBook notch, but it also offers a fair amount of functionality. As a quick-hub, it can provide users with some system stats and a few notifications, all while never seeming to get in the way. It doesn’t command your attention, rather, it works alongside your workflow in a way that's more beneficial than obtrusive.



Rather than trying to reinvent how you navigate macOS, it brings some rather useful information to the forefront. It can provide subtle improvements to your experience, and it’s got some media controls that show it knows how to have a bit of fun. 



However, one downside is that it may be too passive for some users, who may be wanting more active controls for their productivity. It can still be helpful, but it may be more limited than others on this list. While you shouldn’t expect deep interactivity, there are some features that can make it helpful. 



3. NotchNest







As a notch app, NotchNest is all about features. Offering a multitude of apps that can range from jotting down notes to playing mini games, NotchNest takes a transformative approach to your menu bar. Using a single interface, it users can think of it almost more as a workspace rather than a simple utility. 



With a kitchen-sink approach to its offerings, there’s a lot available without feeling overwhelming. For those like multitasking, it’s capable of quite a bit, and it offers a fair amount of efficiency with its access to shortcuts. 



Looking at everything it offers, it can feel a bit busy at times. With others on this list feeling more streamlined, it can feel like the app is gunning for your attention more rather than providing an experience. There can be a learning curve to it, but some may like digging into everything it can offer. 



4. Droppy







Don’t call Droppy a notch app, because it sees itself more as a productivity powerhouse. Offering its fair share of HUDs, this one also has quick file controls, clipboard history, as well as some other features that can make certain tasks more accessible. 



A cool thing about the app is that it doesn’t feel obtrusive. Offering simple-to-navigate controls, this one can be pretty easy to pick up and get going. It’s good for feeling like an extension of your system rather than a whole new experience. 



On the flipside, however, some users note that it can feel unpolished at times, though the developer is good at responding to feedback. This one can be good for those that are looking for some additional features on macOS, but some may still prefer something that takes a simpler approach. 



#5 TopNotch







TopNotch wants to make your notch disappear like a ninja. For those that like aesthetics, TopNotch is all about trying to remove that black space entirely. With this app, your menu bar transforms into a black strip to give your display a more uniform look. It’s pretty good for those that find the notch distracting. 



Since it works in the background, there’s not a lot of setup to be had, making it incredibly straightforward. It also works with multiple displays, and it can even add rounded corners to your wallpaper. 



However, this one is purely going to be cosmetic. You may appreciate how it looks, but it’s not going to introduce any new features or capabilities to your notch. It’s not aiming to, however, so this is one for those that just like the look of things. 



Conclusion: What's the Best Notch App for Your MacBook?



The notch on a stock MacBook can look unappealing for some users, but a great MacBook notch app should provide a bit of functionality without feeling like it’s taking on too much. If you’re looking for access to quick controls that can benefit your macOS experience, NotchNook is the way to go. With how much it can save on your workflow compared to the cost, it’s going to transform your MacBook notch in a way that’s beneficial yet not over complicated. ]]></content:encoded>
</item>
<item>
<title><![CDATA[A Practical Approach To Graphing The Planet]]></title>
<description><![CDATA[BloodHound OpenGraph Processing with DataHoundBackgroundContextBloodHound was originally created by SpecterOps to assist with the analysis of Active Directory environments. The platform was later expanded to include Entra ID (Azure) resources.The BloodHound OpenGraph further extends Attack Path M...]]></description>
<link>https://tsecurity.de/de/3404648/hacking/a-practical-approach-to-graphing-the-planet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3404648/hacking/a-practical-approach-to-graphing-the-planet/</guid>
<pubDate>Fri, 03 Apr 2026 08:20:06 +0200</pubDate>
<content:encoded><![CDATA[<h4>BloodHound OpenGraph Processing with DataHound</h4><h3>Background</h3><h4>Context</h4><p>BloodHound was originally created by SpecterOps to assist with the analysis of Active Directory environments. The platform was later expanded to include Entra ID (Azure) resources.</p><p>The BloodHound OpenGraph further extends Attack Path Management analysis beyond Active Directory and Entra environments. OG provides a JSON schema to represent custom data and the ability to ingest it into BloodHound.</p><p>With some creativity, you can graph just about anything.</p><p>With this new capability, there is a need for new robust tooling to support custom data. <strong>DataHound was created to help bridge this gap, allowing developers and researchers to create OpenGraph extensions at scale. </strong>This post is the first in a series and will focus on the design of the collection components.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*nQQ6PL1EhEmTtlws.png"><figcaption>Graph the Planet</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1023/1*FZgWgNxB7qcLUsYXNSSFBQ.png"><figcaption>hackers think in graphs</figcaption></figure><h3>DataHound</h3><h4>Overview</h4><p>The core of the project is a <strong>data processing engine that performs two operations:</strong></p><ol><li><strong>collect</strong>: Process and transform Pandas DataFrames into OpenGraph JSON.</li><li><strong>connect</strong>: Process two existing graph files and generate a JSON of hybrid edges between the two original data sets.</li></ol><p>The collector modules in the project are proof-of-concept examples of how the engine can be used. There are currently 12 PoC collector modules with data sources ranging from HTTP to LDAP and PE parsing.</p><p>The flat file formats (CSV, JSON, XML, YAML) are the most versatile and powerful, as the original data source could be <em>anything</em>.</p><p><a href="https://github.com/toneillcodes/DataHound/tree/main?tab=readme-ov-file#supported-collectors">https://github.com/toneillcodes/DataHound/tree/main?tab=readme-ov-file#supported-collectors</a></p><h4>Technology Stack</h4><p>DataHound is built on Python and Pandas.</p><p>This stack was selected to leverage Python’s robust data analysis capabilities and its support for high-performance processing of large datasets.</p><p>As a bonus, the extensive library ecosystem enables the development of a wide range of collector modules.</p><h3>Collect Operation</h3><h4>BloodHound ETL Process</h4><p>BloodHound uses an ETL pattern for data processing:</p><ul><li><strong>E</strong>xtract the data</li><li><strong>T</strong>ransform the data</li><li><strong>L</strong>oad the data</li></ul><p>The utility that performs the Extract and Transform steps is typically referred to as the ‘collector,’ and the Load step of the E-T-L series is completed by uploading (ingesting) the data to BloodHound.</p><p>Examples of classic, well-known collectors are SharpHound, AzureHound, and bloodhound.py. These solutions extract data from AD and/or Azure environments and format it into a set of BloodHound-compliant JSON files.</p><h4>Configuration File</h4><p>Data sources are unique and cannot all be handled the same way. Even if sources use the same technology (i.e., HTTP), they may require different request parameters or different parsing logic.</p><ul><li>We don’t want to reinvent the wheel every time we integrate another data source.</li><li>We don’t want to duplicate code across projects and repositories, creating sprawling technical debt.</li></ul><p><strong>How can we abstract the extraction and transformation logic and make it reusable?</strong></p><p>The processing engine is driven by a ‘collection definition’ config file that has collection and transformation properties for each data element to be processed.</p><p>Each data element has a block of properties that specify details such as the item type (node or edge), data source information, transformation rules, and the data elements to be output in the OG graph.</p><p>Below is an example of the definition to retrieve the <strong>User nodes </strong>from a BloodHound instance by invoking the <strong>bloodhound-users</strong> HTTP API endpoint:</p><pre>    {<br>        "item_type": "node",<br>        "item_name": "Users",<br>        "item_description": "Users found in the BloodHound instance",<br>        "source_type": "url",<br>        "source_url": "http://127.0.0.1:8080/api/v2/bloodhound-users",<br>        "source_auth_type": "bearer-token",<br>        "source_auth_token": "key.key.key",<br>        "data_root": "users",<br>        "column_mapping": {<br>            "id": "id",<br>            "principal_name": "name",<br>            "last_login": "last_login"<br>        },<br>        "output_columns": [            <br>            "id",<br>            "name",<br>            "last_login"<br>        ],<br>        "id_location": "id",          <br>        "item_kind": "BHUser",<br>        "source_name": "bloodhound-users"<br>    }</pre><p>Below is an example of the definition to retrieve the <strong>edge</strong> between a <strong>User and an SSO Provider</strong>, which uses the same <strong>bloodhound-users</strong> HTTP API endpoint to process different data:</p><pre> {<br>        "item_type": "edge",<br>        "item_name": "User SSO Provider Edges",<br>        "item_description": "User-[ProviderFor]-&gt; SSO Provider mappings in the BloodHound instance",<br>        "source_type": "url",<br>        "source_url": "http://127.0.0.1:8080/api/v2/bloodhound-users",<br>        "source_auth_type": "bearer-token",<br>        "source_auth_token": "key.key.key",<br>        "data_root": "users",<br>        "edge_type": "static",<br>        "edge_name": "ProviderFor",<br>        "source_column": "sso_provider_id",<br>        "target_column": "id",<br>        "source_node_type": "BHSSOProvider",<br>        "target_node_type": "BHUser",<br>        "source_name": "bloodhound-users"<br>    }</pre><p>More detailed information about the formatting and options for the collection definitions can be found in the project documentation on:</p><p><a href="https://github.com/toneillcodes/DataHound/blob/main/CollectorConfigurationGuide.md">https://github.com/toneillcodes/DataHound/blob/main/CollectorConfigurationGuide.md</a></p><p>Each item in the definitions file is processed by calling ‘process_config_item’ and passing the config properties and source_kind:</p><pre>    operation = args.operation<br>    if operation == "collect":       <br>        ...                 <br>        # parse through each item in the config file<br>        for config in config_list:<br>            # centralized processing logic moved to a dedicated method which parses the config and invokes the dispatcher<br>            # target_list should be either 'node' or 'edge' to indicate which part of the graph is being returned<br>            # data contains the processed and transformed graph data to be appended<br>            target_list, data = process_config_item(config, source_kind)</pre><p>‘process_config_item’ is a dispatcher function that parses the definition properties and invokes the appropriate processing and transformation functions to complete the operation.</p><h4>Extract</h4><p>To decouple the collection activities from the data processing entirely, the extraction process was broken into two components:</p><p>(1) The ‘process_’ function that calls the ‘collector module’ and parses the result.</p><p>The ‘process_’ functions handle most of the error checking and configuration property parsing to ensure it has everything needed to invoke the ‘collector module’.</p><p>Example: ‘process_csv_source’ from DataHound.py</p><pre>def process_csv_source(config):<br>    """<br>    Docstring for process_csv_source<br>    <br>    :param config: data collection and transformation definition in JSON format<br>    """<br>    item_name = config.get('item_name', 'NA')<br>    # validation<br>    source_path = config.get('input_file')<br>    if not source_path:<br>        logging.error(f"'input_file' is required. Skipping item: {item_name}.")<br>        return False<br><br>    # invoke collector<br>    csv_data = collect_csv_data(config)<br>    if csv_data is None:<br>        logging.warning(f"Skipping item {item_name} due to failed parsing of input file.")<br>        return False<br>    <br>    # something was returned, point data_object to it for processing<br>    #print(f"csv_data: {csv_data}")<br>    logging.info(f"Successfully processed {item_name}")<br>    return csv_data</pre><p>(2) The ‘collector module’ that interacts with the data source and parses raw data.</p><p>The collector modules themselves are kept simple and clean, performing the collection job and passing the data back to the ‘process_’ function.</p><p>Example: ‘collect_csv_data’ from collector_modules\csv_collector.py</p><pre>def collect_csv_data(config: dict) -&gt; Optional[pd.DataFrame]:<br>    """<br>    Loads a CSV file from a path specified in the configuration using pandas.<br>    Returns a pandas DataFrame if successful, otherwise None.<br>    Adds correlation_id for tracing.<br>    """<br>    # generate correlation ID<br>    correlation_id = str(uuid.uuid4())<br><br>    # retrieve the input_file configuration parameter<br>    csv_file_path = config.get('input_file')<br>...<br>    try:<br>        # load CSV file into a pandas dataframe<br>        df = pd.read_csv(<br>            csv_file_path,<br>            sep=sep,<br>            encoding=encoding,<br>            dtype=str<br>            # Add other common kwargs if needed, e.g., index_col, dtype, parse_dates<br>        )<br>        <br>        # structured info log for successful data load<br>        logging.info(json.dumps({<br>            "event": "CSV_LOAD_SUCCESS",<br>            "correlation_id": correlation_id,<br>            "file_path": csv_file_path,<br>            "rows": len(df),<br>            "columns": len(df.columns),<br>            "message": "CSV file loaded successfully into DataFrame."<br>        }))<br>        <br>        return df</pre><h4>Transform</h4><p>With the <strong>E</strong>xtract step done, the next stop in our ETL pipeline is <strong>T</strong>ransform.</p><p>The ‘process_’ function prepared the DataFrame, and the goal at this point is to apply the transformation rules defined in the configuration properties.</p><p>At a high level, there are two types of transformations that DataHound must process: Nodes and Edges. What are the minimum requirements to build each?</p><p>The minimum data elements for a node are:</p><ul><li>id, name, Kind, Base Kind</li></ul><p>The minimum data elements for an edge are:</p><ul><li>Edge Kind, Start node, End node</li></ul><p>The configuration properties instruct the transformation function where to locate these data elements in the DataFrame and allow the code to build the OG graph elements.</p><p>The transformation step can perform additional data operations, such as remapping identified column names to new names, trimming the output data, and performing other activities.</p><p><strong>How do we apply this to the DataFrame?</strong></p><p>First, a dispatch map determines which transformation function should be invoked for the target data by keying off the ‘item_type’ property.</p><pre>    TRANSFORMERS = {<br>        'node': transform_node, <br>        'edge': transform_edge,<br>        'static_edge': transform_edge, <br>        'hybrid_edge': transform_edge<br>    }<br><br>    transformer = TRANSFORMERS.get(item_type)</pre><p><em>NOTE: The concept of a ‘static edge’ and ‘hybrid edge’ will be covered in another post.</em></p><p>The resolved transformer function is invoked and passed the DataFrame with config properties for processing:</p><pre>    # Apply transformation logic<br>    try:<br>        if item_type == 'node':<br>            #print(f"Using tranformation function: {transformer}")<br>            transformed_data = transformer(df, config, source_kind)<br>        else:<br>            transformed_data = transformer(df, config)</pre><p>The ‘transform_node’ and ‘transform_edge’ functions contain logic that parse the config properties, process the data, and return OG JSON.</p><p>For example, below is some of the <strong>edge </strong>processing logic that parses the source column (Start) and target column (End) properties and returns an OG edge_data object:</p><pre>def transform_edge(input_object: pd.DataFrame, config: dict):<br>    df = input_object.copy()<br>    column_mapping = config.get('column_mapping', {})<br>    source_col = config['source_column']<br>    target_col = config['target_column']<br>...<br>    edge_data = []<br>    for row in df.to_dict('records'):<br>        target_val = row[target_col]<br>        source_val = row[source_col]<br><br>        # Resolve end_id<br>        if isinstance(target_val, dict) and target_column_id:<br>            end_id = target_val.get(target_column_id)<br>        else:<br>            end_id = target_val<br>...<br>        edge_data.append({<br>            "kind": str(kind or edge_name).strip(),<br>            "start": {"value": str(source_val).strip()},<br>            "end": {"value": str(end_id).strip()}<br>        })<br>    <br>    return edge_data</pre><p>There is a ‘graph_structure’ object that represents an empty OG graph.</p><pre>    graph_structure = {<br>        "metadata": { "source_kind": source_kind }, <br>        "graph": {<br>            "nodes": [],<br>            "edges": []<br>        }<br>    }   </pre><p>The processing results for each data element are collected in either the ‘nodes’ or ‘edges’ objects of ‘graph_structure’. When all config elements have been processed, graph_structure is written to the provided output file.</p><pre># parse through each item in the config file<br>for config in config_list:<br>    # centralized processing logic moved to a dedicated method which parses the config and invokes the dispatcher<br>    # target_list should be either 'node' or 'edge' to indicate which part of the graph is being returned<br>    # data contains the processed and transformed graph data to be appended<br>    target_list, data = process_config_item(config, source_kind)<br>    <br>    if target_list and data:<br>        graph_structure['graph'][target_list].extend(data)<br>        logging.info(f"Successfully added {len(data)} items to {target_list}.")<br><br># done processing, output graph              <br># todo: add output controls<br>output_file = args.output<br>if output_file:<br>    logging.info(f"Writing graph to output file: {output_file}")<br>    try:      <br>        with open(output_file, 'w') as f:<br>            json.dump(graph_structure, f, indent=4, default=str)         <br>        logging.info(f"Successfully Wrote graph to {output_file}")<br>    except Exception as e: <br>        logging.error(f"Failed to write output file: {output_file}. Error: {e}")</pre><h4>Load</h4><p>At this point, DataHound has done its job. The final step in the ETL process is to upload the JSON to BloodHound and explore the graph with Cypher queries. This is the shortest section, since DataHound doesn’t have functionality to upload the graph.</p><ol><li>Login to BloodHound as a user with upload permissions</li><li>Access ‘Quick Upload’ from the navigation panel</li><li>Complete the upload process in the UI and wait click ‘View File Ingest History’ to monitor the progress</li><li>Wait for the job to be flagged as ‘Complete’</li><li>Access ‘Explore’ from the navigation panel and use Cypher queries to interact with the data</li></ol><p>Custom nodes will appear with a question mark unless Custom Icons are defined for the node types.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0F5nWEIz8nJ78k7cPIGU9Q.png"></figure><p><strong>HoundTrainer</strong> is a complementary tool that can facilitate the creation and management of these custom icons to support a rich and vibrant graph with useful icons.</p><p><a href="https://github.com/toneillcodes/HoundTrainer">https://github.com/toneillcodes/HoundTrainer</a></p><h3>Examples</h3><h4>DPAPI: Mapping blobs to Profiles and Computers</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-snZgLF3qMr7q2GvRTz9Dw.png"><figcaption>DPAPI: Mapping blobs to Profiles and Computers</figcaption></figure><h4>NMap: Visualizing service distribution</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*cR-_69C72yI7apXT"><figcaption>NMap: Visualizing service distribution</figcaption></figure><h4>PE Analysis: Analyzing Import Address Table</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*RNBXJ3wKii9qH52G"><figcaption>PE Analysis: Analyzing Import Address Table</figcaption></figure><h3>Connect Operation</h3><h4>Summary</h4><p>The connect operation takes two JSON files (--graphA and --graphB) and creates new edges between nodes that share a common, correlatable property.</p><h4>How it Works</h4><ol><li>Performs an outer merge using Pandas DataFrames to match nodes based on a specified property ( --matchA and --matchB).</li><li>For successful matches, it generates a new edge object with the specified kind ( --edge-kind) connecting the matched nodes.</li><li>Outputs the generated edges into a new graph file</li></ol><p>Example usage connecting a BHCE graph to the Azure sample data set.</p><pre>python DataHound.py --operation connect \<br>--graphA dev\bhce-collection-20251204.json \<br>--rootA nodes --idA id --matchA properties.email \<br>--graphB entra_sampledata\azurehound_example.json \<br>--rootB data --idB data.id --matchB data.userPrincipalName \<br>--edge-kind MapsTo --output ..\bhce-connected-to-azure.json</pre><h3>Summary</h3><ul><li>BloodHound OpenGraph is awesome</li><li>DataHound is a powerful and flexible processing engine</li><li>DataHound turns Pandas DataFrames into OpenGraph JSON</li><li>DataHound can connect two graphs with hybrid edges</li><li>When paired with a tool like HoundTrainer for icon and Cypher management, DataHound can help to rapidly turn an idea into a PoC.</li></ul><h3>Next Steps</h3><h4>Follow-up Posts</h4><ul><li>The concept of static nodes and how to use them</li><li>The concept of static and hybrid edges, and how to use them</li><li>AI-assisted collector module prototyping</li></ul><h4>Development</h4><ul><li>Refactor into a library</li><li>Streamline and simplify configuration properties</li><li>Documentation updates &amp; examples</li></ul><h3>Resources</h3><h4>DataHound</h4><ul><li>DataHound GitHub repo <a href="https://github.com/toneillcodes/DataHound/">https://github.com/toneillcodes/DataHound/</a></li></ul><h4>HoundTrainer</h4><ul><li>HoundTrainer GitHub repo <a href="https://github.com/toneillcodes/HoundTrainer">https://github.com/toneillcodes/HoundTrainer</a></li></ul><h4>SpecterOps</h4><ul><li><strong>OpenGraph documentation</strong> <a href="https://bloodhound.specterops.io/opengraph/overview">https://bloodhound.specterops.io/opengraph/overview</a></li><li><strong>BloodHound Gang Slack</strong> has a bunch of channels, #bloodhound-chat and #opengraph</li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1d43b28b8f63" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/a-practical-approach-to-graphing-the-planet-1d43b28b8f63">A Practical Approach To Graphing The Planet</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[칼럼 | HR의 AI 도입, 성과로 이어지지 못하는 이유]]></title>
<description><![CDATA[지난 1년 사이 AI를 둘러싼 논의는 크게 달라졌다. 많은 기업이 파일럿 단계를 넘어 실제 운영 환경에 AI를 도입하는 단계로 이동했다. 그러나 AI가 실제로 어디에서, 어떤 방식으로 가치를 창출하고 있는지는 대다수 AI 도입 기업이 밝히는 것보다 훨씬 복잡하다. 현재 우리가 마주한 AI 도입의 모습은 ‘도입했다’ 혹은 ‘도입하지 않았다’로 나뉘는 이분법이 아니라, 조직 곳곳에 파편화된 양상에 가깝다.



대부분의 프로그램은 경영진 차원의 야심 찬 전략, 중간 단계의 불균등한 배포, 현장에서의 일관성 없는 성과라는 구조로 설...]]></description>
<link>https://tsecurity.de/de/3395181/it-nachrichten/hr-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395181/it-nachrichten/hr-ai/</guid>
<pubDate>Tue, 31 Mar 2026 09:17:13 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>지난 1년 사이 AI를 둘러싼 논의는 크게 달라졌다. 많은 기업이 파일럿 단계를 넘어 실제 운영 환경에 AI를 도입하는 단계로 이동했다. 그러나 AI가 실제로 어디에서, 어떤 방식으로 가치를 창출하고 있는지는 대다수 AI 도입 기업이 밝히는 것보다 훨씬 복잡하다. 현재 우리가 마주한 AI 도입의 모습은 ‘도입했다’ 혹은 ‘도입하지 않았다’로 나뉘는 이분법이 아니라, 조직 곳곳에 파편화된 양상에 가깝다.</p>



<p>대부분의 프로그램은 경영진 차원의 야심 찬 전략, 중간 단계의 불균등한 배포, 현장에서의 일관성 없는 성과라는 구조로 설명할 수 있다. 특히 사람을 중심으로 운영되는 HR 영역에서 이러한 불균형은 단순한 기술 문제가 아니다. 이는 결국 사람의 문제로 귀결된다.</p>



<h2 class="wp-block-heading">말과 행동의 격차</h2>



<p>이사회에서는 AI를 둘러싼 논의가 ‘도입할 것인가’에서 ‘얼마나 빠르게 도입할 것인가’로 옮겨갔다. 그러나 최근 연구는 뚜렷한 성숙도 격차를 보여준다. 미국의 HR 전문 미디어 HR 이그제큐티브 조사 결과에 따르면 HR 테크 리더의 88%가 AI 이니셔티브에서 유의미한 투자 대비 수익(ROI)을 거두지 못했다고 <a href="https://hrexecutive.com/new-research-from-gartner-phenom-and-others-reveals-ais-roi-problem-plus-industry-roundup-and-news/?utm_source=chatgpt.com" target="_blank" rel="nofollow">응답했다</a>. 도입 지표는 긍정적이지만, 실제 구현이 아직 측정 가능한 비즈니스 성과로 이어지지 못하고 있음을 시사한다.</p>



<p><a href="https://www.ey.com/en_gl/insights/workforce/work-reimagined-survey" target="_blank" rel="nofollow">EY의 글로벌 조사</a>에서도 유사한 결과가 나타났다. 직원 10명 중 약 9명이 업무에서 AI 도구를 사용하고 있지만, 이를 고부가가치 성과로 전환한 조직은 약 28%에 그쳤다.</p>



<p>이는 HR 조직이 AI 도구를 배포하는 데는 성공했지만, 채용 효율성, 인재 유지, 인력 계획과 같은 핵심 지표를 변화시킬 만큼 통합적인 프로세스 전환에는 아직 이르지 못했음을 의미한다. 이러한 괴리는 정렬된 운영 모델이나 성과 측정 체계 없이 빠르게 실험을 반복하는 기업 전반의 흐름과도 맞닿아 있다.</p>



<h2 class="wp-block-heading">섀도 AI, 기업 전반 과제가 드러난 단면</h2>



<p>통제된 AI 도입을 가로막는 가장 지속적인 장애물 중 하나는 섀도 AI다. 이스라엘 보안 기업 XM사이버의 <a href="https://xmcyber.com/blog/shadow-it-is-everywhere-xm-cyber-finds-80-of-companies-show-signs-of-unapproved-ai-activity/#:~:text=According%20to%20XM%20Cyber%2C%20over%2080%25%20of,code%2C%20customer%20PII%2C%20financial%20models%2C%20and%20credentials" target="_blank" rel="nofollow">조사에 따르면</a> 기업의 80%가 업무 환경에서 섀도 AI 사용을 경험하고 있다. 특히 HR은 민감한 직원 데이터를 보안이 취약한 플랫폼에 노출할 가능성이 높은 부서로 지목된다. <a href="https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications,-97-of-which-reported-lacking-proper-ai-access-controls#:~:text=IBM's%202025%20*Cost%20of%20a%20Data%20Breach,breaches%20studied%20involved%20attackers%20using%20AI%20tools**" target="_blank" rel="nofollow">IBM에 따르면</a> AI를 관리하거나 섀도 AI를 탐지하기 위한 정책을 갖춘 기업은 37%에 불과하다.</p>



<p>HR에서 섀도 AI는 여러 형태로 나타난다.<br>• 채용 담당자가 공개 생성형 AI를 활용해 채용 공고를 수정하거나 이력서를 선별하는 경우<br>• 관리자가 빠른 인사이트를 얻기 위해 직원 성과 데이터를 별도의 통제되지 않은 도구에 입력하는 경우<br>• 팀이 컴플라이언스 검증 없이 AI 어시스턴트를 실험적으로 도입해 직원 문의를 처리하는 사례 등이 대표적이다.</p>



<p>섀도 AI가 본질적으로 악의적인 것은 아니다. 맹목적 신뢰가 아니라 인간의 검토를 전제로 한다면 일부 활용은 문제가 되지 않을 수 있다. 그러나 이는 공식 역량을 넘어선 현장의 수요를 보여주는 신호이기도 하다. 동시에 그에 따른 위험도 분명히 존재한다.</p>



<p>승인되지 않은 사용은 데이터 유출, 규정 위반, 비윤리적 의사결정으로 이어질 수 있다. 특히 공정성이 핵심 가치로 작용하는 인재 채용 분야에서는 이러한 문제가 더욱 두드러질 수 있다.</p>



<h2 class="wp-block-heading">진짜 병목은 ‘변화 관리’다</h2>



<p>2025년 들어 또 하나 분명해진 흐름은 AI 도입 속도가 교육을 앞지르고 있다는 점이다. 여러 조사에 따르면 HR 전문가 사이에서 AI 활용은 빠르게 확산되고 있다. <a href="https://www.staffingindustry.com/editorial/it-staffing-report/ai-adoption-outpaces-training-in-hr-departments" target="_blank" rel="nofollow">최근 한 조사</a>에서는 활용 비율이 70%를 넘어선 것으로 나타났다. 그러나 실제로 직무에 특화된 AI 활용 교육을 받은 인원은 그중 일부에 그친다.</p>



<p>이와 관련해 워크데이(Workday)는 비교적 두드러진 사례로 꼽힌다. 워크데이는 일회성 교육이 아니라 직무에 맞춘 다단계 학습 여정에 집중 투자했다. 그 결과 직원의 약 80%가 AI 도구를 활용하도록 이끌었다고 <a href="https://fortune.com/2025/09/25/workday-got-80-percent-of-its-employees-to-use-ai" target="_blank" rel="nofollow">포춘은 전했다</a>.</p>



<p>이 대목은 CIO에게 중요한 시사점을 던진다. 병목은 AI 기술 자체가 아니다. 사람의 준비도다. 단계별 역량 개발과 역할별 맞춤 지원에 선제적으로 투자한 조직은, AI를 또 하나의 소프트웨어 도입 프로젝트로 취급한 조직보다 훨씬 큰 효과를 만들어내고 있다.</p>



<p>교육을 넘어 조직 문화의 뒷받침도 핵심 요소다. <a href="https://www.pwc.com/gx/en/issues/workforce/hopes-and-fears.html" target="_blank" rel="nofollow">PwC의 글로벌 조사에 따르면</a> AI에 대한 신뢰, 명확한 방향성, 조직 구성원 간 인식 정렬이 확보될 때 도입은 지속된다. 반대로 이러한 기반이 부족하면 도입은 정체된다. 이러한 변화는 위에서 아래로, 경영진의 의지에서 출발한다.</p>



<h2 class="wp-block-heading">기술 융합형 HR 직무의 부상</h2>



<p>긍정적인 진화이자 동시에 불균형한 도입의 단면을 보여주는 변화도 나타나고 있다. HR 내부에 기술 융합형 직무가 새롭게 등장하고 있다는 점이다. 피플 애널리틱스 엔지니어, HR AI 프로덕트 매니저, 인재 테크놀로지 리드와 같은 직함이 점점 보편화되고 있다. 전통적 HR과 현대적 기술 역량 사이의 간극을 메우려는 조직의 시도가 반영된 결과다.</p>



<p>조직이 실험 단계를 넘어가면서, 범용 데이터 사이언스 팀이나 기존 HR 직무만으로는 AI 기반 시스템을 온전히 책임지기 어렵다는 사실을 인식하고 있다. 이제는 HR 도메인에 대한 깊은 이해와 기술적 숙련도가 동시에 요구된다. 이러한 역할은 인간의 판단과 기계 지능이 만나는 지점에 자리한다. AI가 도출한 결과를 리더가 신뢰하고 실행할 수 있는 의사결정으로 전환하는 가교 역할을 수행한다.</p>



<p>여기서 얻을 수 있는 중요한 교훈은 분명하다. 효과적인 AI 도입은 단순히 기술을 배포하는 데 그치지 않는다. 이를 책임감 있게, 그리고 대규모로 운영할 수 있는 새로운 전문성을 조직 안에서 발굴하고 체계화하는 데 달려 있다.</p>



<h2 class="wp-block-heading">HR 리더를 위한 AI 도입 핵심 시사점</h2>



<p>HR 영역에서의 AI 도입은 활용 사례가 비교적 명확하고 데이터도 풍부하며, ROI를 창출할 수 있는 지점 또한 분명하다. 그럼에도 불구하고 도입 수준은 여전히 고르지 않다. 이는 유사한 과제가 산업 전반에 걸쳐 존재한다는 신호이기도 하다. AI를 도입하는 기업 전반에 적용할 수 있는 시사점은 다음과 같다.</p>



<p>• 거버넌스는 통제와 속도의 균형을 맞춰야 한다. 섀도 AI는 충족되지 않은 현장 수요와 빠른 기술 혁신이 결합된 결과다. 거버넌스 프레임워크는 단순히 도구 사용을 제한하는 데 그쳐서는 안 된다. 안전한 실험을 가능하게 하면서도 리스크를 관리할 수 있어야 한다.</p>



<p>• 기술 선택보다 변화 관리가 더 중요하다. 문제의 근본 원인은 대개 도구 자체가 아니다. 사람의 학습, 프로세스 재설계, 명확한 보상 체계에 대한 투자가 가장 진보한 모델을 좇는 것보다 훨씬 큰 가치를 만들어낸다.</p>



<p>• 역할은 진화해야 한다. 전통적인 조직도는 인간의 복잡성과 알고리즘 논리를 동시에 이해하는 융합형 인재를 충분히 반영하지 못한다. 이러한 역량을 신속히 발굴하고 채용하며 육성하는 일이 경쟁력을 유지하는 핵심 요소다.</p>



<p>HR에서의 AI는 일의 미래를 실제로 바꾸고 있다. 그러나 그 영향은 조직이나 활용 사례에 따라 균등하게 나타나지 않는다. 장기적으로 경쟁에서 앞설 기업은 전략적이고 책임 있는 AI 프로그램을 실행할 수 있는 역량과 조직 문화, 그리고 거버넌스 체계를 갖춘 곳이 될 것이다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.1 Preview should finally solve some WiFi performance issues]]></title>
<description><![CDATA[On top of the huge SteamOS 3.8 preview Valve put up recently, a smaller bug-fix release landed with SteamOS 3.8.1.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3393038/linux-tipps/steamos-381-preview-should-finally-solve-some-wifi-performance-issues/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393038/linux-tipps/steamos-381-preview-should-finally-solve-some-wifi-performance-issues/</guid>
<pubDate>Mon, 30 Mar 2026 14:37:49 +0200</pubDate>
<content:encoded><![CDATA[On top of the huge SteamOS 3.8 preview Valve put up recently, a smaller bug-fix release landed with SteamOS 3.8.1.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/03/steamos-3-8-1-preview-should-finally-solve-some-wifi-performance-issues/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The state of AI in HR: Big promises, uneven reality]]></title>
<description><![CDATA[AI conversation has shifted dramatically over the last year. In many cases, we’ve moved from AI pilots to AI that is really here in production. But how and where its truly driving value is far more complex than most AI-enabled businesses let on. Today, we face an AI adoption picture that’s not bi...]]></description>
<link>https://tsecurity.de/de/3385969/it-security-nachrichten/the-state-of-ai-in-hr-big-promises-uneven-reality/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3385969/it-security-nachrichten/the-state-of-ai-in-hr-big-promises-uneven-reality/</guid>
<pubDate>Fri, 27 Mar 2026 11:06:38 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI conversation has shifted dramatically over the last year. In many cases, we’ve moved from AI pilots to AI that is really here in production. But how and where its truly driving value is far more complex than most AI-enabled businesses let on. Today, we face an AI adoption picture that’s not binary (did we or didn’t we), but fragmented.  </p>



<p>Most programs can be defined by ambitious strategy at the top, patchy deployment in the middle and inconsistent impact on the ground. In HR, where jobs revolve around people, this uneven adoption isn’t just a technical issue. It’s a people problem.  </p>



<h2 class="wp-block-heading">The ‘say-do’ gap </h2>



<p>In boardrooms, the language around AI has shifted from if to how fast. But recent research reveals a stark maturity gap. In a <a href="https://hrexecutive.com/new-research-from-gartner-phenom-and-others-reveals-ais-roi-problem-plus-industry-roundup-and-news/?utm_source=chatgpt.com" target="_blank" rel="nofollow">2025 industry roundup</a>, 88% of HR tech leaders reported no significant ROI from their AI initiatives, despite positive adoption indicators — a sign that implementation isn’t delivering measurable business results yet. </p>



<p>Similarly, a <a href="https://www.ey.com/en_gl/insights/workforce/work-reimagined-survey?utm_source=chatgpt.com" target="_blank" rel="nofollow">global workforce survey from EY</a> found that while roughly nine out of ten employees use AI tools at work, only about 28% of organizations translated those deployments into high-value outcomes. </p>



<p>What this tells us is that while HR organizations may deploy AI tools, they’re not yet achieving the integrated process change necessary to shift key outcomes such as talent acquisition efficiency, retention or workforce planning. This disconnect mirrors broader enterprise patterns that include rapid experimentation without aligned operating models or measurement frameworks. </p>



<h2 class="wp-block-heading">Shadow AI: The manifestation of a broader enterprise challenge </h2>



<p>One of the most persistent barriers to controlled adoption is shadow AI. Research shows that <a href="https://xmcyber.com/blog/shadow-it-is-everywhere-xm-cyber-finds-80-of-companies-show-signs-of-unapproved-ai-activity/#:~:text=According%20to%20XM%20Cyber%2C%20over%2080%25%20of,code%2C%20customer%20PII%2C%20financial%20models%2C%20and%20credentials" target="_blank" rel="nofollow">80</a><a href="https://xmcyber.com/blog/shadow-it-is-everywhere-xm-cyber-finds-80-of-companies-show-signs-of-unapproved-ai-activity/#:~:text=According%20to%20XM%20Cyber%2C%20over%2080%25%20of,code%2C%20customer%20PII%2C%20financial%20models%2C%20and%20credentials" target="_blank" rel="nofollow">% of companies experience the use of shadow AI at work</a>, with HR among the functions most likely to expose sensitive employee data to insecure platforms. According to <a href="https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications,-97-of-which-reported-lacking-proper-ai-access-controls#:~:text=IBM's%202025%20*Cost%20of%20a%20Data%20Breach,breaches%20studied%20involved%20attackers%20using%20AI%20tools**" target="_blank" rel="nofollow">IBM</a>, only 37% have policies to manage AI or detect shadow AI.  </p>



<p>In HR, this can take shape in several ways: </p>



<ul class="wp-block-list">
<li>Recruiters using public generative AI to rewrite job descriptions or screen resumes </li>
</ul>



<ul class="wp-block-list">
<li>Managers inputting employee performance data into ungoverned tools for quick insights </li>
</ul>



<ul class="wp-block-list">
<li>Teams experimenting with AI assistants to manage employee questions without compliance vetting. </li>
</ul>



<p>Shadow AI isn’t inherently malicious, and in many scenarios, its use (when paired with human scrutiny, not blind trust) is fine. It is, however, an indicator of a demand outpacing formal capability, and the risk is real.  </p>



<p>Unauthorized use opens the door to data leakage, compliance violations and unethical decision-making. This can be especially apparent in functions like talent acquisition, where fairness is deeply important.  </p>



<h2 class="wp-block-heading">The real bottleneck: Change management </h2>



<p>Another clear pattern emerged in 2025: AI adoption is outpacing training. Multiple sources show that while adoption among HR professionals is rising (surpassing 70%, <a href="https://www.staffingindustry.com/editorial/it-staffing-report/ai-adoption-outpaces-training-in-hr-departments?utm_source=chatgpt.com" target="_blank" rel="nofollow">according to a recent survey</a>), only a fraction have received job-specific training on how to use AI effectively. </p>



<p>Our partner, Workday, has been one of the rare companies to excel in this area. HR leaders succeeded in getting nearly 80% of employees to use AI tools by investing deeply in tailored, multi-stage learning journeys rather than one-off sessions (<a href="https://fortune.com/2025/09/25/workday-got-80-percent-of-its-employees-to-use-ai/?utm_source=chatgpt.com" target="_blank" rel="nofollow"><em>Fortune</em></a>).  </p>



<p>This insight is critical for CIOs. AI isn’t the bottleneck; human preparedness is. Organizations that invest upfront in layered skills development and role-specific support create far more impact than those that treat AI like another software rollout. </p>



<p>Beyond training, cultural support matters deeply. A <a href="https://www.pwc.com/gx/en/issues/workforce/hopes-and-fears.html?utm_source=chatgpt.com" target="_blank" rel="nofollow">global PwC survey</a> underscored that trust, clarity and workforce alignment around AI shape whether adoption sticks or stalls. This comes from the top down.  </p>



<h2 class="wp-block-heading">The rise of technical HR roles </h2>



<p>A positive evolution, yet also a sign of uneven adoption, is the emergence of hybrid technical titles within HR. Titles like People Analytics Engineer, HR AI Product Manager and Talent Technology Lead are becoming more common. It’s a sign of the times,  as organizations try to bridge the gap between traditional and modern HR. </p>



<p>As organizations move beyond experimentation, they’re realizing that neither generic data science teams nor traditional HR roles can fully own AI-enabled systems. Deep HR domain knowledge and technical fluency are now critical. These roles sit at the intersection of human judgment and machine intelligence, translating AI outputs into decisions leaders can trust and act on.  </p>



<p>The important lesson here is that effective AI adoption isn’t just about deploying the technology itself, but surfacing new kinds of expertise that can operationalize it responsibly and at scale. </p>



<h2 class="wp-block-heading">Key AI takeaways for HR leaders  </h2>



<p>AI adoption is uneven in HR, even where use cases are well-defined, data is rich and ROI levers are clear. This is a sign that similar challenges exist across industries. Here are several takeaways that span across enterprises adopting AI:   </p>



<ul class="wp-block-list">
<li><strong>Governance needs to balance control with speed.</strong> Shadow AI is a product of unmet need and rapid innovation. Governance frameworks must enable safe experimentation, not just restrict tools. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Change management trumps technology choice.</strong> The tools themselves are rarely the root of the problem. Investing in human learning, process redesign, and clear incentives leads to far more value than chasing the most advanced models. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Roles must evolve.</strong> Traditional org charts don’t account for hybrid thinkers who can navigate human complexity and algorithmic logic. Identifying, recruiting and developing those skills (and fast) is essential to stay competitive.  </li>
</ul>



<p>AI in HR is shaping the future of work in real ways. But that impact isn’t evenly distributed across organizations or use cases. The companies that will win in the long run are those that built capability, culture and governance frameworks to deploy strategic, responsible AI programs.  </p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI – Ongoing coverage of its impact on the enterprise]]></title>
<description><![CDATA[Over the next few years, agentic AI is expected to bring not only rapid technological breakthroughs, but a societal transformation, redefining how we live, work and interact with the world. And this shift is happening quickly.  “By 2028, 33% of enterprise software applications will include agenti...]]></description>
<link>https://tsecurity.de/de/3375185/it-nachrichten/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3375185/it-nachrichten/agentic-ai-ongoing-coverage-of-its-impact-on-the-enterprise/</guid>
<pubDate>Tue, 24 Mar 2026 03:31:42 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Over the next few years, agentic AI is expected to bring not only rapid technological breakthroughs, but a societal transformation, <a href="https://www.computerworld.com/article/2514480/the-promise-and-peril-of-agentic-ai.html" data-type="link" data-id="https://www.computerworld.com/article/2514480/the-promise-and-peril-of-agentic-ai.html">redefining how we live, work and interact with the world</a>. And this shift is happening quickly.  “By 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, enabling 15% of day-to-day work decisions to be made autonomously,” according to research firm Gartner.</p>



<p>Unlike traditional AI, which typically follows preset rules or algorithms, agentic AI adapts to new situations, learns from experiences, and operates independently to pursue goals without human intervention. In short, agentic AI empowers systems to act autonomously, making decisions and executing tasks — even communicating directly with other AI agents — with little or no human involvement.</p>



<p>Agentic AI will enable machines to interact with the physical world with unprecedented intelligence, allowing them to perform complex tasks in dynamic environments, which could be especially useful for industries facing labor shortages or hazardous conditions.However, the rise of agentic AI also brings security and ethical concerns. Ensuring these autonomous systems operate safely, transparently and responsibly will require governance frameworks and testing.</p>



<p>Follow this page for ongoing agentic AI coverage from <em>Computerworld</em> and Foundry’s other publications.</p>



<h2 class="wp-block-heading">Agentic AI news and insights</h2>



<h3 class="wp-block-heading">Cisco goes all in on agentic AI security</h3>



<p><em>March 26, 2026</em>: Cisco is rolling out identity and access management capabilities, a toolkit customers can use to <a href="https://www.networkworld.com/article/4148823/cisco-goes-all-in-on-agentic-ai-security.html">embed security controls in AI agents</a>, and automation features that will allow security operations teams to quickly see and respond to problems.</p>



<h3 class="wp-block-heading">AI agents still need humans to teach them</h3>



<p><em>February 20, 2026</em>: <a href="https://www.computerworld.com/article/4135331/ai-agents-still-need-humans-to-teach-them.html">AI agents need skills</a> — specific procedural knowledge — to perform tasks well, but they can’t teach themselves, a new research suggests.</p>



<h3 class="wp-block-heading">Why most agentic AI projects stall before they scale</h3>



<p><em>February 18, 2026</em>: As enterprises race from pilots to autonomous systems, rising costs, fragile governance, and unrealistic expectations are forcing a reckoning. <a href="https://www.cio.com/article/4132031/why-most-agentic-ai-projects-stall-before-they-scale.html">So what separates agentic AI initiatives that survive</a> from those that quietly shut down?</p>



<h3 class="wp-block-heading">How agentic AI helps prospective and existing students at DeVry</h3>



<p><em>February 18, 2026</em>: DeVry is no stranger to AI. It’s used the technology in its classrooms for 10 years and started experimenting with NLP bots and gen AI use cases for internal use as soon as it became widely available. So in <a href="https://www.cio.com/article/4132196/how-agentic-ai-helps-prospective-and-existing-students-at-devry.html">April 2025, Devry University deployed its first AI agent</a>.</p>



<h3 class="wp-block-heading">Task management software gets an agentic boost</h3>



<p><em>February 11, 2026</em>: Task management apps aren’t just for storing and tracking data — they act on it. <a href="https://www.computerworld.com/article/1721258/task-management-apps-collaborative-project-tracking-tools-for-the-digital-workplace.html">Explore tools that tap AI to auto-generate workflows</a>, balance team capacity, and eliminate administrative overhead.</p>



<h3 class="wp-block-heading">OpenClaw: The AI agent that’s got humans taking orders from bots</h3>



<p><em>February 6, 2026</em>: How one man’s vibe-coding session evolved into a <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html">reckless global AI experiment</a> where nobody’s accountable.</p>



<h3 class="wp-block-heading">Forward Networks launches agentic AI system built on network digital twin</h3>



<p><em>January 30, 2026</em>: The new <a href="https://www.networkworld.com/article/4125111/forward-networks-launches-agentic-ai-system-built-on-network-digital-twin.html">Forward AI capability builds on the vendor’s digital twin</a> and is designed to allow network teams to ask complex questions, understand network behavior, validate outcomes and safely automate workflows.</p>



<h3 class="wp-block-heading">Agentic AI exposes what we’re doing wrong</h3>



<p><em>January 23, 2026:</em> <a href="https://www.infoworld.com/article/4120858/agentic-ai-exposes-what-were-doing-wrong.html">Agentic AI has changed cloud computing</a>, but not in the way the hype machine wants you to believe. It hasn’t magically replaced engineering, nor has it made architecture irrelevant. </p>



<h3 class="wp-block-heading">How to get your enterprise architecture ready for agentic AI</h3>



<p><em>January 22, 2026</em>: While <a href="https://www.cio.com/article/4119297/how-to-get-your-enterprise-architecture-ready-for-agentic-ai.html">C-suite leaders say they’re investing in agentic AI</a>, the complex enterprise architectures of large organizations often struggle with the tech’s demands.</p>



<h3 class="wp-block-heading">IBM targets agentic AI scale-up with new Enterprise Advantage consulting service</h3>



<p><em>January  20, 2026</em>: IBM has launched a new consulting service named Enterprise Advantage, designed to <a href="https://www.cio.com/article/4119056/ibm-targets-agentic-ai-scale-up-with-new-enterprise-advantage-consulting-service.html">help CIOs take their agentic and other AI applications</a> from experimentation to large-scale production.</p>



<h3 class="wp-block-heading">EY exec: If you think agentic AI is a challenge, you’re not ready for what’s coming</h3>



<p><em>January 15, 2026</em>: Companies struggling to keep up with the arrival of AI agents should buckle up: Even <a href="https://www.computerworld.com/article/4117377/ey-exec-if-you-think-agentic-ai-is-a-challenge-youre-not-ready-for-whats-coming.html">more complicated agentic AI technologies</a> are quickly coming down the pike. That includes physical AI, which includes robots and quantum computing. </p>



<h3 class="wp-block-heading">Managing agentic AI risk: Lessons from the OWASP Top 10</h3>



<p><em>December 19, 2025</em>: <a href="https://www.csoonline.com/article/4109123/managing-agentic-ai-risk-lessons-from-the-owasp-top-10.html">LLM-powered chatbots have risks</a> that we see playing out in the headlines on a nearly daily basis. But chatbots are limited to answering questions. AI agents, however, access data and tools and carry out tasks, making them infinitely more capable – and more dangerous to enterprises.</p>



<h3 class="wp-block-heading">Agentic AI in 2026: More mixed than mainstream</h3>



<p><em>December 18, 2025:</em> Agentic AI is having its everything, everywhere, all at once moment. Or is it? Data clarifies. While 39% of organizations surveyed by McKinsey say they are experimenting with agents, <a href="https://www.cio.com/article/4107315/agentic-ai-in-2026-more-mixed-than-mainstream.html">only 23% have begun scaling AI agents</a> within one business function</p>



<h3 class="wp-block-heading">Overcome governance and trust issues to drive agentic AI</h3>



<p><em>December 18, 2025</em>: Fully autonomous agentic AI is still way off but <a href="https://www.cio.com/article/4105490/overcome-governance-and-trust-issues-to-drive-agentic-ai.html">AI agents are making inroads within enterprise software</a> and workflows. Gartner predicts 40% of enterprise software will feature task-specific AI agents by the end of 2026 as the current trend for embedded AI assistants evolves.</p>



<h3 class="wp-block-heading">Nvidia bets on open infrastructure for the agentic AI era with Nemotron 3</h3>



<p><em>Decenber 15, 2025</em>: <a href="https://www.infoworld.com/article/4106756/nvidia-bets-on-open-infrastructure-for-the-agentic-ai-era-with-nemotron-3.html">AI agents must be able to cooperate, coordinate, and execute</a> across large contexts and long time periods, and this, says Nvidia, demands a new type of infrastructure, one that is open. The company says it has the answer with its new Nemotron 3 family of open models.</p>



<h3 class="wp-block-heading">Microsoft drops M365 Copilot price for SMBs, upgrades free Copilot Chat</h3>



<p><em>November 19, 2025</em>: Microsoft announced that it <a href="https://www.computerworld.com/article/4093224/microsoft-drops-m365-copilot-price-for-smbs-upgrades-free-copilot-chat.html">reduce the price of Microsoft 365 Copilot for small and mid-sized firms</a> beginning next month. Microsoft 365 Copilot for Business will cost $21 per user, per month for customers with any Microsoft 365 Business plan. That’s down from the current $30 monthly price.</p>



<h3 class="wp-block-heading">Microsoft Fabric IQ adds ‘semantic intelligence’ layer to Fabric</h3>



<p><em>November 19, 2025</em>: Microsoft promises enterprises better understanding of their data for workers and <a href="https://www.infoworld.com/article/4093181/microsoft-fabric-iq-adds-semantic-intelligence-layer-to-fabric.html">autonomous agents</a> alike, but analysts fear deployment hurdles and vendor lock-in.</p>



<h3 class="wp-block-heading">Microsoft unveils Agent 365 to help IT manage AI ‘agent sprawl’</h3>



<p><em>November 18, 2025:</em> As businesses begin deploying AI agents in greater numbers, IT teams will need to manage and secure those AI systems as they connect to corporate data. That’s the idea behind Microsoft’s Agent 365 (A365), a new “control plane” that lets customers deploy and govern the use of agents. </p>



<h3 class="wp-block-heading">From chatbots to colleagues: How agentic AI is redefining enterprise automation</h3>



<p><em>November 17, 2025</em>: <a href="https://www.computerworld.com/article/4083589/from-chatbots-to-colleagues-how-agentic-ai-is-redefining-enterprise-automation.html">A new wave of agentic AI</a> is taking shape: systems that not only converse but also reason, plan, and act within enterprise workflows. These agents are not assistants that talk; they are digital colleagues that think.</p>



<h3 class="wp-block-heading">The enterprise IT overhaul: Architecting your stack for the agentic AI era</h3>



<p><em>November 10, 2025</em>: For the CIO, the conversation has officially moved past the large language model (LLM). <a href="https://www.cio.com/article/4086719/the-enterprise-it-overhaul-architecting-your-stack-for-the-agentic-ai-era.html">The next critical chapter is agentic AI </a>— autonomous systems capable of reasoning, planning and executing multi-step tasks across your enterprise. Agentic AI is here. Now, CIOs must orchestrate</p>



<p><em>October 23, 2025</em>: Agentic AI is about to change how companies create value.  Yet, most enterprises aren’t ready. The problem isn’t the technology — it’s the planning and execution. Too <a href="https://www.cio.com/article/4076519/agentic-ai-is-here-now-cios-must-orchestrate.html">many pilots stall out because CIOs haven’t built the AI systems</a>, guardrails and culture to move beyond experiments. </p>



<h3 class="wp-block-heading">AI agents might smooth some of retail’s worst data problems</h3>



<p><em>October 21, 2025</em>: So many retail challenges hinge on unreliable product data. <a href="https://www.computerworld.com/article/4074007/ai-agents-might-smooth-some-of-retails-worst-data-problems.html">Can agentic AI clean up that data enough</a> to make a difference? Can it do the same for other verticals?</p>



<h3 class="wp-block-heading">The impact of agentic AI on SaaS and partner ecosystems</h3>



<p><em>October 16, 2025</em>: The enterprise technology landscape is entering a <a href="https://www.cio.com/article/4072984/the-impact-of-agentic-ai-on-saas-and-partner-ecosystems.html">critical pivot point as agentic AI transforms partner ecosystems</a> from human-mediated, application integration networks into autonomous, self-orchestrating and intelligent ecosystems.</p>



<h3 class="wp-block-heading">Salesforce updates its agentic AI pitch with Agentforce 360</h3>



<p><em>October 13  2025</em>:  Salesforce announced a new release of Agentforce that, it says, “gives teams the <a href="https://www.cio.com/article/4071597/salesforce-updates-its-agentic-ai-pitch-with-agentforce-360.html">fastest path from AI prototypes to production-scale agents</a>” — although with many of the new release’s features still to come, or yet to enter pilot phases or beta testing, some parts of that path will be much slower than others.</p>



<h3 class="wp-block-heading">Gemini Enterprise is Google’s new ‘front door’ for agentic AI access at work</h3>



<p><em>October 9, 2025</em>: Google introduced an AI assistant to serve as a platform so users can access and <a href="https://www.computerworld.com/article/4070253/gemini-enterprise-is-googles-new-front-door-for-agentic-ai-access-at-work.html">coordinate AI agents that automate work tasks</a>. Gemini Enterprise, which replaces the Agentspace app launched last year, also features new enterprise search functions to help customers tap into data from across an organization’s business apps. </p>



<h3 class="wp-block-heading">Oracle’s agentic AI push in Fusion Cloud CX offers embedded automation for CX leaders</h3>



<p>October 7, 2025: <a href="https://www.cio.com/article/4068707/oracles-agentic-ai-push-in-fusion-cloud-cx-offers-embedded-automation-for-cx-leaders.html">Oracle is adding new pre-built agents</a> to its Advertising and Customer Experience Cloud (Fusion Cloud CX) to help enterprises increase operational efficiency by automating sales, service, and marketing processes.</p>



<h3 class="wp-block-heading">IBM touts agentic AI orchestration, cryptographic risk controls</h3>



<p><em>October 7, 2025</em>: IBM watsonx Orchestrate offers more than 500 tools and customizable, domain-specific agents from IBM and third-party contributors. Among the additions to watsonx Orchestrate are <a href="https://www.networkworld.com/article/4068958/ibm-touts-agentic-ai-orchestration-cryptographic-risk-controls.html">AgentOps capabilities </a>that offer real-time monitoring and policy-based controls for observability and governance.</p>



<h3 class="wp-block-heading">How self-learning AI agents will reshape operational workflows</h3>



<p><em>October 6, 2025</em>: Google’s recent whitepaper, “Welcome to the Era of Experience,” signals a shift in the way AI agents are trained. Google hypothesizes that allowing <a href="https://www.infoworld.com/article/4067840/how-self-learning-ai-agents-will-reshape-operational-workflows.html">AI agents to learn from the experience of agents </a>rather than solely from human-generated training data will enable autonomous AI to surpass its current capabilities.</p>



<h3 class="wp-block-heading">Are your agentic AI projects driving toward success?</h3>



<p><em>October 3, 2025:</em> Anushree Verma, Gartner senior director analyst, says most <a href="https://www.cio.com/article/4067338/ai-agentics-key-factors-for-steering-projects-toward-success.html">agentic AI projects today are early-stage experiments or proofs of concept</a>, fueled primarily by hype and often misapplied.</p>



<h3 class="wp-block-heading">Microsoft unveils framework for building agentic AI apps</h3>



<p><em>October 3. 2025</em>:<a href="https://www.infoworld.com/article/4067500/microsoft-unveils-framework-for-building-agentic-ai-apps.html"> Microsoft has introduced the Microsoft Agent Framework</a>, an open-source SDK and runtime for building, orchestrating, and deploying AI agents and multi-agent workflows, with full framework support for .NET and Python.</p>



<h3 class="wp-block-heading">Salesforce Trusted AI Foundation seeks to power the agentic enterprise</h3>



<p><em>October 2, 2025</em>: As <a href="https://www.cio.com/article/4066640/salesforce-trusted-ai-foundation-provides-scaffolding-for-the-agentic-enterprise.html">Salesforce pushes further into agentic AI</a>, its aim is to evolve Salesforce Platform from an application for building AI to a foundational operating system for enterprise AI ecosystems. </p>



<h3 class="wp-block-heading">ServiceNow’s AI Experience is an agentic AI UI for the Now Platform</h3>



<p><em>September 30, 2025</em>: ServiceNow today launched the AI Experience (AIx), <a href="https://www.cio.com/article/4065541/servicenows-ai-experience-is-an-agentic-ai-ui-for-the-now-platform.html">a contextually aware multimodal AI-driven use UI for its Now platform</a>. Building on the <a href="https://www.cio.com/article/4054799/servicenow-zurich-release-introduces-agentic-ai-to-the-platform.html">ServiceNow AI Platform</a> and with a foundation in Now Assist, the company describes it as “a unified, conversational front door to enterprise AI.”</p>



<h3 class="wp-block-heading">How MCP is making AI agents actually do things in the real world</h3>



<p><em>September 29, 2025</em>: You’ve seen them: Those incredible large language models (LLMs) that can chat, write and even generate code. They’ve revolutionized how we interact with technology, but there’s a new, even more exciting chapter unfolding.  Discover how <a href="https://www.infoworld.com/article/4064169/how-mcp-is-making-ai-agents-actually-do-things-in-the-real-world.html">MCP is turning chatbots into doers</a>, and the future of work may never look the same.</p>



<h3 class="wp-block-heading">Agentic AI in IT security: Where expectations meet reality</h3>



<p><em>September 29, 2025</em>: <a href="https://www.csoonline.com/article/4064158/agentic-ai-in-it-security-where-expectations-meet-reality.html">Agentic AI has shifted from lab demos to real-world SOC</a> deployments. Unlike traditional automation scripts, software agents are designed to act on signals and execute security workflows intelligently, correlating logs, enriching alerts, and even take first-line containment actions.</p>



<h3 class="wp-block-heading">Walmart looks to cash in on agentic AI</h3>



<p><em>September 19, 2025</em>: <a href="https://www.cio.com/article/4059020/walmart-looks-to-cash-in-on-agentic-ai.html">Walmart doesn’t intend to lose its retail crown anytime soon</a>. And, according to US EVP and CTO Hari Vasudev, the $815B company’s artificial intelligence strategy will play a key role in preventing that from happening.</p>



<h3 class="wp-block-heading">5 steps for deploying agentic AI red teaming</h3>



<p><em>September 17, 2025</em>: As more enterprises deploy agentic AI applications, the potential attack surface increases in complexity and reach. But there is still hope that <a href="https://www.csoonline.com/article/4055224/5-steps-for-deploying-agentic-ai-red-teaming.html">AI agents can be harnessed for defensive purposes</a> too, including using traditional red teaming and penetration testing techniques but updated for the AI world.</p>



<h3 class="wp-block-heading">Google unveils payments protocol for AI agents with major financial firms</h3>



<p><em>September 17. 2025</em>: Google has introduced the Agent Payments Protocol (AP2), an open framework developed with more than 60 payments and technology companies to support <a href="https://www.computerworld.com/article/4058571/google-unveils-payments-protocol-for-ai-agents-with-major-financial-firms.html">secure, agent-led transactions</a> across platforms and payment methods.</p>



<h3 class="wp-block-heading">CrowdStrike bets big on agentic AI with new offerings after $290M Onum buy</h3>



<p><em>September 16, 2025</em>: At its Fal.Con conference, the cybersecurity giant <a href="https://www.csoonline.com/article/4057472/crowdstrike-bets-big-on-agentic-ai-with-new-offerings-after-290m-onum-buy.html">launched its Agentic Security Platform and Agentic Security Workforce</a>, aiming to outpace AI-driven adversaries with real-time intelligence, automation, and a common language for defense.</p>



<h3 class="wp-block-heading">Adobe makes Agent Orchestrator and AI agents generally available</h3>



<p><em>September 10, 2025</em>:  Adobe Experience Platform (AEP) Agent Orchestrator and six new AI agents are designed to build, deliver, and optimize customer experience and marketing campaigns. The company also announced Experience Platform Agent Composer for customizing and configuring <a href="https://www.cio.com/article/4054211/adobe-makes-agent-orchestrator-and-ai-agents-generally-available.html">AI agents based on brand guidelines and organizational policy</a>.</p>



<h3 class="wp-block-heading">Rethinking the IT organization for the agentic AI era</h3>



<p><em>September 2, 2025:</em> With the <a href="https://www.cio.com/article/4046473/rethinking-the-it-organization-for-the-agentic-ai-era.html">advent of agentic AI</a>, CIOs must be poised to adjust strategic IT priorities, mitigate new security risks, and reskill staff for a new era.</p>



<h3 class="wp-block-heading">How to build a production-grade agentic AI platform</h3>



<p><em>September 2, 2025</em>: Modular orchestration, fail-safe design, hybrid memory management, and LLM integration with domain knowledge are essential to <a href="https://www.infoworld.com/article/4037795/how-to-build-a-production-grade-agentic-ai-platform-lessons-from-gravity.html">agentic AI systems</a> that reason, act, and adapt at scale.</p>



<h3 class="wp-block-heading">Agentic AI: A CISO’s security nightmare in the making?</h3>



<p><em>September 2, 2025</em>: Enterprises will no doubt be using agentic AI for a growing number of workflows and processes, including software development, customer support automation, and more. But what are the c<a href="http://enterprises%20will%20no%20doubt%20be%20using%20agentic%20ai%20for%20a%20growing%20number%20of%20workflows%20and%20processes,%20including%20software%20development,%20customer%20support%20automation,%20robotic%20process%20automation%20(rpa),%20and%20employee%20support.%20among%20the%20key%20questions%20for%20cisos%20and%20their%20staffs/">ybersecurity risks of agentic AI</a>, and how much more work will it take for them to support their organizations’ agentic AI dreams?</p>



<h3 class="wp-block-heading">Microsoft researchers develop new tech for video AI agents</h3>



<p><em>September 2, 2025</em>: Microsoft researchers are developing technologies for a <a href="https://www.computerworld.com/article/4049703/microsoft-researchers-develop-new-tech-for-video-ai-agents.html">new class of video AI agents</a> to explore three-dimensional spaces before making decisions.The technology framework, called MindJourney, uses a range of AI technologies to understand and analyze 3D spaces, reason about the surroundings, and predict movement</p>



<h3 class="wp-block-heading">Salesforce AI Research unveils new tools for AI agents</h3>



<p><em>August 27, 2025</em>: Salesforce announced a simulated enterprise environment, benchmark, and account data unification tool that are designed to help customers transform into <a href="https://www.cio.com/article/4046713/salesforce-ai-research-unveils-new-tools-for-ai-agents.html">agentic AI enterprises</a>.</p>



<h3 class="wp-block-heading">Agentic AI promises a cybersecurity revolution — with asterisks</h3>



<p><em>August 18, 2025:</em> The hottest topic at this year’s Black Hat conference was the meteoric <a href="https://www.csoonline.com/article/4040145/agentic-ai-promises-a-cybersecurity-revolution-with-asterisks.html">emergence of AI tools for both cyber adversaries and defenders</a>, particularly the use of agentic AI to strengthen cybersecurity programs.</p>



<h3 class="wp-block-heading">4 thoughts on who should manage AI agents</h3>



<p>August 11, 2025: As AI agents proliferate, we need to turn our attention beyond AI agent builder platforms to AI orchestration and AI GRC platforms. It also raises questions about which <a href="https://www.cio.com/article/4036809/4-thoughts-on-who-should-manage-ai-agents.html">groups within the enterprise should manage AI agents </a>and how they should be treated.</p>



<h3 class="wp-block-heading">How bright are AI agents? Not very, recent reports suggest</h3>



<p><em>July 31, 2025</em>: Security researchers are adding more weight to a truth that infosec pros had already grasped: <a href="https://www.csoonline.com/article/4032291/how-bright-are-ai-agents-not-very-recent-reports-suggest.html">AI agents are not very bright</a>, and are easily tricked into doing stupid or dangerous things</p>



<h3 class="wp-block-heading">Will AI agents eat the SaaS market? Experts are split</h3>



<p><em>July 31,2025</em>: As hype about AI agents reaches new heights, an emerging theory suggests that the groundbreaking <a href="https://www.cio.com/article/4028997/will-ai-agents-eat-the-saas-market-experts-are-split.html">AI tools will kill the SaaS business model. </a>The claim isn’t particularly new, but is resurfacing, with people like Microsoft CEO Satya Nadella voicing this position. </p>



<h3 class="wp-block-heading">How agentic AI will change database management</h3>



<p>July 28, 2025: Generative AI has already had a profound impact on the world of database management. And now,  thanks to AI’s knack for pattern-recognition, teams can <a href="https://www.infoworld.com/article/4028146/how-agentic-ai-will-change-database-management.html">use generative AI to analyze data sets, </a>detect anomalies, and access invaluable insights with record speed and precision. </p>



<h3 class="wp-block-heading">As AI agents go mainstream, companies lean into confidential computing for data security</h3>



<p><em>July 21, 2025</em>: Companies need to stop ignoring data security as AI agents take over internal data movement in IT environments, analysts and IT execs warn.  To address that issue, some tech players are embracing the concept of “confidential computing.” While it’s existed for years, it;s now finding new life with the rise of genAI.</p>



<h3 class="wp-block-heading">How agentic AI will transform mobile apps and field operations</h3>



<p><em>July 15, 2015</em>: <a href="https://www.infoworld.com/article/4019656/how-agentic-ai-will-transform-mobile-apps-and-field-operations.html" data-type="link" data-id="https://www.infoworld.com/article/4019656/how-agentic-ai-will-transform-mobile-apps-and-field-operations.html">Agentic AI will usher in new mobile AI experiences</a>. Construction, manufacturing, healthcare, and other industries with significant field operations will benefit from mobile AI agents and the resulting operational agility. </p>



<h3 class="wp-block-heading">MCP is fueling agentic AI — and introducing new security risks</h3>



<p><em>July 10, 2025</em>: Model Context Protocol (MCP)  has caught fire, with several thousand MCP servers now available from a wide range of vendors enabling AI assistants to connect to their data and services. And with agentic AI increasingly seen as the future of IT, MCP will only grow in use in the enterprise. But innovations like <a href="https://www.csoonline.com/article/4015222/mcp-uses-and-risks.html">MCP also come with significant security risks</a>.</p>



<h3 class="wp-block-heading">3 industries where agentic AI is poised to make its mark</h3>



<p>July 4, 2024:  IT leaders from finance, retail, and healthcare lend insights into <a href="https://www.cio.com/article/4016392/how-agentive-ai-is-making-an-impact-an-industry-by-industry-overview.html">what organizations are doing with AI agents</a> today — and where they see the technology taking their organizations and industries in the future.</p>



<h3 class="wp-block-heading">IFS rolls TheLoops agentic AI into industrial ERP</h3>



<p><em>June 27, 2025:</em> <a href="https://www.cio.com/article/4014112/ifs-rolls-theloops-agentic-ai-into-industrial-erp.html">IFS is adding AI agent development and management capabilities</a> to its ERP platform with the acquisition of software startup The acquisition brings TheLoops’ full Agent Development life cycle (ADLC) platform into IFS, enabling enterprises to design, test, deploy, monitor, and fine-tune AI agents with built-in support for versioning, compliance, and performance optimization.</p>



<h3 class="wp-block-heading">How AI agents and agentic AI differ from each other</h3>



<p><em>June 12, 2025</em>: With agentic AI in its infancy and organizations rushing to adopt AI agents, there seems to be confusion about <a href="https://www.cio.com/article/4003880/how-ai-agents-and-agentic-ai-differ-from-each-other.html">the difference between “agentic AI” and “AI agents” technologies</a>, but experts say there’s growing understanding that the two are separate, but related, tools. </p>



<h3 class="wp-block-heading">The future of RPA ties to AI agents</h3>



<p>June 10, 2025: RPA is accelerating toward a crossroads, with IT leaders and experts debating its future. Some IT leaders say that more powerful and autonomous AI agents will replace the two-decade-old AI precursor technology, while others predict that <a href="https://www.cio.com/article/4001371/the-future-of-rpa-ties-to-ai-agents.html">AI agents and RPA </a>will work hand-in-hand.</p>



<h3 class="wp-block-heading">MCP is enabling agentic AI, but how secure is it?</h3>



<p><em>June 2, 2025</em>: Model context protocol<a href="https://www.cio.com/article/3997968/mcp-is-enabling-agentic-ai-but-how-secure-is-it.html"> (MCP) is becoming the plug-and-play standard for agentic AI</a> apps to pull in data in real time from multiple sources. However, this also makes it more attractive for malicious actors looking to exploit weaknesses in how MCP has been deployed. </p>



<h3 class="wp-block-heading">The agentic AI assist Stanford University cancer care staff needed</h3>



<p><em>May 30, 2025</em>: At Microsoft Build 2025 earlier this month, Nigam Shah, CDO for Stanford Health Care, discussed <a href="https://www.cio.com/article/3997951/stanford-university-alleviates-oncology-healthcare-worker-overload-with-agentive-ai.html">agentic AI’s ability to redefine healthcare</a>, especially in oncology, as physicians get overloaded with the administrative tasks of medicine, he said, which lead to burnout.</p>



<h3 class="wp-block-heading">Agentic AI, LLMs and standards big focus of Red Hat Summit</h3>



<p><em>May 26, 2025</em>: Red Hat, announced a number of improvements in its core enterprise Linux product, including better security, better support for containers, better support for edge devices. But the <a href="https://www.networkworld.com/article/3993622/agentic-ai-llms-and-standards-big-focus-of-red-hat-summit.html">one topic that dominated the conversation was AI</a>.</p>



<h3 class="wp-block-heading">Putting agentic AI to work in Firebase Studio</h3>



<p><em>May 21, 2025</em>: Putting agentic AI to work in software engineering can be done in a variety of ways. Some agents work independently of the developer’s environment, working essentially like a remote developer. Other <a href="https://www.infoworld.com/article/3981588/putting-agentic-ai-to-work-in-firebase-studio.html?utm_date=20250521140633&amp;utm_campaign=Infoworld%20US%20First%20Look&amp;utm_content=slotno-1-readmore-Building%20a%20database-backed%20web%20application%20with%20Gemini%20in%20Firebase%20is%20far%20from%20perfect%2C%20but%20it%E2%80%99s%20better%20than%20coding%20without%20AI.%20&amp;utm_term=Infoworld%20US%20Editorial%20Newsletters&amp;utm_medium=email&amp;utm_source=Adestra&amp;aid=2255020&amp;huid=0b2f6c0f-9f15-45f8-bd06-4e1810ba35be">agents directly within a developer’s own environment</a>. Google’s Firebase Studio is an example of the latter, drawing on Google’s Gemini LLM o help developers prototype and build applications .</p>



<h3 class="wp-block-heading">Why is Microsoft offering to turn websites into AI apps with NLWeb?</h3>



<p><em>May 20. 2025</em>: NLWeb, short for Natural Language Web, is designed to help enterprises build a natural language interface for their websites using the model of their choice and data to answer user queries about the contents of the website.<a href="http://microsoft%E2%80%99s%20strategy%20to%20stake%20its%20claim%20on%20the%20agentic%20web%20before%20rivals%20such%20as%20google%20and%20amazon%20do/"> Microsoft hopes to stake its claim on the agentic web </a>before rivals Google and Amazon do.</p>



<h3 class="wp-block-heading">Databricks to acquire open-source database startup Neon to build the next wave of AI agents</h3>



<p><em>May 14, 2025</em>: Agentic AI requires a new type of architecture because traditional workflows create gridlock, dragging down speed and performance. To get ahead in this next generation of app building, <a href="https://www.infoworld.com/article/3985947/databricks-to-acquire-open-source-database-startup-neon-to-build-the-next-wave-of-ai-agents.html">Databricks announced it will purchase Neon</a>, an open-source serverless Postgres company. </p>



<h3 class="wp-block-heading">Agentic mesh: The future of enterprise agent ecosystems</h3>



<p><em>May 13, 2025</em>: Nvidia CEO Jensen Huang predicts we’ll soon see “a couple of hundred million digital agents” inside the enterprise. Microsoft CEO Satya Nadella takes it even further: “<a href="https://www.infoworld.com/article/3978819/agentic-mesh-the-future-of-enterprise-agent-ecosystems.html">Agents will replace all software</a>.”</p>



<h3 class="wp-block-heading">Google to unveil AI agent for developers at I/O, expand Gemini integration</h3>



<p><em>May 13, 2025</em>: <a href="https://www.computerworld.com/article/3984016/google-to-unveil-ai-agent-for-developers-at-i-o-expand-gemini-integration.html">Google is expected to unveil a new AI agent </a>aimed at helping software developers manage tasks across the coding lifecycle, including task execution and documentation. The tool has reportedly been demonstrated to employees and select external developers ahead of the company’s annual I/O conference.</p>



<h3 class="wp-block-heading">Nvidia, ServiceNow engineer open-source model to create AI agents</h3>



<p><em>May 6, 2025</em>: <a href="https://www.computerworld.com/article/3978481/nvidia-servicenow-engineer-open-source-model-to-create-ai-agents.html">Nvidia and ServiceNow have created an AI model</a> that can help companies create learning AI agents to automate corporate workloads. The open-source Apriel model, available generally in the second quarter on HuggingFace, will help create AI agents that can make decisions around IT, human resources and customer-service functions.</p>



<h3 class="wp-block-heading">How IT leaders use agentic AI for business workflows</h3>



<p><em>April 30, 2025</em>: Jay Upchurch, CIO at SAS, backs <a href="https://www.cio.com/article/3966870/how-it-leaders-use-agentic-ai-for-business-workflows.html">agentic AI to enhance sales, marketing, IT, and HR motions</a>. “Agentic AI can make sales more effective by handling lead scoring, assisting with customer segmentation, and optimizing targeted outreach,” he says.</p>



<h3 class="wp-block-heading">Microsoft sees AI agents shaking up org charts, eliminating traditional functions</h3>



<p><em>April 28, 2025</em>: As companies increasingly automate work processes using agents, traditional functions such as finance, marketing, and engineering may fall away, giving <a href="https://www.cio.com/article/3972714/ms-ai-agents-become-teammates-a-new-enterprise-form-emerges.html">rise to an ‘agent boss’ era of delegation</a> and orchestration of myriad bots.</p>



<h3 class="wp-block-heading">Cisco automates AI-driven security across enterprise networks</h3>



<p><em>April 28, 2025</em>: Cisco announced a range of AI-driven security enhancements, including improved threat detection and response capabilities in Cisco XDR and Splunk Security, <a href="https://www.networkworld.com/article/3972640/cisco-automates-ai-driven-security-across-enterprise-networks.html">new AI agents</a>, and integration between Cisco’s AI Defense platform and ServiceNow SecOps.</p>



<h3 class="wp-block-heading">Hype versus execution in agentic AI</h3>



<p>April 25, 2025: <a href="https://www.infoworld.com/article/3970002/hype-versus-execution-in-agentic-ai.html">Agentic AI promises autonomous systems</a> capable of reasoning, making decisions, and dynamically adapting to changing conditions. The allure lies in machines operating independently, free of human intervention, streamlining processes and enhancing efficiency at unprecedented scales. But  David Linthicum writes, don’t be swept up by ambitious promises. </p>



<h3 class="wp-block-heading">Agents are here — but can you see what they’re doing?</h3>



<p>April 23, 2025: As the <a href="https://www.cio.com/article/3959486/agents-are-here-but-can-you-see-what-theyre-doing.html">agentic AI models powering individual agents get smarter</a>, the use cases for agentic AI systems get more ambitious — and the risks posed by these systems increase exponentially.A multicloud experiment in agentic AI: Lessons learned</p>



<h3 class="wp-block-heading">Agentic AI might soon get into cryptocurrency trading — what could possibly go wron</h3>



<p><em>April 15, 2025</em>: <a href="https://www.computerworld.com/article/3959170/agentic-ai-might-soon-get-into-cryptocurrency-trading-what-could-possibly-go-wrong.html">Agentic AI promises to simplify complex tasks</a> such as crypto trading or managing digital assets by automating decisions, enhancing accessibility, and masking technical complexity.</p>



<h3 class="wp-block-heading">Agentic AI is both boon and bane for security pros</h3>



<p><em>April 15, 2025</em>:  <a href="https://www.csoonline.com/article/3957719/agentic-ai-is-both-boon-and-bane-for-security-pros.html">Cybersecurity is at a crossroads with agentic AI</a>. It’s a powerful tool that can create reams of code in a blink of an eye, find and defuse threats, and be used so decisively and defensively. This has proved to be a huge force multiplier and productivity boon. But while powerful, agentic AI isn’t dependable, and that is the conundrum. </p>



<h3 class="wp-block-heading">AI agents vs. agentic AI: What do enterprises want?</h3>



<p><em>April 15, 2025</em>:  Now that this AI agent story has morphed into “agentic AI,” it seems to have taken on the same big-cloud-AI flavor that enteriprise already rejected. What do they want from AI agents, <a href="https://www.networkworld.com/article/3957285/ai-agents-vs-agentic-ai-what-do-enterprises-want.html">why is “agentic” thinking wrong</a>, and where is this all headed?</p>



<h3 class="wp-block-heading">A multicloud experiment in agentic AI: Lessons learned</h3>



<p><em>April 11, 2025</em>: Turns out you really can <a href="https://www.infoworld.com/article/3959533/i-built-an-agentic-ai-system-across-multiple-public-cloud-providers.html">build a decentralized AI system </a>that operates successfully across multiple public cloud providers. It’s both challenging and costly.</p>



<h3 class="wp-block-heading">Google adds open source framework for building agents to Vertex AI</h3>



<p>April 9, 2025: Google is adding a new open source framework for <a href="https://www.infoworld.com/article/3957875/google-adds-open-source-framework-for-building-agents-to-vertex-ai.html">building agents</a> to its AI and machine learning platform Vertex AI, along with other updates to help deploy and maintain these agents. The open source Agent Development Kit (ADK) will make it possible to build an AI agent in under 100 lines of Python code. It expects to add support for more languages later this year.</p>



<h3 class="wp-block-heading">Google’s Agent2Agent open protocol aims to connect disparate agents</h3>



<p><em>April 9, 2025</em>: Google has taken the covers off a new open protocol — Agent2Agent (A2A) — that aims to <a href="https://www.infoworld.com/article/3958032/googles-agent2agent-open-protocol-aims-to-connect-disparate-agents.html">connect agents across disparate ecosystems</a>.. At its annual Cloud Next conference, Google said that the A2A protocol will enable enterprises to adopt agents more readily as it bypasses the challenge of agents that are built on different vendor ecosystems not being able to communicate with each other.</p>



<h3 class="wp-block-heading">Riverbed bolsters AIOps platform with predictive and agentic AI</h3>



<p>April 8, 2025: Riverbed  unveiled updates to its <a href="https://www.networkworld.com/article/3957181/riverbed-bolsters-aiops-platform-with-predictive-and-agentic-ai.html">AIOps and observability platform</a> that the company says will transform how IT organizations manage complex distributed infrastructure and data more efficiently.  Expanded AI capabilities are aimed at making it easier to manage AIOps and enabling IT organizations to transition from reactive to predictive IT operations. </p>



<h3 class="wp-block-heading">Microsoft’s newest AI agents can detail how they reason</h3>



<p><em>March 26, 2025</em>: If you’re wondering <a href="https://www.computerworld.com/article/3854386/microsofts-newest-ai-agents-can-detail-how-they-reason.html">how AI agents work</a>, Microsoft’s new Copilot AI agents provide real-time answers on how data is being analyzed and sourced to reach results. The Researcher and Analyst agents take a deeper look at data sources such as email, chat or databases within an organization to produce research reports, analyze strategies, or convert raw information into meaningful data.</p>



<h3 class="wp-block-heading">Microsoft launches AI agents to automate cybersecurity amid rising threats</h3>



<p><em>March 26, 2025</em>: Microsoft has introduced a new set of <a href="https://www.csoonline.com/article/3853599/microsoft-launches-ai-agents-to-automate-cybersecurity-amid-rising-threats.html">AI agents for its Security Copilot</a> platform, designed to automate key cybersecurity functions as organizations face increasingly complex and fast-moving digital threats. The new tools focus on tasks such as phishing detection, data protection, and identity management.</p>



<h3 class="wp-block-heading">How AI agents work</h3>



<p><em>March 24, 2025</em>: By leveraging technologies such as machine learning, natural language processing (NLP), and contextual understanding, <a href="https://www.computerworld.com/article/3846150/how-ai-agents-work.html">AI agents can operate independently</a>, even partnering with other agents to perform complex tasks.</p>



<h3 class="wp-block-heading">5 top business use cases for AI agents</h3>



<p><em>March 19, 2025</em>: <a href="https://www.cio.com/article/3843379/5-top-business-use-cases-for-ai-agents.html">AI agents are poised to transform the enterprise</a>, from automating mundane tasks to driving customer service and innovation. But having strong guardrails in place will be key to success.<br></p>



<h3 class="wp-block-heading">Nvidia launches AgentIQ toolkit to connect disparate AI agents</h3>



<p><em>March 21, 2025</em>: As enterprises look to <a href="https://www.infoworld.com/article/3851326/nvidia-launches-agentiq-toolkit-to-connect-disparate-ai-agents.html">adopt agents and agentic AI </a>to boost the efficiency of their applications, Nvidia this week introduced a new open-source software library — AgentIQ toolkit — to help developers connect disparate agents and agent frameworks..</p>



<h3 class="wp-block-heading">Deloitte unveils agentic AI platform</h3>



<p><em>March 18, 2025</em>: At Nvidia GTC 2025 in San Jose, <a href="https://www.cio.com/article/3848252/deloitte-unveils-agentic-ai-platform.html">Deloitte announced Zora AI</a>, a new agentic AI platform that offers a portfolio of AI agents for finance, human capital, supply chain, procurement, sales and marketing, and customer service.The platform draws on Deloitte’s experience from its technology, risk, tax, and audit businesses, and is integrated with all major enterprise software platforms. </p>



<h3 class="wp-block-heading">The dawn of agentic AI: Are we ready for autonomous technology?</h3>



<p><em>March 15, 202</em>5: Much of the AI work prior has focused on large language models (LLMs) with a goal to give prompts to get knowledge out of the unstructured data. So it’s a question-and-answer process. Agentic AI goes beyond that. You can give it a task that might involve a complex set of steps that can change each time.</p>



<h3 class="wp-block-heading">How to know a business process is ripe for agentic AI</h3>



<p><em>March 11, 2025</em>: Deloitte predicts that in 2025, 25% of companies that use generative AI will launch <a href="https://www.cio.com/article/3829620/how-to-know-a-business-process-is-ripe-for-agentic-ai.html" target="_blank">agentic AI pilots or proofs of concept</a>, growing to 50% in 2027. The firm says some agentic AI applications, in some industries and for some use cases, could see actual adoption into existing workflows this year.</p>



<h3 class="wp-block-heading">With new division, AWS bets big on agentic AI automation</h3>



<p><em>March 6, 2025</em>: Amazon Web Services customers can expect to hear a lot more about <a href="https://www.computerworld.com/article/3840429/with-new-division-aws-bets-big-on-agentic-ai-automation.html">agentic AI from AWS</a> in future with the news that the company is setting up a dedicated unit to promote the technology on its platform.</p>



<h3 class="wp-block-heading">How agentic AI makes decisions and solves problems</h3>



<p><em>March 6, 2025</em>: GenAI’s latest big step forward has been the arrival of <a href="https://www.computerworld.com/article/3617392/what-are-ai-agents-and-why-are-they-now-so-pervasive.html">autonomous AI agents</a>. Agentic AI is based on AI-enabled applications capable of perceiving their environment, making decisions, and taking actions to achieve specific goals. </p>



<h3 class="wp-block-heading">CIOs are bullish on AI agents. IT employees? Not so much</h3>



<p><em>Feb. 4, 2025</em>: Most <a href="https://www.cio.com/article/3815935/cios-are-bullish-on-ai-agents-it-employees-not-so-much.html" target="_blank">CIOs and CTOs are bullish on agentic AI</a>, believing the emerging technology will soon become essential to their enterprises, but lower-level IT pros who will be tasked with implementing agents have serious doubts.</p>



<h3 class="wp-block-heading">The next AI wave — agents — should come with warning labels. Is now the right time to invest in them?</h3>



<p><em>Jan.13, 2025</em>: The <a href="https://www.computerworld.com/article/3727412/the-next-ai-wave-agents-should-come-with-warning-labels.html">next wave of artificial intelligence</a> (AI) adoption is already under way, as AI agents — AI applications that can function independently and execute complex workflows with minimal or limited direct human oversight — are being rolled out across the tech industry.</p>



<h3 class="wp-block-heading">AI agents are unlike any technology ever</h3>



<p><em>Dec. 1, 2024</em>: The agents are coming, and they represent a <a href="https://www.computerworld.com/article/3608973/ai-agents-are-unlike-any-technology-ever.html">fundamental shift in the role artificial intelligence</a> plays in businesses, governments, and our lives.</p>



<h3 class="wp-block-heading">AI agents are coming to work — here’s what businesses need to know</h3>



<p><em>Nov. 21, 2024</em>: <a href="https://www.computerworld.com/article/3609764/ai-agents-are-coming-to-work-heres-what-businesses-need-to-know.html">AI agents will soon be everywhere</a>, automating complex business processes and taking care of mundane tasks for workers — at least that’s the claim of various software vendors that are quickly adding intelligent bots to a wide range of work apps.</p>



<h3 class="wp-block-heading">Agentic AI swarms are headed your way</h3>



<p><em>November 1, 2024</em>: OpenAI launched an experimental framework called Swarm. It’s a “lightweight” system for the development of agentic AI swarms, which are <a href="https://www.computerworld.com/article/3594235/agentic-ai-swarms-are-headed-your-way.html">networks of autonomous AI agents</a> able to work together to handle complex tasks without human intervention, according to OpenAI. </p>



<h3 class="wp-block-heading">Is now the right time to invest in implementing agentic AI?</h3>



<p><em>October 31, 2024</em>: While software vendors say their current <a href="https://www.cio.com/article/3596212/is-now-the-right-time-to-invest-in-implementing-agentic-ai.html">agentic AI-based offerings</a> are easy to implement, analysts say that’s far from the truth.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.8.0 Preview brings initial Steam Machine support, and improvements for many handhelds]]></title>
<description><![CDATA[SteamOS 3.8.0 Preview is another big upgrade for Valve's Linux distribution, with lots of enhancements to hardware support across the board for handhelds.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3366303/linux-tipps/steamos-380-preview-brings-initial-steam-machine-support-and-improvements-for-many-handhelds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3366303/linux-tipps/steamos-380-preview-brings-initial-steam-machine-support-and-improvements-for-many-handhelds/</guid>
<pubDate>Fri, 20 Mar 2026 10:53:40 +0100</pubDate>
<content:encoded><![CDATA[SteamOS 3.8.0 Preview is another big upgrade for Valve's Linux distribution, with lots of enhancements to hardware support across the board for handhelds.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/03/steamos-3-8-0-preview-brings-initial-steam-machine-support-and-improvements-for-many-handhelds/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The WhatsApp takeover scam that doesn’t need your password]]></title>
<description><![CDATA[How a simple “I found your photo” message can quietly take over your account]]></description>
<link>https://tsecurity.de/de/3365422/it-security-nachrichten/the-whatsapp-takeover-scam-that-doesnt-need-your-password/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365422/it-security-nachrichten/the-whatsapp-takeover-scam-that-doesnt-need-your-password/</guid>
<pubDate>Fri, 20 Mar 2026 04:35:22 +0100</pubDate>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://blog.avast.com/blog/onlinescams/whatsapppairingscam" title="" class="hs-featured-image-link"> <img src="https://blog.avast.com/hubfs/Screenshot%202025-12-15%20at%2012.13.04%20PM.png" alt="The WhatsApp takeover scam that doesn’t need your password" class="hs-featured-image"> </a> 
</div> 
<p><strong>How a simple “I found your photo” message can quietly take over your account</strong></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud at 20: Cost, complexity, and control]]></title>
<description><![CDATA[When Amazon Web Services launched its Simple Storage Service (S3) in March 2006, it sparked the imagination of IT leaders worldwide. I remember that era well. It was a time when the enterprise was feverishly searching for a way out of restrictive, on-premises silos. S3 and the emerging concept of...]]></description>
<link>https://tsecurity.de/de/3365011/ai-nachrichten/cloud-at-20-cost-complexity-and-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365011/ai-nachrichten/cloud-at-20-cost-complexity-and-control/</guid>
<pubDate>Fri, 20 Mar 2026 04:27:02 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When Amazon Web Services launched its Simple Storage Service (S3) in March 2006, it sparked the imagination of IT leaders worldwide. I remember that era well. It was a time when the enterprise was feverishly searching for a way out of restrictive, on-premises silos. S3 and the emerging concept of public cloud promised almost unlimited scalability, pay-as-you-go economics, and the freeing of IT departments from the shackles of hardware, data centers, and routine maintenance. The vision was that enterprises could offload their IT headaches and focus on business outcomes, letting cloud providers do the heavy lifting.</p>



<p>Twenty years later, S3 has ballooned into a monster-scale system of more than 500 trillion objects stored, hundreds of exabytes under management, and operations spanning every corner of the planet. Netflix, Spotify, and other companies have used S3 and the wider AWS ecosystem to reinvent whole industries, scaling to dimensions that would have seemed impossible in the pre-cloud era.</p>



<p>But as we light the candles on S3’s birthday cake, the reality for most enterprises does not match the sleek simplicity once promised. Far from outsourcing all their IT to the cloud, most organizations today find themselves facing greater complexity, reduced transparency, and spiraling costs. Cloud hasn’t eliminated traditional IT problems; it has merely shifted and, in many cases, compounded them.</p>



<h2 class="wp-block-heading">The failed promise of savings</h2>



<p>It turns out, in the vast majority of cases, that moving workloads to the cloud does not inherently reduce costs or complexity. Many enterprises naively expected a simple equation: Moving infrastructure to the cloud equals lower costs plus greater agility. Instead, organizations gradually discovered that the pay-as-you-go model could quickly balloon budgets when left unchecked.</p>



<p><a href="https://www.infoworld.com/article/3486837/how-to-bring-runaway-cloud-costs-under-control.html">Cloud spending</a> often began as a tiny line item within IT budgets, but two decades on, it’s frequently one of the highest and fastest-growing costs, sometimes eclipsing the very expenses it was meant to replace. Enterprises face a jungle of service tiers, intricate pricing metrics, unexpected data egress fees, licensing quirks, and rapid consumption of compute and storage. The quest for scale and innovation, fueled by cloud computing, often leads to sprawl: hundreds or thousands of workloads distributed across multiple cloud accounts and regions, each adding yet another layer of expense.</p>



<p>The real concern for CIOs isn’t just surprise costs but the struggle to implement cloud discipline. Even for organizations that embrace <a href="https://www.infoworld.com/article/2338592/6-finops-best-practices-to-reduce-cloud-costs.html">finops </a>(the emerging practice of cloud financial operations), the speed of innovation outpaces their ability to govern usage. Business units spin up workloads on a whim only to forget or abandon them. Cloud cost visibility is confounded by opaque billing dashboards, and the containerization trend has made it even harder to pin down exactly where money is going.</p>



<p>This runaway spending is not the result of malfeasance, but rather the product of the cloud’s core attribute: enabling rapid, frictionless innovation in exchange for complex, often unpredictable billing. In recent years, the pendulum has begun to swing back, with many organizations <a href="https://www.infoworld.com/article/3628746/cost-conscious-cloud-repatriation-strategies.html">repatriating some workloads</a> to on-premises infrastructure just to regain cost control and predictability.</p>



<h2 class="wp-block-heading">The cloud giveth and taketh away</h2>



<p>Early cloud pioneers believed that entrusting security to hyperscale providers would mean fewer headaches. After all, who better to patch, monitor, and defend IT infrastructure than the companies running the largest, most sophisticated data centers on earth? To an extent, this is true. Cloud providers have invested untold billions in every flavor of physical and software security.</p>



<p>But the paradox is that by its very flexibility and openness, cloud introduces enormous security and operational complexity. The infamous rash of open S3 buckets left exposed to the world due to default configurations or simple oversight testified to the challenges of managing distributed, cloud-native architectures. Enterprises must now invest in new skills, new tools, and new processes just to manage the endless stream of updates, permissions, encryption keys, and <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">access policies</a>. Instead of outsourcing pain points, many organizations just replaced one set of hassles with another.</p>



<p>Moreover, the notion of “set it and forget it” in the cloud has proven dangerously outdated. The constant drumbeat of threats, from ransomware to nation-state actors, combined with the proliferation of APIs and services, makes the cloud a shifting, ever-expanding attack surface. Enterprises are forced not only to upskill but also to adopt whole new mindsets around zero trust, observability, and resilience engineering.</p>



<h2 class="wp-block-heading">The future: more of the same</h2>



<p>The original fantasy of cloud was that it would be a single pane of glass: one provider (often AWS), powering an enterprise’s every workload, integrated from edge to core to SaaS. In reality, as we reach this 20-year milestone, we’re in a multicloud reality whether by design, accident, or necessity. Enterprises are now managing portfolios that span AWS, Microsoft Azure, Google Cloud, and sometimes dozens of SaaS or niche providers and their own private clouds.</p>



<p>This shift actually magnifies all previous challenges. Not only do organizations have to master the idiosyncrasies of each provider’s architectures, costs, and security models, but they must also contend with interoperability, data movement, compliance, and the talent gap across every platform in use. The modern IT estate is a patchwork, not a seamless fabric.</p>



<p>As the next chapter of the cloud era unfolds, three trends are set to dominate. First, finops will become inseparable from devops and IT operations as enterprises seek to assert financial discipline over their cloud estates. Second, continuous investment in security will be essential: not just tools, but human capital and process change, with automation serving as a key enabler. Third, complexity won’t disappear; the goal will be to manage and mitigate it, not magically eliminate it.</p>



<p>The 20th anniversary of S3 isn’t just a celebration of a technological achievement; it’s a sobering reminder that the journey to the cloud, for most enterprises, is more marathon than sprint. The dream of outsourced, seamless IT has, for most, become managed, governed, orchestrated complexity. The next 20 years will see continued investments in cost control, security, and managing the multicloud labyrinth. Cloud may have transformed technology forever, but for the enterprise, the work—and the surprises—is just beginning.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Appsec News & Interviews from RSAC on Identity and AI - Rami Saas, Charlotte Wylie - ASW #331]]></title>
<description><![CDATA[In the news, Coinbase deals with bribes and insider threat, the NCSC notes the cross-cutting problem of incentivizing secure design, we cover some research that notes the multitude of definitions for secure design, and discuss the new Cybersecurity Skills Framework from the OpenSSF and Linux Foun...]]></description>
<link>https://tsecurity.de/de/3356268/it-security-nachrichten/appsec-news-interviews-from-rsac-on-identity-and-ai-rami-saas-charlotte-wylie-asw-331/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356268/it-security-nachrichten/appsec-news-interviews-from-rsac-on-identity-and-ai-rami-saas-charlotte-wylie-asw-331/</guid>
<pubDate>Tue, 17 Mar 2026 17:57:49 +0100</pubDate>
<content:encoded><![CDATA[<p>In the news, Coinbase deals with bribes and insider threat, the NCSC notes the cross-cutting problem of incentivizing secure design, we cover some research that notes the multitude of definitions for secure design, and discuss the new Cybersecurity Skills Framework from the OpenSSF and Linux Foundation. Then we share two more sponsored interviews from this year's RSAC Conference.</p> <p>With more types of identities, machines, and agents trying to access increasingly critical data and resources, across larger numbers of devices, organizations will be faced with managing this added complexity and identity sprawl. Now more than ever, organizations need to make sure security is not an afterthought, implementing comprehensive solutions for securing, managing, and governing both non-human and human identities across ecosystems at scale.</p> <p>This segment is sponsored by Okta. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/oktarsac">https://securityweekly.com/oktarsac</a> to learn more about them!</p> <p>At Mend.io, we believe that securing AI-powered applications requires more than just scanning for vulnerabilities in AI-generated code—it demands a comprehensive, enterprise-level strategy. While many AppSec vendors offer limited, point-in-time solutions focused solely on AI code, Mend.io takes a broader and more integrated approach.</p> <p>Our platform is designed to secure not just the code, but the full spectrum of AI components embedded within modern applications. By leveraging existing risk management strategies, processes, and tools, we uncover the unique risks that AI introduces—without forcing organizations to reinvent their workflows. Mend.io's solution ensures that AI security is embedded into the software development lifecycle, enabling teams to assess and mitigate risks proactively and at scale.</p> <p>Unlike isolated AI security startups, Mend.io delivers a single, unified platform that secures an organization's entire codebase—including its AI-driven elements. This approach maximizes efficiency, minimizes disruption, and empowers enterprises to embrace AI innovation with confidence and control.</p> <p>This segment is sponsored by Mend.io. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/mendrsac">https://securityweekly.com/mendrsac</a> to book a live demo!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/asw">https://www.securityweekly.com/asw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/asw-331">https://securityweekly.com/asw-331</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digital twin: A crystal ball from ‘what happened’ to ‘what next’]]></title>
<description><![CDATA[The newspaper of tomorrow costs a million dollars, but yesterday’s newspaper cost less than a dollar. It is always a human endeavor to know or predict the future as accurately as possible, but it remains elusive due to technological limitations, static models, outdated data or gut feeling. In the...]]></description>
<link>https://tsecurity.de/de/3338044/it-security-nachrichten/digital-twin-a-crystal-ball-from-what-happened-to-what-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3338044/it-security-nachrichten/digital-twin-a-crystal-ball-from-what-happened-to-what-next/</guid>
<pubDate>Tue, 10 Mar 2026 12:07:21 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The newspaper of tomorrow costs a million dollars, but yesterday’s newspaper cost less than a dollar. It is always a human endeavor to know or predict the future as accurately as possible, but it remains elusive due to technological limitations, static models, outdated data or gut feeling. In the world, torn by wars, tariffs, political fragmentation, geopolitical risk, rapid AI adaptation and weather catastrophes, uncertainty is just the norm rather than an exception.</p>



<p>During COVID-19, the world was exposed to huge supply chain disruption, essential commodities became scarce, and the world started understanding the challenge of the long supply chain. You will be surprised to know the iPhone travels 240k miles, the distance between Earth and the Moon, before you turn it on. Apple depends on suppliers from 50 countries to manufacture the iPhone; any small disruption has huge implications for the iPhone supply chain.</p>



<p>As a supply chain expert, I have seen how C-suite executives of every company struggled during the tariff war introduced last year by the US. Today, most supply chains are global, meaning raw materials are produced in one country, manufacturing in another and products are used in another. To increase efficiency and cost reduction, the chain of the supply chain has only been elongated. With technological advancement and communication improvement in land, sea and water, dependencies of one country on another have only increased. It is non-negotiable that the critical supply chain must continue in the face of any uncertainty. No company ever considered the tariff in the landed cost (total cost to bring in an item from outside), which increased the price of the final product that consumers pay. Companies are planning to move their manufacturing to the Friend Shore rather than onshore or offshore.</p>



<p>Launching a first-of-its-kind product is a forecasting nightmare. Without a historical roadmap, executives often fly blind, making it nearly impossible to scale production or manage suppliers accurately. The stakes are high: One wrong guess can lead to a mountain of unsold stock or — just as bad — turning away eager customers.   </p>



<p>In manufacturing, the failure of a single critical machine can stall operations for weeks. When repairs are delayed by long lead times for parts or specialized expertise, the resulting production bottlenecks lead to significant revenue loss and damaged customer relationships.</p>



<p>In a traditional product design approach, designers and engineers wait for customer feedback to be incorporated in the next iteration. Frequent changes in product safety regulations could derail the entire design.   </p>



<p>In an era where decision speed is the ultimate currency, volatility has become the new norm. Moving from annual to monthly product development cycles provides a vital competitive edge. By shifting from reactive to proactive strategies, AI-powered digital twins act as a “crystal ball,” providing the accurate forecasts needed to unlock new operational possibilities.</p>



<h2 class="wp-block-heading">Digital twins in the supply chain</h2>



<p>What is a digital twin in the context of the supply chain? Generally speaking, a digital twin is a digital replica of a physical object. It could be anything from an electric iron to a multistory building. Having a digital twin helps organizations simulate real-life applications and user-friendliness. Similarly, organizations using digital twins in their supply chain are better suited to deploy AI technology to drive and extract the best possible operational outcomes.</p>



<p>Digital twins in the supply chain allow an organization to extract its own captive data from manufacturing, inventory, suppliers, ESG, compliance and more into a single point of truth so proactive decisions can be made from real-time visibility. In this way, digital twins can speed <a href="https://www.mckinsey.com/featured-insights/mckinsey-explainers/what-is-digital-twin-technology" rel="nofollow">decision-making by up to 90%</a>, according to a McKinsey study.</p>



<h3 class="wp-block-heading">Real-life use cases</h3>



<p>According to a <a href="https://sparq360.com/digital-twin-usage-in-supply-chains-the-war-games-of-modern-logistics/#realworld-applications-whos-using-digital-twins" rel="nofollow">study </a>by SPARQ360, a supply chain optimization, sustainability and compliance firm, some of the most effective digital twins in supply chain are:</p>



<ul class="wp-block-list">
<li><strong>Unilever:</strong> Uses digital twin technology to <a href="https://www.unilever.com/news/news-search/2025/how-were-building-a-leaner-more-agile-supply-chain/" rel="nofollow">model factory operations, optimize production schedules and enhance sustainability initiatives</a>, leading to greater efficiency and cost savings.</li>



<li><strong>Boeing:</strong> Employs digital twins to improve supply chain transparency, reducing delays in aircraft production by modeling real-time supply constraints.</li>



<li><strong>DHL:</strong> Leverages digital twins in logistics operations to simulate and optimize warehouse efficiency, improving order fulfillment speed and reducing downtime. (</li>



<li><strong>Siemens:</strong> Uses digital twin simulations to design and manage supply chains for its industrial manufacturing clients, ensuring optimized production and distribution. (https://www.siemens.com/global/en/company/stories/industry/2025/digital-twin-for-industry.html)</li>
</ul>



<p>From personal experience, the Kion Group partnered with Accenture and NVIDIA to leverage this innovation to address inefficiencies in warehouse operations. We enhanced supply chain efficiency through AI-driven solutions and digital twins, which were created to simulate warehouse dynamics. The digital twins facilitated real-time testing and optimization of layouts, robotic fleet management and operational processes.</p>



<p>This collaboration led to more autonomous and efficient warehouse operations, reducing manual interventions and allowing quicker adaptations to operational changes, thereby streamlining warehouse management and increasing overall efficiency.</p>



<h2 class="wp-block-heading">Overcoming implementation challenges</h2>



<p>Digital twins can be a part of the overall digital transformation strategies of an organization’s supply chain. However, as in all digital transformations, the following challenges will need to be considered:</p>



<h3 class="wp-block-heading">Data integration and accuracy issues</h3>



<p>One of the biggest challenges of digital supply chain twins is the mismatch of data. Often, inaccurate or conflicting data is sourced from logistics management software, ERP systems, inventory management systems and IoT sensors. This makes coordination with multiple stakeholders extremely difficult.</p>



<p>One approach we’ve often implemented to fix this issue is to first understand the data maturity model of the architecture you’re implementing the digital twin in, which includes mapping all the data sources and calling out the potential data silos. Secondly, we look at employing a myriad of different additional data strategies, like a data mesh or data fabric, to essentially call some of the data, as opposed to simply leveraging data lakes and data warehouses. </p>



<p>When building a data lake or migrating data to a centralized source, leveraging a solution like <a href="https://www.snowflake.com/en/" rel="nofollow">Snowflake </a>or <a href="https://aws.amazon.com/" rel="nofollow">AWS </a>can be effective. With regards to data mesh and data fabrics, there are some commercial off-the-shelf (COTS) software solutions that install within existing topologies to map all data points into a meshed architecture. Conversely, we have also developed custom mesh solutions for digital twins in the supply chain by partnering with firms like Palantir or Amazon to achieve similar results.  </p>



<h3 class="wp-block-heading">High upfront and maintenance costs</h3>



<p>Digital Transformation initiatives are seldom easy or without high costs. Integrating supply chain digital twins requires investing in hardware, software, AI-driven analytics tools and cloud infrastructures, along with ongoing maintenance costs. Here are some tips as platitudes we have tried in the past that seem to help: </p>



<ul class="wp-block-list">
<li><strong>Don’t boil the ocean.</strong> Digital transformation in the supply chain is about showing value as quickly as possible. Nothing gets to value quicker than starting with a small pilot project the scale up. The team needs to focus on the most critical constraint, deliver value quickly and build momentum.</li>



<li><strong>Don’t reinvent the wheel.</strong> Utilize existing data sources and integrate with current infrastructure to reduce the need for new data collection and technology and collaborate with industry partners. Collaborative models can spread financial risk and leverage shared expertise, leading to cost savings and enhanced capabilities.</li>
</ul>



<p>By employing these strategies, organizations can effectively manage the financial burdens associated with building and maintaining Digital Twins by minimizing upfront investment while continuously improving the system’s value, allowing organizations to allocate resources based on proven benefits.</p>



<p>These steps also allow organizations to test the Digital Twin concept, refine strategies and demonstrate value without significant investment.</p>



<h3 class="wp-block-heading">Resistance to change</h3>



<p>In many ways, we have noticed that the best approach towards removing resistance to change starts by implementing a culture of change. Employee resistance is very common when it comes to the implementation of digital twins, especially in supply chain management. This often stems from inadequate training in the Internet of Things (IoT), data analytics, artificial intelligence (AI) and working with the digital twins themselves.</p>



<p>From our own experiences, the best approach is to implement such changes in a phased manner and then scale up. This includes the following steps:</p>



<ul class="wp-block-list">
<li><strong>Ensuring leadership buy-in.</strong> It starts at the top with strategies where leadership champions experimentation, setting the tone and providing necessary resources.</li>



<li><strong>Creating a safe space for failure.</strong> Communicate and champion a message that resonates with how users are in a safe environment where failures are seen as learning opportunities.</li>



<li><strong>Measuring success beyond traditional metrics.</strong> Leverage alternative metrics to promote experimentation and innovation.</li>
</ul>



<p>By taking these steps, integration and adoption of digital twins become seamless and focused on value, not mandates.  </p>



<h2 class="wp-block-heading">The future of digital twins in the supply chain</h2>



<p>Once you’ve implemented digital twins in your supply chain and successfully garnered employee confidence, the story doesn’t just end there. Scaling up your supply chain digital twins is the next logical step forward. And this is where AI integration with digital twin applications comes into the picture.</p>



<p>Imagine the possibilities a well-integrated supply chain digital twin system with AI can bring to the table. With AI enabling the processing, analyzing and interpreting of massive multidimensional datasets, your supply chain can remain agile and resilient while navigating the turbulence of geopolitical or macroeconomic disruptions.</p>



<p><strong><u>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></u></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From OpEx to CapEx: The case for modular AI pods]]></title>
<description><![CDATA[If you want to see the immediate future of enterprise org planning, don’t look at NVIDIA’s stock price. Look at the severance packages at Chegg.



In late 2025, the education giant cut 45% of its workforce, leaving it with fewer than 500 employees, down from nearly 2,000 just two years prior. Th...]]></description>
<link>https://tsecurity.de/de/3325266/it-security-nachrichten/from-opex-to-capex-the-case-for-modular-ai-pods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325266/it-security-nachrichten/from-opex-to-capex-the-case-for-modular-ai-pods/</guid>
<pubDate>Wed, 04 Mar 2026 14:05:29 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>If you want to see the immediate future of enterprise org planning, don’t look at NVIDIA’s stock price. Look at the <a href="https://www.cnbc.com/2025/10/27/chegg-slashes-45percent-of-workforce-blames-new-realities-of-ai.html" rel="nofollow">severance packages at Chegg</a>.</p>



<p>In late 2025, the education giant cut 45% of its workforce, leaving it with fewer than 500 employees, down from nearly 2,000 just two years prior. The reason? They were selling “rented intelligence” for homework answers. When AI made that intelligence free, their fixed-cost business model collapsed. They had built a massive permanent workforce to deliver a commodity that suddenly cost zero.</p>



<p>Chegg is the extreme case, but it’s a canary in the coal mine for every CIO.</p>



<p>Walk into most Fortune 500 boardrooms today, and you’ll see executives misreading the landscape. They’re obsessed with the idea of the “hardware hangover”. This is the staggering <a href="https://www.cnn.com/2025/12/19/tech/ai-chips-lifecycle-questions" rel="nofollow">$400 billion spent in 2025 alone</a> on GPUs and data centers. They think “CapEx” (capital expenditure) means buying servers, but the real war isn’t over silicon; it’s over <a href="https://www.bodhiai.io/post/sovereign-ai-explained-a-strategic-roadmap-for-forward-thinking-leaders" rel="nofollow">software sovereignty</a>.</p>



<p>Most companies are currently drowning in a rental trap. You pay monthly subscriptions for SaaS tools, you pay per-token for API calls and you hire full-time employees to stitch them together. If you stop paying the bills, the intelligence turns off. You own nothing.</p>



<p>In 2026, the smart CIOs are flipping this model, moving from renting capability (OpEx) to owning IP (CapEx). They aren’t doing this by hiring 500 new data scientists, they’re doing it with a modular, elastic workforce that builds the asset and then leaves.</p>



<h2 class="wp-block-heading">What can we learn from Intuit about the trauma of skill swapping?</h2>



<p>The fundamental problem with the 2023-2024 AI hiring boom was that it treated AI skills as static. In the AI-era, skills depreciate faster than hardware.</p>



<p>We saw this play out at Intuit. <a href="https://fortune.com/2024/07/10/intuit-layoffs-email-hiring-ai-transformation/" rel="nofollow">In mid-2024, they laid off 1,800 people</a> (roughly 10% of their workforce) while simultaneously announcing plans to hire 1,800 new roles to support their AI transformation. Despite the symmetry, this wasn’t a swap; it was a painful structural reset. They had to shed legacy roles to make room for “customer-facing” and product roles that could leverage AI. To add insult to injury, now <a href="https://www.businessinsider.com/anthropics-new-ai-announcements-spark-concerns-across-software-sector-2026-1" rel="nofollow">Intuit’s stock is in freefall</a> because AI is “eating” their software.</p>



<p>So what’s the main takeaway? If you lock your strategy into full-time headcount, the only way to pivot is through trauma: layoffs, severance and cultural destruction.</p>



<h2 class="wp-block-heading">Why fire and rehire when you can just bolt on?</h2>



<p>I learned the hard way that adding headcount doesn’t solve all staffing issues during my time as a talent acquisition leader in the technology sector. Having a core team with augmented contract support for high-flux hiring always served our budgets better than a monolithic team of full-time staff. The same now rings true across all teams, but most acutely for software engineering and AI/ML departments.</p>



<p>Think of it as Gig 2.0 economics, where we define contractors as “capital expenditure catalysts” rather than temporary labor.</p>



<p>To explain it simply:</p>



<ul class="wp-block-list">
<li><strong>The old way:</strong> You pay a salary forever to maintain a system.</li>



<li><strong>The new way:</strong> You pay a specialized pod to <em>build</em> a proprietary system in 90 days. When they finish, the headcount cost goes to zero, but the asset stays on your balance sheet.</li>
</ul>



<h2 class="wp-block-heading">The accounting reality: Why uncertainty demands modularity</h2>



<p>For years, CIOs hoped accounting rules would make it easier to capitalize their AI experiments. The reality of 2026 is exactly the opposite and that makes the modular model even more critical.</p>



<p>In late 2025, <a href="https://www.fasb.org/Page/Document?pdf=ASU%202025-06.pdf&amp;title=Accounting%20Standards%20Update%202025-06%E2%80%94Intangibles%E2%80%94Goodwill%20and%20Other%E2%80%94Internal-Use%20Software%20(Subtopic%20350-40):%20Targeted%20Improvements%20to%20the%20Accounting%20for%20Internal-Use%20Software">the Financial Accounting Standards Board (FASB) issued </a><a href="https://www.fasb.org/Page/Document?pdf=ASU%202025-06.pdf&amp;title=Accounting%20Standards%20Update%202025-06%E2%80%94Intangibles%E2%80%94Goodwill%20and%20Other%E2%80%94Internal-Use%20Software%20(Subtopic%20350-40):%20Targeted%20Improvements%20to%20the%20Accounting%20for%20Internal-Use%20Software" rel="nofollow">ASU 2025-06</a><a href="https://www.fasb.org/Page/Document?pdf=ASU%202025-06.pdf&amp;title=Accounting%20Standards%20Update%202025-06%E2%80%94Intangibles%E2%80%94Goodwill%20and%20Other%E2%80%94Internal-Use%20Software%20(Subtopic%20350-40):%20Targeted%20Improvements%20to%20the%20Accounting%20for%20Internal-Use%20Software" rel="nofollow">.</a> While it simplified some aspects of software accounting, it introduced a “significant development uncertainty” hurdle. Put simply: If your project is “novel” or “unproven” (which almost all innovative AI is), you likely have to expense the costs until that uncertainty is resolved. You can’t capitalize it.</p>



<p>This is a dangerous trap for CIOs looking to hire.</p>



<p>If you hire 50 full-time engineers to build a novel AI agent, and FASB says the project is uncertain, you are forced to treat their entire payroll as an expense (OpEx). You are loading your P&amp;L with fixed costs for an experiment. If the project fails, you destroy your EBITDA <em>and</em> you’re stuck with the headcount. The board won’t like that.</p>



<p>The new way avoids this trap. By using contingent pods for the uncertainty phase, you treat the innovation phase as a sandbox:</p>



<ul class="wp-block-list">
<li><strong>Scenario A (failure):</strong> The novel AI doesn’t work. You disband the pod. The expense stops instantly. No layoffs.</li>



<li><strong>Scenario B (success):</strong> The pod proves the concept. The uncertainty is resolved. <em>Now</em> you can bring it in-house or capitalize the remaining build, knowing the asset is viable.</li>
</ul>



<h2 class="wp-block-heading">Understanding the elastic talent capacity ratio</h2>



<p>To execute this, you need a new headcount architecture. I call it the elastic talent capacity ratio, and it involves a 70/30 split:</p>



<ul class="wp-block-list">
<li><strong>70% the core team:</strong> These are your full-time employees. They are the product owners, the data governors, the strategists. They ensure the AI aligns with your company values. Their job is not to write every line of code; their job is to set the strategic direction and be stewards of existing infrastructure.</li>



<li><strong>30% the bolt-on team:</strong> These are high-performance pods who enter with a specific mission to build a specific asset.</li>
</ul>



<p>This structure protects you from the market. When the economy dips, you dial down the 30% without touching your core. When the economy booms (or a new model drops), you dial it up without waiting six months for HR to recruit.</p>



<p>Crucially, this also solves the “shelf-life” problem of AI talent. The innovation cycle in our industry <a href="https://www.bodhiai.io/post/agent-advantage-the-18-month-window-that-separates-leaders-from-followers" rel="nofollow">h</a><a href="https://www.bodhiai.io/post/agent-advantage-the-18-month-window-that-separates-leaders-from-followers" rel="nofollow">as compressed to roughly six months</a>. Today, you might need a pod specializing in ultra-low latency voice AI for a customer service overhaul. Next quarter, the priority might shift to predictive maintenance for your logistics fleet, or perhaps a completely new reasoning model that hasn’t even been released yet.</p>



<p>If you try to hire full-time employees for every new wave, you end up with a team built for the <em>last</em> war. A modular approach allows you to swap in experts who live on the bleeding edge of that specific niche. You don’t need to own the skill forever; you just need to rent the expertise long enough to build the capability, capitalize it and then pivot to the next breakthrough.</p>



<h2 class="wp-block-heading">Get ready to be nimble, things will only accelerate into 2027</h2>



<p>The companies that win in 2026 won’t be the ones with the largest payrolls OR the most layoffs. They will be the ones who can assemble the best talent for the specific problem, solve it and scale.</p>



<p>The accounting rules, the market volatility and the pace of technology all point to the same conclusion: agility is the only asset that will appreciate.</p>



<p>Stop renting your future from big tech. Stop loading your balance sheet with permanent risk for temporary problems. Start using the Gig 2.0 approach to build an asset economy.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From digital transformation to intelligent transformation]]></title>
<description><![CDATA[Over the past decade, digital transformation has focused on converting manual processes to digital ones, migrating infrastructure to the cloud, updating applications and creating new channels for customer and employee engagement. These efforts have resulted in tangible benefits such as accelerate...]]></description>
<link>https://tsecurity.de/de/3309597/it-security-nachrichten/from-digital-transformation-to-intelligent-transformation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3309597/it-security-nachrichten/from-digital-transformation-to-intelligent-transformation/</guid>
<pubDate>Wed, 25 Feb 2026 13:05:01 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Over the past decade, digital transformation has focused on converting manual processes to digital ones, migrating infrastructure to the cloud, updating applications and creating new channels for customer and employee engagement. These efforts have resulted in tangible benefits such as accelerated cycle times, increased transparency and reduced costs. However, these initiatives have also revealed limitations: Simply digitizing a flawed process does not resolve its underlying issues; it only makes the inefficiencies operate at a faster pace.</p>



<h2 class="wp-block-heading">The shift to intelligent transformation</h2>



<p>A new shift is underway. The next phase moves beyond digital — it is intelligent. Intelligent transformation is about evolving enterprises into systems that can sense, reason, make decisions and take action with minimal friction. This evolution is driven by the emergence of AI agents: Autonomous software systems capable of achieving goals by orchestrating workflows and leveraging tools such as APIs, applications, databases and automation technologies.</p>



<h2 class="wp-block-heading">From apps and dashboards to agents and actions</h2>



<p>In the digital era, organizational value was derived from systems of record like ERP and CRM, as well as systems of insight such as business intelligence and analytics. In the intelligent era, a new dimension is added: Systems of action, defined by agentic capabilities that execute tasks across diverse functions.</p>



<p>AI agents don’t merely answer questions; they are capable of planning steps, invoking tools, retrieving relevant information and completing end-to-end workflows. Modern agent architectures employ tool calling or function calling, where a model determines the next action, the application executes it and the model continues based on the outcome. This approach effectively bridges language models and enterprise systems, transforming agents into practical operational levers rather than mere demonstrations.</p>



<h2 class="wp-block-heading">Cross-industry value: Where agents compound outcomes</h2>



<h3 class="wp-block-heading">Manufacturing: From connected factories to learning factories</h3>



<p>Industry 4.0 connected machines and visualised data through dashboards. Intelligent transformation advances this by converting signals into actions: Agents detect abnormal patterns, recommend parameter adjustments, initiate maintenance requests and coordinate the availability of parts. The cumulative benefits extend beyond uptime to faster root-cause analysis, reduced quality deviations and more predictable throughput. Even minor improvements in planning stability can lead to significant gains in service and inventory management across complex networks.</p>



<h3 class="wp-block-heading">Healthcare &amp; life sciences: From documentation burden to decision support</h3>



<p>Clinicians and scientists often navigate context overload due to guidelines, patient histories, research literature, protocols and regulatory requirements. Agents can collate relevant context, draft structured notes, suggest trial eligibility matches or summarise evidence, all while ensuring human oversight in decision-making. Responsible implementations integrate retrieval from trusted sources, audit trails and strict permissions, as accuracy, privacy and traceability remain essential.</p>



<h3 class="wp-block-heading">Retail &amp; consumer: From personaliziation to orchestration</h3>



<p>Personalised recommendations marked the initial stage. Now, agents can orchestrate the entire customer journey — resolving issues, amending orders, offering suitable alternatives and updating inventory systems. Internally, agents produce assortment insights, conduct promotion analyses and automate supplier communication, reducing turnaround times from weeks to hours.</p>



<h2 class="wp-block-heading">The new enterprise stack: Agentic workflows built on trust</h2>



<p>As agents advance in capability, the critical question will shift from “Can the model write?” to “Can the enterprise operate safely with agentic systems?”</p>



<p>A pragmatic stack is emerging:</p>



<ul class="wp-block-list">
<li><strong>Experience layer:</strong> Copilots within work tools (email, CRM, service desk) and role-based agent interfaces.</li>



<li><strong>Reasoning &amp; orchestration:</strong> Policies, routing, human-in-the-loop approvals and monitoring.</li>



<li><strong>Knowledge layer:</strong> Retrieval from curated internal content with permissions and provenance.</li>



<li><strong>Tool layer:</strong> APIs, RPA, workflow engines and systems of record enabling agent actions.</li>



<li><strong>Governance &amp; risk:</strong> Evaluation, security, compliance and auditability by design.</li>
</ul>



<p>Consequently, AI risk management has become a board-level concern. Frameworks such as NIST’s AI Risk Management Framework stress the importance of embedding trustworthiness across the AI lifecycle and managing risks to individuals, organizations and society.</p>



<h2 class="wp-block-heading">The uncomfortable truth: Agents amplify both productivity and risk</h2>



<p>Agents have the potential to deliver substantial productivity gains, but they also introduce new vulnerabilities: Prompt injection, data leakage, unsafe actions and excessive reliance on generated outputs. Leading platforms are continuously enhancing agent safety and implementing robust controls.</p>



<p>Enterprises that succeed will treat agents like other critical systems — establishing guardrails, enforcing least-privilege access, mandating approvals for sensitive actions, continually evaluating performance and maintaining traceability of data and actions.</p>



<h2 class="wp-block-heading">The operating model shift: Product thinking, not project thinking</h2>



<p>Intelligent transformation does not succeed as a one-time rollout. Agents are never static; they learn, adapt and evolve as business needs and risks change. This calls for a shift from project-based delivery to a product-oriented operating model:</p>



<ul class="wp-block-list">
<li><strong>Business-led outcomes:</strong> Each agent is linked to a measurable business KPI (cycle time, NPS, yield, cash conversion).</li>



<li><strong>Fusion teams:</strong> Domain experts, engineers, data specialists and risk/compliance professionals collaborate as a unified team.</li>



<li><strong>Evaluation as a discipline:</strong> Ongoing test suites for accuracy, safety, robustness and cost.</li>



<li><strong>Change management at the edge:</strong> Successful adoption is achieved through daily workflow integration, not just on launch day.</li>
</ul>



<h2 class="wp-block-heading">Measuring value: 3 horizons that executives can govern</h2>



<p>To effectively scale enterprise value, leaders should consider three horizons:</p>



<ol start="1" class="wp-block-list">
<li><strong>Horizon 1: Assist.</strong> Copilots that draft, summarise, search and explain, delivering rapid adoption and immediate time savings.</li>



<li><strong>Horizon 2: Augment.</strong> Agents that complete defined workflows with approvals, offering greater ROI and governance.</li>



<li><strong>Horizon 3: Automate.</strong> New operating models that reinvent customer and enterprise value chains, presenting the largest opportunities but requiring significant change.</li>
</ol>



<p>The common mistake is attempting to leap directly to Horizon 3. The most effective strategy is to build progressively: Use Horizon 1 to establish fluency and trust, Horizon 2 to standardise platforms and guardrails and Horizon 3 to transform the enterprise after developing confidence and capability.</p>



<h2 class="wp-block-heading">Conclusion: Intelligent transformation is a leadership agenda</h2>



<p>Digital transformation modernised technology, while intelligent transformation modernises the enterprise itself — how work is discovered, decided and delivered. AI agents serve as force multipliers, converting knowledge into action and action into learning.</p>



<p>Ultimately, success will not be determined by who can showcase the most impressive agent, but by who can develop the most trustworthy agentic ecosystem — one that is secure by design, outcome-oriented and embraced by employees who feel empowered rather than displaced.</p>



<p>In the age of AI agents, scaling enterprise value transcends traditional transformation. It requires building an organization capable of continuous self-transformation, with intelligence embedded in every decision and action.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The agentic enterprise: Why value streams and capability maps are your new governance control plane]]></title>
<description><![CDATA[The economic pivot: From creation to execution



The enterprise is currently undergoing a seismic pivot from generative AI, which focuses on content creation, to agentic AI, which focuses on goal execution. Unlike their predecessors, these agents possess “structured autonomy”: the ability to per...]]></description>
<link>https://tsecurity.de/de/3309440/it-security-nachrichten/the-agentic-enterprise-why-value-streams-and-capability-maps-are-your-new-governance-control-plane/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3309440/it-security-nachrichten/the-agentic-enterprise-why-value-streams-and-capability-maps-are-your-new-governance-control-plane/</guid>
<pubDate>Wed, 25 Feb 2026 12:07:02 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">The economic pivot: From creation to execution</h2>



<p>The enterprise is currently undergoing a seismic pivot from generative AI, which focuses on content creation, to agentic AI, which focuses on goal execution. Unlike their predecessors, these agents possess “structured autonomy”: the ability to perceive contexts, plan actions and execute across systems without constant human intervention.</p>



<p>For the CIO and the enterprise architect, this is not merely an upgrade in automation speed; it is a fundamental shift in the firm’s economic equation. We are moving from labor-centric workflows to digital labor capable of disassembling and reassembling entire value chains.</p>



<p>In my experience, this autonomy introduces non-deterministic behaviors that traditional IT governance cannot contain. According to an <a href="https://arxiv.org/abs/2501.01732#:~:text=3%20Jan%202025%5D-,Combined%20Hyper-Extensible%20Extremely-Secured%20Zero-Trust%20CIAM-,specifically%20for%20large-scale%20enterprises." rel="nofollow">article by Shivom Aggarwal, Shourya Mehra and Safeer Sathar,</a> the rise in persistent cyber threats and advancements in technology require organizations to move toward adaptive and zero-trust security frameworks, making it essential to rethink and repurpose core architectural models like value streams and business capability models, rather than relying solely on new tools.</p>



<h2 class="wp-block-heading">The governance gap: Why agents break traditional IT</h2>



<p>Agents operating without defined boundaries create significant operational capacity. Because they can make decisions dynamically, it becomes difficult to trace decision paths or audit outcomes. Furthermore, in multi-agent systems, a single error or hallucination can propagate downstream, creating “chained vulnerabilities” that compromise entire workflows — a risk distinct from the static failures of traditional software.</p>



<p>To govern this complexity, enterprise architecture must elevate its artifacts from static documentation to active governance instruments.</p>



<h2 class="wp-block-heading">Value stream engineering: The new control plane</h2>



<p>In an agentic enterprise, the value stream map is no longer just a diagram; it is the control plane. It must explicitly define the handoff protocols between human and digital agents.  In my opinion, Value stream maps must move from static documents stored in a repository to context documents used to drive agentic automation.</p>



<h2 class="wp-block-heading">Hardening the legacy estate</h2>



<p>Most existing value streams were designed for human judgment. To introduce agents, we must harden these streams to tolerate non-deterministic actors.</p>



<ul class="wp-block-list">
<li><strong>Define autonomy zones:</strong> Architects must audit streams to identify contiguous blocks of high-volume, low-ambiguity tasks. These become autonomy zones where agents cycle freely.</li>



<li><strong>Implement halt-on-exception: </strong>To prevent cascading errors, streams must include explicit logic that triggers an immediate routing change to a human actor when an agent’s confidence score drops (e.g., below 90%).</li>



<li><strong>The flight recorder:</strong> Agents are inherently opaque. Value streams must be augmented with mandatory logging steps — observability checkpoints — where an agent must cryptographically sign a log entry before proceeding to the next stage.</li>
</ul>



<h2 class="wp-block-heading">Case study: The over-the-air (OTA) software update stream<br><br></h2>



<p>Consider the value stream for vehicle software patch deployment. This process is high-risk; an error can incapacitate a fleet of vehicles.</p>



<ul class="wp-block-list">
<li><strong>Current state (fragile):</strong> Steps include code commit &gt; automated test &gt; regional deployment. The risk is that an agent tasked with optimizing deployment speed might bypass a slow testing gate to meet a goal, resulting in a flawed update.</li>



<li><strong>Architected state (governed):</strong>
<ul class="wp-block-list">
<li><strong>Step 1: Ingest (autonomy zone):</strong> An agent acts as the release coordinator, autonomously packaging the build and triggering 5,000 simulation tests.</li>



<li><strong>Step 2: The observability checkpoint:</strong> The value stream enforces a hard gate requiring the agent to sign a log entry detailing the simulation results cryptographically.</li>



<li><strong>Step 3: The halt-on-exception logic:</strong> If &gt;0.5% of simulations show latency spikes, the agent is technically blocked from accessing the deployment API. The stream automatically creates a Jira ticket for a human safety engineer.</li>



<li><strong>Step 4: Execution:</strong> Only if the threshold is met does the stream permit the agent to schedule the OTA rollout.</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading">The greenfield approach: Agent-first mapping</h2>



<p>If a value stream does not exist, you cannot automate it. For new agentic workflows, do not map the current human process. Instead, use an outcome-backwards approach. Work backward from the concrete deliverable (e.g., customer onboarded) to identify the minimum viable API calls required. Before granting write access, run the new agentic stream in shadow mode to validate agent decisions against human outcomes.</p>



<h2 class="wp-block-heading">Capability models: The readiness heatmap</h2>



<p>According to Enterprise Strategy Group (ESG) research, <a href="https://kpmg.com/kpmg-us/content/dam/kpmg/pdf/2025/esg-showcase-red-hat-kpmg-aug-2025.pdf" rel="nofollow">38% of organizations cite unclear business goals as the primary blocker to AI value realization</a>. In the era of agentic AI, this lack of clarity is dangerous and I see this leading to agentic AI sprawl.</p>



<p>As chief architect at Ford, I learned that the business capability model is the most effective tool for preventing the deployment of toy pilots that fail to scale. It serves as a readiness heatmap, identifying which business functions possess the structural maturity to host autonomous agents.</p>



<p><strong>Assessing agent readiness</strong></p>



<p>Do not deploy agents based on use case popularity. Deploy based on capability maturity.</p>



<ul class="wp-block-list">
<li><strong>Data integrity:</strong> Is the lineage within this capability clean enough for machine consumption?</li>



<li><strong>Boundary isolation:</strong> Are the APIs defined? If a capability relies on spaghetti code, an agent will likely break it or cause unintended side effects.</li>



<li><strong>Action:</strong> Block deployments in capabilities that do not meet these structural standards.</li>
</ul>



<h2 class="wp-block-heading">The digital insider strategy</h2>



<p>We must treat agents not as software, but as digital insiders mapped to specific capabilities.</p>



<ul class="wp-block-list">
<li><strong>Containment via capability:</strong> Assign agents role-based access control (RBAC) strictly tied to the resources of their parent capability. This prevents a compromised agent from moving laterally across the enterprise.</li>



<li><strong>Budgeting as governance:</strong> Bind compute and token budgets to the capability. If an agent enters a loop of rapid-fire, low-value transactions, the capability’s budget cap acts as a circuit breaker, preventing runaway costs.</li>
</ul>



<h2 class="wp-block-heading">Case study: R&amp;D vs. aftermarket sales</h2>



<p>An automotive OEM evaluates two potential pilots. The capability map determines viability based on boundary isolation and data integrity.</p>



<ul class="wp-block-list">
<li><strong>Capability A: Autonomous drive research (high maturity)</strong>
<ul class="wp-block-list">
<li><em>Assessment:</em> Data integrity is high (petabytes of structured driving data). Boundary isolation is strict (air-gapped simulation environment).</li>



<li><em>Decision:</em> <strong>Go.</strong> The agent is deployed to generate synthetic training scenarios and is bound to the R&amp;D compute budget.</li>
</ul>
</li>



<li><strong>Capability B: Aftermarket parts supply chain (low maturity)</strong>
<ul class="wp-block-list">
<li><em>Assessment:</em> Data integrity is low (reliance on legacy mainframes and manual spreadsheets). Boundary isolation is poor (tightly coupled systems).</li>



<li><em>Decision:</em> <strong>No go.</strong> Deploying an agent here creates identity sprawl and high risk. The recommendation is to remediate the data architecture <em>before</em> piloting the agent.</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading">The cost of inaction</h2>



<p>The trade-offs of ignoring these architectural primitives are severe.</p>



<ul class="wp-block-list">
<li><strong>Financial:</strong> Without capability-tied controls, organizations risk unmanaged operational spikes from inefficient agent loops.</li>



<li><strong>Security:</strong> A lack of value stream definitions leads to unmanaged agent-to-agent interactions, allowing threats to exploit undefined trust boundaries.</li>



<li><strong>Strategic:</strong> Fragmented pilots result in identity explosion — thousands of non-human identities that cannot be audited, rotated or governed.</li>
</ul>



<p>In the age of agentic AI, architecture is no longer an ivory tower discipline. It is the prerequisite for safety, scalability and value.</p>



<h2 class="wp-block-heading">From gatekeeper to market maker</h2>



<p>For the past decade, EA has often been mischaracterized as a department of no — a friction layer that slows agile delivery. In the agentic era, this dynamic inverts. Because agents are non-deterministic, governance is no longer a constraint on speed; it is the mathematical prerequisite for it.</p>



<p>Without the structural guardrails of value streams and capability maps, the CIO cannot scale agentic fleets beyond the prototype stage. The risk of hallucinations cascading into production databases forces the organization to keep human-in-the-loop ubiquitously, negating the economic benefits of the labor substitution.</p>



<p>By implementing these architectural primitives, the chief architect transforms from a gatekeeper into a market maker for digital labor.</p>



<h2 class="wp-block-heading">The new economic equation: Cost of verification vs. cost of execution</h2>



<p>The value of an agent is not defined by how fast it runs, but by how little it needs to be watched.</p>



<ul class="wp-block-list">
<li><strong>The ungoverned state:</strong> The cost of execution is low, but the cost of verification is infinite. Every output requires human review because trust boundaries are undefined.</li>



<li><strong>The architected state:</strong> By hardening the value stream with observability checkpoints and halting logic, the cost of verification drops to near zero for all transactions within the defined autonomy zone.</li>
</ul>



<p><strong>The recommendation:</strong> Shift the ROI metric. Do not measure AI adoption (a vanity metric). Measure autonomous throughput — the volume of transactions an agent executes <em>without</em> human intervention, enabled strictly by architectural confidence.</p>



<h2 class="wp-block-heading">The technical implementation: The dynamic control plane</h2>



<p>To operationalize this, EA must partner with platform engineering to embed these concepts into the runtime environment. The capability map must evolve from a static PowerPoint into a policy engine residing within your API gateway or service mesh.</p>



<ul class="wp-block-list">
<li><strong>Policy-as-code:</strong> When an agent attempts an API call, the gateway checks the readiness heatmap.</li>



<li><strong>Runtime logic:</strong>
<ul class="wp-block-list">
<li><em>Does the calling agent possess the cryptographic signature required for this value stream stage?</em></li>



<li><em>Is the target capability rated “mature” for write-access?</em></li>



<li><em>Is the request within the capability’s token budget?</em></li>
</ul>
</li>
</ul>



<p>If the answer is no, the transaction is rejected at the network layer. This allows the chief architect to govern 10,000 agents without reviewing a single line of code.</p>



<h2 class="wp-block-heading">The architect’s moment</h2>



<p>We are witnessing the industrialization of cognition. Just as the assembly line required industrial engineers to organize labor into efficient physical streams, the agentic enterprise requires enterprise architects to organize digital labor into efficient logical streams.</p>



<p>The organizations that treat this transition as a software upgrade will drown in operational opacity. The organizations that treat it as an architectural restructuring — using value streams to direct flow and capabilities to secure boundaries — will capture the market.</p>



<p>Architecture is no longer an ivory tower discipline. I believe it is the only way to build a firm that is both safe and fast.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI isn’t failing, people are failing with AI]]></title>
<description><![CDATA[In 2018, Google released the AI model BERT, forever changing how machines understood context in a language. BERT, short for Bidirectional Encoder Representations from Transformers, solved a long-standing problem in natural language understanding. Before BERT, researchers needed multiple bespoke m...]]></description>
<link>https://tsecurity.de/de/3304888/it-security-nachrichten/ai-isnt-failing-people-are-failing-with-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3304888/it-security-nachrichten/ai-isnt-failing-people-are-failing-with-ai/</guid>
<pubDate>Mon, 23 Feb 2026 13:17:45 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In 2018, Google released the AI model <a href="https://arxiv.org/pdf/1810.04805" rel="nofollow">BERT</a>, forever changing how machines understood context in a language. BERT, short for Bidirectional Encoder Representations from Transformers, solved a long-standing problem in natural language understanding. Before BERT, researchers needed multiple bespoke models (and datasets) to understand the different contextual meanings of human languages. BERT demonstrated that one model could process contextual meaning across multiple languages (via mBERT).</p>



<p>While BERT became a fundamental building block in natural language processing (NLP), its impact on how we interact with computers came from its application. That change did not come from shoehorning the technology into existing solutions. It stemmed from an applied understanding of how BERT functioned, would evolve and could solve domain-specific challenges. I know because my team at Google used BERT to create responsive search ads. Our work transformed online text advertising.</p>



<p>Our success in applying BERT wasn’t simply because we had TPUs or more resources than our competitors. (Those things helped, undoubtedly.) Our advantage was my team’s domain expertise and close collaboration with the Google Research team, who created the model. Collectively, we could envision how to apply BERT to fundamentally reshape advertising because we understood:<br><br></p>



<ol start="1" class="wp-block-list">
<li><strong>How the model operates</strong>, including its strengths, weaknesses and dependencies.</li>



<li><strong>The specific industry problems and operational challenges</strong> we were solving for.</li>



<li><strong>The way we’d tune the model and create a system around it,</strong> at scale.</li>
</ol>



<p>This framework remains pertinent today, as business leaders seek to understand how to build and deliver scaled impact with large language models (LLMs).</p>



<h2 class="wp-block-heading">Weighing the pros and cons of models</h2>



<p>As critics and pundits debate the efficacy of generative AI, numerous studies underscore a similar finding: people are unsure of how to use LLMs. To address these uncertainties, leaders need to ensure that their organization’s decision-makers understand, at a high level, how these models function and can be applied.</p>



<p>That technical understanding mattered when we applied BERT. It matters even more now. Because while BERT required domain expertise to deploy effectively, today’s LLMs make it dangerously easy to deploy them poorly and unknowingly. It’s likely the reason so many AI projects never proceed past pilots, <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai#/download/%2F~%2Fmedia%2Fmckinsey%2Fbusiness%20functions%2Fquantumblack%2Four%20insights%2Fthe%20state%20of%20ai%2Fnovember%202025%2Fthe-state-of-ai-in-2025-agents-innovation-and-transformation.pdf%3FshouldIndex%3Dfalse">as McKinsey reported.</a></p>



<p>BERT’s success underscored the power of pre-training and fine-tuning a model on a large dataset to enhance token-level semantic context within NLP. But where BERT zigged, OpenAI’s Generative Pre-trained Transformer (GPT) zagged. Unlike BERT’s encoder-only architecture, GPTs use a decoder-only architecture to generate outputs, trained to predict the next token in a sequence. BERT was trained on billions of tokens, while today’s GPTs are trained on trillions. The more tokens these LLMs were trained upon, the more capabilities they gained.</p>



<p>Early applications of these LLMs have centered on their ability to generate creative, fluent and coherent writing, coding and imagery. This “creativity” reflects the probabilistic patterns that these models have learnt from their massive training datasets. But this same predictive output can be disadvantageous when these models need to be deployed in factual, deterministic environments.</p>



<p>Deep learning researchers have long argued that setting any rules, following the historical method of symbolic reasoning, would inhibit the model’s abilities. Structured to predict an output, even when the model is uncertain, LLMs have demonstrated a tendency to hallucinate. Hallucinations are not a bug, but a feature. They’re inherent to how these models operate and should limit your applications without guardrails. After all, mistakes in consequential industries like healthcare, finance and legal can be catastrophic.</p>



<p>This historical comparison, while surface-level, still illustrates how the model’s underlying functions impact its outputs and applications. Understanding these architectures solves half the problem. The other half is building a strategy to collect and scale data within your specific domain.<strong></strong></p>



<h2 class="wp-block-heading">AI’s scaling problem is a domain problem</h2>



<p>Healthcare, finance and legal are all industries with ample data and capital to spend. While each sector presents distinct challenges, they all have found success with AI.</p>



<p>Hospitals epitomize the opportunities and obstacles within the healthcare industry. The average<a href="https://www.statnews.com/2024/12/03/health-care-data-storage-environmental-cost-climate-change/#:~:text=Ask%20anyone%20in%20this%20field,of%20data%20becomes%20incomprehensibly%20large."> hospital generates 50 petabytes</a> of data annually, enough tokens to train a sophisticated model. But 97 percent of this data isn’t used: it consists of unstructured clinical notes and radiology reports, redacted documents following HIPAA compliance, and data siloed or managed under regulatory scrutiny. When you can access it cleanly, as illustrated by <a href="https://pubs.rsna.org/doi/abs/10.1148/radiol.243688" rel="nofollow">AI detections of tumors in radiology images</a>, a measurable impact is possible. When you can’t, your pilot stalls.</p>



<p>Finance presents different tradeoffs. Transaction data is generally well-structured and high-volume, enabling novel applications in fraud detection and customer service automation. But limiting these applications is<a href="https://arxiv.org/html/2508.05201v2" rel="nofollow"> </a><a href="https://arxiv.org/html/2508.05201v2" rel="nofollow">LLMs’ high error rates</a> on multi-step numerical reasoning, creating fundamental misalignment for calculation-intensive applications.</p>



<p>The pervasiveness of<a href="https://www.thomsonreuters.com/en-us/posts/technology/genai-hallucinations/" rel="nofollow"> </a><a href="https://www.thomsonreuters.com/en-us/posts/technology/genai-hallucinations/" rel="nofollow">hallucinations spotted in trial briefs</a> and documents has sown distrust in AI within the legal industry.<a href="https://www.msba.org/site/site/content/News-and-Publications/News/General-News/ABAs_2024_Legal_Technology_Survey_Report_Trends_in_Online_Research.aspx" rel="nofollow"> </a><a href="https://www.msba.org/site/site/content/News-and-Publications/News/General-News/ABAs_2024_Legal_Technology_Survey_Report_Trends_in_Online_Research.aspx" rel="nofollow">The ABA’s 2024 Legal Technology Survey</a> found 75% of attorneys cite accuracy concerns as a primary barrier to their AI adoption. But outside the courtroom, there are many applications of AI to radically reshape legal work, including managing contracts, conducting compliance and risk assessments, protecting intellectual property, etc. These instances lend themselves to LLMs’ strengths: ability to handle unstructured data, pattern recognition, information extraction and data structure analysis.</p>



<h2 class="wp-block-heading">Your development framework to scale data</h2>



<p>The distinction between courtroom risk and contract is exactly the advantage that we identified at Ironclad. Every business function generates contracts that include information on renewal dates, payment terms, obligations and counterparty details. Training models on this data is a strategy that leverages LLMs’ strengths with minimal risk.</p>



<p>Compared to legal briefs and documents, where incorrect AI summaries have massive implications, the risk of applying AI to contracts is lower. Our approach at Ironclad is modeled after the automotive industry’s safety framework for deploying autonomous vehicles, the SAE J3016. This standard distinguishes between systems in which humans retain responsibility (Levels 1-2, driver assistance) and those in which machines become accountable (Levels 3-5, automated driving).</p>



<p>Applied to enterprise AI, this risk-based framework clarifies deployment roadmaps and boundaries. We chose to develop our Intake Agent, which extracts contract data from third-party papers, and our Conversational Search Agents, which enable natural language querying of documents, because we saw them as “Level 1-2” applications with low adoption barriers and associated risks. Verifying a contract autonomously, while plausible with today’s LLMs, might seem innocuous, but unsupervised verification could be very risky. There’s a plausible scenario in which an agent could overlook litigation between the two engaged parties and autonomously renew a contract because it can’t access the tort proceedings data.</p>



<p>Using a risk-based framework can help determine where and how to build your AI applications by answering the question: what’s the likelihood we’ll get this right, and what happens if we’re wrong? This calculation, not competitive pressure, should then determine your deployment sequencing.</p>



<h2 class="wp-block-heading"><a></a>Build a foundation, create transformation</h2>



<p>During my twenty-plus years of working with AI, I’ve found that the most significant determinant of a technology’s impact on a business is the organization’s fluency with it.</p>



<p>As planning ensues, organizations trying to determine how and where to apply generative AI to their business need first to have an introspective look and ask themselves:</p>



<ol class="wp-block-list">
<li><strong>Do you understand the technology’s actual mechanisms? </strong>Not marketing promises, but fundamental architecture. LLMs perform statistical pattern matching, not logical reasoning. They require extensive general training followed by domain-specific fine-tuning. Without this understanding, you’ll deploy for impossible tasks.</li>



<li><strong>How does the industry you’re serving share, collect and store data? </strong>W<strong>hat data will you use to tune and fine-tune your models, if at all? </strong>LLMs are foundational because they require sophisticated pre-training, followed by fine-tuning to generate meaningful, domain-specific outputs.</li>



<li><strong>Do you have a framework, such as a risk-based model, to prioritize, deploy and assess which products to develop?</strong> Start with low-risk, human-supervised applications. Conduct evaluations and build feedback loops. Expand systematically as reliability proves out.</li>
</ol>



<p>Over my career, I’ve watched people overestimate what AI can do this quarter while underestimating what it will do this decade. Technology evolves. Industries are reshaped. But transformations are created by businesses that do the foundational work.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 AI strategy archetypes every CIO should know]]></title>
<description><![CDATA[“Such an embarrassment of a flag carrier. I will never fly AC unless I absolutely have to.”



“This is absolutely outrageous.”



These were some of the nicer social media reactions on carrier Air Canada following November 2022, when a well-intended chatbot on the airline’s website confidently i...]]></description>
<link>https://tsecurity.de/de/3297646/it-security-nachrichten/4-ai-strategy-archetypes-every-cio-should-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3297646/it-security-nachrichten/4-ai-strategy-archetypes-every-cio-should-know/</guid>
<pubDate>Thu, 19 Feb 2026 13:05:57 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><em>“Such an embarrassment of a flag carrier. I will never fly AC unless I absolutely have to.”</em></p>



<p><em>“This is absolutely outrageous.”</em></p>



<p>These were some of the nicer <a href="https://www.reddit.com/r/vancouver/comments/1ase30c/air_canada_forced_to_refund_vancouver_customer" rel="nofollow">social media reactions</a> on carrier Air Canada following November 2022, when a well-intended <a href="https://www.wired.com/story/air-canada-chatbot-refund-policy/" rel="nofollow">chatbot on the airline’s website confidently invented a refund policy</a>, triggering lawsuits and a reputational crisis far outweighing the chatbot’s original cost-saving ambition. Not unlike <a href="https://fortune.com/2025/06/09/duolingo-ceo-surprised-backlash-ai-first-company-announcement/" rel="nofollow">Duolingo</a>, <a href="https://economictimes.indiatimes.com/news/international/us/company-that-sacked-700-workers-with-ai-now-regrets-it-scrambles-to-rehire-as-automation-goes-horribly-wrong/articleshow/121732999.cms" rel="nofollow">Klarna</a> and <a href="https://www.forbes.com/sites/tonybradley/2025/07/15/mcdonalds-ai-breach-reveals-the-dark-side-of-automated-recruitment/" rel="nofollow">McDonald’s</a>, Air Canada had not failed because it used AI — but because it failed to align AI with business priorities.</p>



<p>Under huge pressure from boards and markets, organizations now declare themselves AI-first before answering a far more fundamental question: AI for what and what not, exactly? For CIOs, this is no longer a technological question but a strategic one. Organizations too often rush ahead without first properly aligning AI with their business model, established value creation approaches and the risks their company can handle.</p>



<p>We propose a fix: 4 AI strategy archetypes, as we call them. These blueprint-like AI approaches were distilled from our yearslong AI strategy work and help CIOs delineate valuable AI playing fields while balancing both hype (risk blindness) and overcaution (missed opportunities).</p>



<p>By forcing critical appraisal of these extremes, strategy archetypes foster a productive strategy dialogue within the top management team and help organizations avoid their own Air Canada moment.</p>



<h2 class="wp-block-heading">Incorporating AI strategically</h2>



<p>This is important as, despite prominent cautionary tales, too many leadership teams still talk about AI as if there was a single “right” strategy. But this ignores two ways in which organizations profoundly differ: their key levers to create value and the risk degree they can tolerate.</p>



<p>Some firms place bold bets on AI moonshots (as <a href="https://www.chemicalindustryjournal.co.uk/the-new-chemists-ai-agents-are-transforming-the-chemical-industry" rel="nofollow">now observable in the chemical industry</a>), accepting failure risks in exchange for potential market-redefining advantages. Others build on industry-proven, incremental AI optimizations of existing processes with predictable returns.</p>



<p>Even more importantly, AI is still too often unaligned with organizations’ competitive strategies. A luxury goods provider such as Hermès focuses on protecting its craftsmanship, brand image and product scarcity. A retailer like Walmart, on the other hand, has built its business model on operational excellence, scale and exceptional cost efficiency. Clearly, it’s strategic nonsense to expect both to leverage AI in the same way. And yet, such crucial differences are precisely what we see AI discussions miss out on too often.</p>



<p>Why do we still lack more established strategy tools helping the C-suite fit AI strategy to their distinctive business models and value creation logics? The answer, our professional practice shows, is not another AI maturity model.</p>



<p>Throughout years of AI advisory, we started to notice something striking. In our and others’ AI strategy work across industries, geographies and organizational maturities, as well as countless conversations with CIOs, CEOs, CFOs and heads of AI and data, we saw some distinctive strategic patterns around AI emerge.</p>



<p>With each month in the trenches of AI strategy, we further realized it was one differentiator putting a few leading AI organizations ahead of the pack: a decisive clarity and explicitness about where to focus AI efforts in value creation while saying no to disproportionate risk.</p>



<p>Observing this choice across organizations, we distilled four distinct AI strategy archetypes that can help leadership teams position AI very deliberately, have a more productive AI strategy dialogue and make smarter bets — before an Air Canada moment forces this conversation.</p>



<h2 class="wp-block-heading">AI strategy archetypes: How they simplify the AI strategy dialogue</h2>



<p>To bring clarity into a company’s AI strategy dialogue, it’s critical to take a step back and recall two fundamental dimensions of business strategy:</p>



<p>The first is the value creation focus: Is AI primarily focused on improving internal processes — i.e., to increase efficiency, productivity and employee capabilities — or is it more externally focused on improving products, services and customer value propositions?</p>



<p>The second dimension is risk tolerance: Does the company deliberately pursue bold, experimental AI bets while accepting uncertainty and failure along the way or does it favor proven AI practices and applications that can be implemented with rather predictable outcomes?</p>



<p>From these two dimensions’ intersection spring four distinct AI strategy archetypes — each with typical strategic measures, each legitimate, each powerful in its own context when aligned with a firm’s business model (see figure 1). It is these two dimensions that anchor the AI strategy dialogue between hype and overcaution.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?quality=50&amp;strip=all 1444w, https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?resize=300%2C228&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?resize=768%2C584&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?resize=1024%2C779&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?resize=917%2C697&amp;quality=50&amp;strip=all 917w, https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?resize=221%2C168&amp;quality=50&amp;strip=all 221w, https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?resize=110%2C84&amp;quality=50&amp;strip=all 110w, https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?resize=631%2C480&amp;quality=50&amp;strip=all 631w, https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?resize=473%2C360&amp;quality=50&amp;strip=all 473w, https://b2b-contenthub.com/wp-content/uploads/2026/02/ai-strategy-archetypes.png?resize=329%2C250&amp;quality=50&amp;strip=all 329w" width="1024" height="779" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><em><strong>Figure 1</strong>. AI strategy archetypes.</em></figcaption></figure><p class="imageCredit">Gerlinde Zimmermann, Marc Feldmann</p></div>



<h3 class="wp-block-heading">Archetype 1: Pioneers</h3>



<p>Pioneers operate in the high-risk, externally focused value creation quadrant of the 2 x 2 matrix. They view AI as a vehicle for breakthrough innovation and are willing to place moonshot bets on untested technologies, novel data sources or entirely new AI-enabled products and markets.</p>



<p>Pioneers accept that many initiatives will fail — and budget for that reality — because they know that few successes can redefine industries or create new ones altogether.</p>



<h3 class="wp-block-heading">Archetype 2: Innovators</h3>



<p>Innovators also embrace risk, but they focus on internal AI activities. Their goal is not to disrupt markets, but rather to radically reinvent the way their company works. Innovators use AI to challenge long-established processes, automate complex decision-making processes and fundamentally rethink operating models. They are the cultural antithesis of “but we’ve always done it this way”-organizations.</p>



<p>Going forward, this will often imply exploring <a href="https://www.cio.com/article/4109639/the-agentic-ai-mindset-redefining-work-from-how-to-what.html">agentic AI as a completely new approach</a> to rethinking the operating model.</p>



<h3 class="wp-block-heading">Archetype 3: Performers</h3>



<p>Performers sit at the opposite end of the risk spectrum, with an internal focus on value creation. They pursue AI pragmatically, using a test-and-scale mindset to incrementally improve efficiency, quality and speed.</p>



<p>Performers rely on comparably mature, well-understood AI use cases — some more frequent topics are financial forecasting, predictive maintenance and rule-based process automation — and embed these cases deeply into existing processes to gradually increase performance.</p>



<h3 class="wp-block-heading">Archetype 4: Pathfinders</h3>



<p>Pathfinders combine low risk tolerance with an external focus. Rather than betting on bold invention, they systematically scan their industry and competitors for AI use cases that have already proven their value elsewhere. They prefer learning from the mistakes that others have made first.</p>



<p>Their strength lies in adapting best-practice AI solutions to their own context in small, controlled steps. For pathfinders, AI strategy is less about being first — and more about arriving with minimal bruises.</p>



<p>But how do AI strategy archetypes really look in action?</p>



<h2 class="wp-block-heading">Case study: Western Rail — strategic repositioning for AI value creation</h2>



<p>Imagine a regional public transport provider, Western Rail, being under pressure back in 2024. Ticket vending machines and travel agencies as non-digital sales channels were no longer what travelers wanted, burdening the P&amp;L with idle costs.</p>



<p>Western Rail also faced margin pressures in public tenders from emerging, low-overhead local competitors. AI initiatives (such as an AI customer support chatbot) had been launched here and there, but as lighthouses rather than measures rigorously focused on actual business needs. Money was being burnt and initial AI enthusiasm among staff started to turn into frustration.</p>



<p>When a new CIO entered the firm, he tasked a small team of AI specialists to radically refocus Western Rail’s AI approach. In initial strategy workshops with channel leadership, the specialists introduced AI strategy archetypes as a navigation system for the firm’s AI strategy dialogue. Performer, pathfinder and the other archetypes provided an intuitive language to talk about AI for the mostly non-technical leadership team.</p>



<p>To establish a common departure point, the team probed leadership on Western Rail’s current AI value creation: They asked: “Are we pursuing results with AI more in our internal processes and costs or around traveler satisfaction and product innovation? Did last year’s AI project ideas spring primarily from operational bottlenecks or from transportation market requirements?”</p>



<p>The specialists also made leadership reflect on the firm’s current AI risk tolerance, asking: “How much budget and time for experimentation do we give teams today before demanding tangible business outcomes? Do staff and competitors view our AI project approvals overall as conservative or bold?”</p>



<p>Being pushed on such questions made a diffuse feeling concrete for leadership: Investments in AI had not produced desired results precisely because the firm had been trying to run in many directions simultaneously. Industry-novel, high-risk cases resembling the innovator archetype were being explored (such as AI travel agents on terminals in travel agencies). Simultaneously, customer support teams were dabbling with process automation tools to cut manual ticket routing and processing — a typical performance measure.</p>



<p>This spread resources thin, preventing the focus and learning curves the firm’s AI initiatives would have needed to truly transform Western Rail’s business — either via differentiating digital innovation of traditional ticket sales channels or radical automation, allowing it to compete with lean emerging players based on cost efficiency.</p>



<p>Archetype-driven questioning in the workshops, deepened by follow-up interviews with operational staff, eventually led the leadership team to one shared problem understanding: With its current AI activities, Western Rail was strategically in a classical stuck-in-the-middle situation.</p>



<p>To refocus Western Rail’s AI activities on business priorities, the AI specialists set up another workshop, this time starting with a slide showing the AI strategy archetype matrix. A red dot in the middle marked Western Rail’s current all-rounder (non)position.</p>



<p>The specialists explained each archetype, asking: “What archetype best aligns with our business priorities and should we move toward over the next 2 to 5 years?” With the archetypes right in front of them, leadership had the concrete blueprints to set a direction for the very first time. To some, the performer archetype had an immediate appeal as it seemed to fit well with Western Rail’s need to control costs.</p>



<p>To explore this target position, the AI specialists challenged the group with follow-up questions such as: “Does our future competitiveness really hinge on internal efficiency and incremental process improvements? Or rather, on a differentiating traveler experience? Will expected shifts in market conditions and traveler behavior require bold mobility innovations from us or rather re-emphasize consumers’ price sensitivity and thus affordable tickets?</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?w=1024" alt="Fig2: Western Rail AI strategy workshop" class="wp-image-4134040" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?quality=50&amp;strip=all 1376w, https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?resize=300%2C228&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?resize=768%2C584&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?resize=1024%2C779&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?resize=916%2C697&amp;quality=50&amp;strip=all 916w, https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?resize=221%2C168&amp;quality=50&amp;strip=all 221w, https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?resize=110%2C84&amp;quality=50&amp;strip=all 110w, https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?resize=631%2C480&amp;quality=50&amp;strip=all 631w, https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?resize=473%2C360&amp;quality=50&amp;strip=all 473w, https://b2b-contenthub.com/wp-content/uploads/2026/02/western-rail-ai-strategy-workshop.png?resize=329%2C250&amp;quality=50&amp;strip=all 329w" width="1024" height="779" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><em><strong>Figure 2. </strong>Illustration from Western Rail AI strategy workshop.</em></figcaption></figure><p class="imageCredit">Gerlinde Zimmermann, Marc Feldmann</p></div>



<p>During the following discussions, a consensus emerged: a performer approach to AI became seen as a North Star for best leading Western Rail into the future (see Figure 2). The reasons were the performer archetype’s cautiousness and focus on internal process efficiency. Achieving such focus became seen as particularly desirable in the customer service team, due to a recently exploding request volume following government ticket subsidies.</p>



<p>In the following weeks, a roadmap with strategic measures to reposition from all-rounder to performer was developed, focusing on adaptation of industry-proven AI use cases, elimination of high-stakes use cases and experimental research cooperations and declaring automation of labor-intensive travel agency and customer support processes as high-leverage AI application areas.</p>



<p>At Western Rail, which was lacking clarity and focus of AI efforts, the performer archetype became not only a powerful template for sponsors to assess upcoming project ideas (“Will this investment make us more or less of a performer?”), it also became a vivid and practical rationale for helping leaders explain to staff why some projects were started and others postponed, giving orientation in everyday project work (“Would this AI assistant’s proposed functionality scope make agency shift planning cheaper and faster or introduce unjustified complexity?”).</p>



<h2 class="wp-block-heading">Where AI strategy archetypes help most</h2>



<p>AI strategy archetypes — as experience-grounded strategic blueprints — help those firms most that struggle with the early question: “Which AI approach is right for us?” At the same time, AI strategy archetypes are not AI strategy lite and certainly not AI strategy replacement. Instead, AI strategy archetypes help set a fruitful destination early on. In doing so, they can kickstart the development of a fleshed-out AI strategy that spells out how to get there.</p>



<p>While designed with the development of an AI stance for one business unit in mind, the AI strategy archetype framework is also applicable to business unit portfolios. Where different business units have different value creation approaches and risk tolerances, one unit may adapt the performer archetype, while another might need to become an innovator. In any case, each business unit will best be served by having its own dedicated strategy dialogue.</p>



<p>AI strategy archetypes act as a navigation system for AI starters, telling CIOs and other leaders where to look first for AI use cases in their firms and how to clarify the level of acceptable risk. With that, archetypes are a powerful tool that can disentangle organizations’ emerging AI strategy dialogue.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p><a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proving AI deployment value needs a more strategic approach]]></title>
<description><![CDATA[You wouldn’t judge the value professional chefs bring to Michelin-starred restaurants by how quickly they chop onions. So why is there such a focus on time saving at work through AI usage?



AI tools, from copilots to agentic systems, have the potential to reinvent entire business workflows, imp...]]></description>
<link>https://tsecurity.de/de/3290661/it-security-nachrichten/proving-ai-deployment-value-needs-a-more-strategic-approach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3290661/it-security-nachrichten/proving-ai-deployment-value-needs-a-more-strategic-approach/</guid>
<pubDate>Mon, 16 Feb 2026 11:06:47 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You wouldn’t judge the value professional chefs bring to Michelin-starred restaurants by how quickly they chop onions. So why is there such a focus on time saving at work through AI usage?</p>



<p>AI tools, from copilots to agentic systems, have the potential to reinvent entire business workflows, impacting business models and changing how enterprises deliver value. Time savings, on the other hand, are easy to measure through employee surveys and analytics collected from heavily monitored activities such as customer care.</p>



<p>So taking this easier approach and just trying to do the same activities in less time is not the way to look at this. Longer-term strategic thinking is required, and businesses that examine what they do from the ground up, and consider how AI could allow them to reconfigure these activities to create value for customers, will be the winners in these turbulent times.</p>



<h2 class="wp-block-heading">Cutting headcount is not a strategy</h2>



<p>No company ever shrank to greatness. Sure, <a href="https://www.cio.com/article/4012162/ai-begins-to-reshape-the-it-job-landscape-as-layoffs-rise.html?utm=hybrid_search">laying off staff in downturns</a> may sometimes be necessary, and deploying AI as a way to do this may bring a short-term bump to the bottom line. But it’s missing the real opportunities AI presents and could actually do longer term damage to a business. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-03-gartner-predicts-half-of-companies-that-cut-customer-service-staff-due-to-ai-will-rehire-by-2027" rel="nofollow">Gartner predicts</a> half of companies cutting customer service staff due to AI will rehire by 2027. They reason AI is just not mature enough to replace the subtleties and empathy that humans bring to customer interactions. The danger, Gartner argues, is that while immediate cost savings may be attractive, there’s a danger of unintended consequences further down the line.</p>



<p>This sentiment is echoed by Ronnie Sheth, CEO of SENEN, a strategic consultancy focused on data and AI. She warns against taking a technology-first approach such as deploying copilots and self-service chatbots without thinking about customer needs and preferences. It’s counterproductive, as a growing number of companies are finding, to handle more customer queries if customer satisfaction levels go down. “To truly realize value, AI initiatives should map directly to strategic business objectives by a defined percentage, not just internal soft metrics such as time saved,” Sheth says.</p>



<h2 class="wp-block-heading">Focus on quality not quantity</h2>



<p>In a world starting to drown in AI-generated slop, the quality of outputs and customer interactions will become ever-more important. Copilots and other AI tools can play a key role in driving quality up, but choosing the right metrics to measure this is key. Founder of technology advisory firm Deep Analysis, Alan Pelz-Sharpe sees the focus on deploying copilots primarily to raise employee outputs as a mistake. “Somebody might write more code, but is it good code and does it actually deliver measurable business value,” he asks. “So if your measurement is tasks completed per hour or headcount, you can argue that you did more, but did you do better, did you deliver enough value to justify the cost and change.”</p>



<p>On top of this, he warns of not monitoring for possible negative consequences further down the line. This is particularly true with coding assistants capable of producing code at speed but which, without skilled human oversight, can cause problems weeks or months later as systems become exposed to the harsh realities of business environments.</p>



<p>A <a href="https://www.harness.io/state-of-software-delivery" rel="nofollow">2025 survey</a> by Harness of 500 software engineers found that while just over 80% felt AI was useful in their jobs, they were also struggling with a blast radius effect where bad code was going into production faster and with a greater impact. This included debugging with 67% of developers spending more time cleaning up code generated by AI, and 68% spending more time dealing with security vulnerabilities from such code.</p>



<h2 class="wp-block-heading">Not business as usual</h2>



<p>Despite justified talk of AI bubbles fuelled by some ridiculous investments and valuations of companies unlikely to ever live up to their promises, a revolution is underway. Seeing AI as a bolt-on that can help businesses perform a bit more efficiently is missing a key point. <a href="https://www.cio.com/article/4104444/8-tips-for-rebuilding-an-ai-ready-data-strategy.html?utm=hybrid_search">How data is gathered, processed, shared, and used</a> is being transformed in terms of speed and quantity but, more importantly, AI is changing how decisions are made on the basis of that data.</p>



<p><a href="https://www.cio.com/article/4119297/how-to-get-your-enterprise-architecture-ready-for-agentic-ai.html?utm=hybrid_search">As agentic solutions evolve</a>, many roles currently performed by humans will either radically change or disappear altogether. When word processing systems emerged in the 1970s and 1980s, a key measure of their value was how much quicker secretaries and admin assistants could produce written documents. However, the real impact of word processors and the PCs that replaced them has been the transfer of much of this work to executive staff, who now manage their own admin tasks.</p>



<p>The impact of AI will be far greater. Enterprises need to rethink how useful their current business processes and, by extension, their business models will be when AI is able to automate or even make current practices redundant. Simply performing current activities quicker is not the way to think about this.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Are there guaranteed cybersecurity benefits with Agentic AI implementation?]]></title>
<description><![CDATA[Can Non-Human Identities Reinvent Cybersecurity with Agentic AI? What if the key to fortifying cybersecurity lies not in more layers of defense, but in effectively managing the machine identities that already exist within your organization’s infrastructure? Enter Non-Human Identities (NHIs)—the…
...]]></description>
<link>https://tsecurity.de/de/3288842/it-security-nachrichten/are-there-guaranteed-cybersecurity-benefits-with-agentic-ai-implementation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3288842/it-security-nachrichten/are-there-guaranteed-cybersecurity-benefits-with-agentic-ai-implementation/</guid>
<pubDate>Sun, 15 Feb 2026 00:33:26 +0100</pubDate>
<content:encoded><![CDATA[<p>Can Non-Human Identities Reinvent Cybersecurity with Agentic AI? What if the key to fortifying cybersecurity lies not in more layers of defense, but in effectively managing the machine identities that already exist within your organization’s infrastructure? Enter Non-Human Identities (NHIs)—the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/are-there-guaranteed-cybersecurity-benefits-with-agentic-ai-implementation/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/are-there-guaranteed-cybersecurity-benefits-with-agentic-ai-implementation/">Are there guaranteed cybersecurity benefits with Agentic AI implementation?</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Prompt governance is the new data governance]]></title>
<description><![CDATA[Not long ago, prompt writing felt like a personal skill. Something you refined quietly, stored in a notes app or copied between chat windows when something worked particularly well.



That model no longer holds.



Across organizations, Generative AI (GenAI) prompting is now shaping executive su...]]></description>
<link>https://tsecurity.de/de/3284053/it-security-nachrichten/prompt-governance-is-the-new-data-governance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3284053/it-security-nachrichten/prompt-governance-is-the-new-data-governance/</guid>
<pubDate>Thu, 12 Feb 2026 14:06:28 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Not long ago, prompt writing felt like a personal skill. Something you refined quietly, stored in a notes app or copied between chat windows when something worked particularly well.</p>



<p>That model no longer holds.</p>



<p>Across organizations, Generative AI (GenAI) prompting is now shaping executive summaries, policy drafts, operational dashboards, clinical documentation and production user interfaces. Yet, in many environments, prompts remain scattered across chat histories, documents and inboxes—unowned, unversioned and largely invisible.</p>



<p>What we’re seeing is a pattern familiar to anyone who has lived through the early—and still persistent—days of shadow IT, as described by David Talby in his article <a href="https://www.cio.com/article/4107318/shedding-light-on-shadow-ai.html">Shedding light on shadow AI</a>. In practice, prompts are quietly becoming enterprise interfaces, but without the governance structures we instinctively apply to data, code or systems.</p>



<p>And like data sprawl before it prompt sprawl creates reliability issues, inefficiency and risk long before leadership realizes what’s happening.</p>



<p>As Talby notes, “People use shadow AI because it’s easy…”</p>



<h2 class="wp-block-heading">Prompt sprawl as shadow IT operations</h2>



<p>In conversations with technology leaders and in recent industry reporting, the issue of prompt sprawl mirrors earlier patterns of data sprawl.</p>



<p>As pointed out in <a href="https://www.deloitte.com/content/dam/assets-zone3/us/en/docs/services/consulting/2025/ai-institute-ai-use-cases-10-06-2025.pdf" rel="nofollow">Deloitte’s AI Dossier</a>, teams are using GenAI daily, often productively but prompts live everywhere: personal chat threads, shared documents, Slack messages, wiki pages. There is no single source of truth and no clear owner. Two people ask the same question and receive meaningfully different answers. Outputs get reworked quietly because the user phrased the prompt just a bit differently. But no one fixes the underlying cause – they simply place a Band-Aid on the issue and move on. Drift unobtrusively enters the equation, and no one notices until outputs no longer align.</p>



<p>This matters for three reasons CIOs care deeply about: reliability, efficiency and risk.</p>



<ol class="wp-block-list">
<li><strong>Reliability</strong>. When the same prompt yields different outputs depending on who runs it or how it’s phrased, decision variance creeps in. Leadership starts questioning not just the AI, but the systems that depend on it.</li>



<li><strong>Efficiency</strong>. As teams duplicate effort, reinvent prompts and rework outputs there is no shared definition of what “good” looks like. Efficiency erodes at the edges and tribal knowledge replaces institutional process and accepted best practice.</li>



<li><strong>Risk</strong>. Ungoverned prompts can leak sensitive inputs, hallucinate policy or create inconsistent external messaging. In regulated or high-stakes environments, that is not theoretical risk, it is operational exposure, as Sofia will expand on later.</li>
</ol>



<p>What I’m seeing isn’t an ephemeral tooling problem. Nor is it a training gap that can be solved by teaching people to write better prompts. The issue is structural. Prompts have crossed a threshold where they influence institutional outcomes, and anything that does <em>that</em> needs governance.</p>



<h2 class="wp-block-heading">Towards a prompt governance framework</h2>



<p>To make prompt governance actionable, my co-author Sofia Penna Elneser and I use a prompt governance framework that borrows intentionally from data governance and software delivery disciplines and adapts them to the realities of GenAI.</p>



<p>Our framework rests on five pillars.</p>



<ol class="wp-block-list">
<li><strong>Purpose and alignment: </strong>Every governed prompt must have a clear intent, approved use case and owner. The goal is not to limit experimentation, but to distinguish exploratory prompts from those that shape decisions, systems or records of truth.</li>



<li><strong>Quality and consistency: </strong>Prompts define expected output shape, tone and structure. Acceptance criteria are explicit. This reduces variance and makes outputs predictable without requiring identical wording every time.</li>



<li><strong>Lifecycle management: </strong>Prompts are versioned, reviewed, refined and eventually retired as obsolescence becomes obvious. Changes are intentional, not accidental. Mature organizations maintain a prompt library just as they maintain shared code or templates.</li>



<li><strong>Risk and compliance: </strong>This aligns closely with the National Institute of Standards and Technology’s AI Risk Management Framework (<a href="https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf" rel="nofollow">A.1.2. Organizational Governance</a>), which emphasizes that AI systems embedded in operational workflows require explicit governance, accountability and ongoing risk assessment. When designing and surfacing our prompts, we set a tiered risk system. Low-risk prompts require light governance. High-risk prompts, those touching policy, finance or patient care, require formal review, testing and escalation paths. We actively document use cases, inputs, outputs and known risks associated with each deployment.</li>



<li><strong>Measurement and enablement: </strong>Adoption, rework and incident rates are tracked. Teams are enabled through templates, examples and direct access to subject matter experts rather than constrained by heavy process.</li>
</ol>



<p>To make this practical, we map these pillars onto a maturity ladder:</p>



<ul class="wp-block-list">
<li><strong>Risk Level 1</strong>: Ad hoc experimentation</li>



<li><strong>Risk Level 2</strong>: Emerging structure</li>



<li><strong>Risk Level 3</strong>: Standardization</li>



<li><strong>Risk Level 4</strong>: Enterprise governance</li>



<li><strong>Risk Level 5</strong>: Regulated, safety-critical operations</li>
</ul>



<p>Low-risk AI use cases tolerate stylistic variance; high-risk use cases cannot. Prompt governance is what allows organizations to move between those levels intentionally rather than reactively.</p>



<p>What this looks like in practice becomes clear when you examine real systems. In the first two case studies below, I break down how my prompts were created and versioned for production at Levels 3 and 4. Sofia then writes about the Level 5 clinical-grade digital assets she employs in a medical technology setting.</p>



<h2 class="wp-block-heading">What prompt governance looks like in practice</h2>



<h3 class="wp-block-heading">Governing consistency in a creative AI workflow (Risk Level 3)</h3>



<p>At the urging of our creative director, I first applied prompt governance principles in a creative context: generating illustration concepts for the American Mathematical Society (AMS) textbook <a href="https://bookstore.ams.org/MBK/154"><em>Analytic Number Theory Revealed: A First Guide to Prime Numbers</em></a> by Andrew Granville.</p>



<p>My role was not creative per se, that responsibility belonged to the creative team, but to improve consistency and efficiency across iterations. The author communicated an intuitive, experience-driven set of visual preferences. The project required multiple illustrations translating advanced mathematical ideas into symbolic imagery. Maintaining a coherent visual language across those illustrations was essential, as iteration cycles with the author were time-consuming and costly. From the outset, the author’s “I’ll know it when I see it” sensibility shaped the process.</p>



<p>Early experimentation with generative AI exposed predictable failure modes. Small changes to prompts produced noticeable stylistic drift, overly literal mathematical representations or inconsistent composition. While creativity was present, it lacked stability. Outputs varied in ways that undermined visual cohesion rather than supporting it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/02/tarot-style-nash-equilibrium.png" alt="Tarot-style AI illustration of the Nash Equilibrium, an advanced mathematical concept." class="wp-image-4130962" srcset="https://b2b-contenthub.com/wp-content/uploads/2026/02/tarot-style-nash-equilibrium.png?quality=50&amp;strip=all 576w, https://b2b-contenthub.com/wp-content/uploads/2026/02/tarot-style-nash-equilibrium.png?resize=200%2C300&amp;quality=50&amp;strip=all 200w, https://b2b-contenthub.com/wp-content/uploads/2026/02/tarot-style-nash-equilibrium.png?resize=465%2C697&amp;quality=50&amp;strip=all 465w, https://b2b-contenthub.com/wp-content/uploads/2026/02/tarot-style-nash-equilibrium.png?resize=112%2C168&amp;quality=50&amp;strip=all 112w, https://b2b-contenthub.com/wp-content/uploads/2026/02/tarot-style-nash-equilibrium.png?resize=56%2C84&amp;quality=50&amp;strip=all 56w, https://b2b-contenthub.com/wp-content/uploads/2026/02/tarot-style-nash-equilibrium.png?resize=320%2C480&amp;quality=50&amp;strip=all 320w, https://b2b-contenthub.com/wp-content/uploads/2026/02/tarot-style-nash-equilibrium.png?resize=240%2C360&amp;quality=50&amp;strip=all 240w, https://b2b-contenthub.com/wp-content/uploads/2026/02/tarot-style-nash-equilibrium.png?resize=167%2C250&amp;quality=50&amp;strip=all 167w" width="576" height="864" sizes="auto, (max-width: 576px) 100vw, 576px"></figure><p class="imageCredit">Tim McMahon</p></div>



<p>I addressed this by treating the prompt as a versioned production asset rather than an ad hoc creative input. The creative director and I collaborated on a baseline specification, which I formalized into a structured style guide for use with the GenAI tool. This specification defined constraints such as symbolic density, phased execution and an embedded self-check to validate alignment with the agreed visual language before producing final output.</p>



<p>The result was a set of tarot-style illustrations that differed meaningfully in subject matter but clearly belonged to the same visual system. The author’s creativity was not constrained; production variability was. Once my role was complete, the creative team resumed control of the assets, refining them as needed and preparing them for publication in the final work.</p>



<p>The image shown in this section is an example of the prompt in action. This was not used in the author’s book, rather I used the master prompt and GenAI to create a new JSON file and then output a card explicitly for this article.</p>



<p>If a follow-on volume to the author’s work were to require continuation of this motif, the organization would avoid several thousand dollars in additional production effort. The system would be reused rather than built from scratch.</p>



<p>This reflects Level 3 prompt governance maturity: standardized quality, scalability and repeatability without the overhead of enterprise-wide controls.</p>



<h3 class="wp-block-heading">Governing correctness and reuse in a production system (Risk Level 4)</h3>



<p>I applied the same governance principles in a far less forgiving environment: a production workflow supporting the AMS Annual Meeting, also known as the <a href="https://jointmathematicsmeetings.org/jmm" rel="nofollow">Joint Mathematics Meetings</a>. This is the largest mathematical conference in the world, where the daily schedule is a mission-critical asset rather than a creative deliverable.</p>



<p>In this case, GenAI supported the creation of scripts that consume a live pipeline of conference data normalized into JSON. This was then rendered to accessible, Bootstrap-based user interfaces. Inconsistency here is not solely an aesthetic concern. It breaks pages, confuses users and creates long-term maintenance risk.</p>



<p>As in Use Case 1, early experimentation exposed familiar failure modes: hallucinated fields, inconsistent keys, partial outputs and subtle divergence between environments. These failures were unacceptable at this scale. Compounding the challenge was organizational inertia, stakeholders accustomed to improvisational change were now being asked to operate within explicit, rules-based constraints.</p>



<p>The solution was not a better prompt and prompt chain, but a governed system boundary that can be reused year after year. I introduced a constrained, pipeline-aware specification that encoded an authoritative data source, schema validation, complete-file output and accessibility requirements.</p>



<p>Once those constraints were in place, outputs became predictable. Debugging shifted from “why did the model do this?” to “which rule was violated?” This workflow now moved from an experimental helper to a reliable, bounded participant in production workflows, one whose behavior could be reasoned about, validated and trusted.</p>



<p>In the interest of full disclosure, I will state that the system is still evolving. I do not doubt that next year the system will be better defined and further refined.</p>



<p>This process reflects Level 4 maturity: governed systems where the workflow is subordinate to explicit authority, validation and human accountability.</p>



<p>Up to this point, the failures encountered were costly but recoverable. In creative and operational systems, inconsistency wastes time, undermines trust and creates technical debt. When GenAI begins feeding systems of record and affecting human outcomes, that margin disappears. In healthcare, prompts no longer function as flexible instructions; they operate as regulated components.</p>



<h3 class="wp-block-heading">Treating prompts as clinical-grade digital assets in medical technology (Risk Level 5)</h3>



<p>Our highest-risk example comes from the medical technologyindustry.</p>



<p>In this setting, the stakes change. While a stylistic variance is fine in a creative workflow, even a slight deviation from the source text in a clinical environment is a liability as these outputs become part of the patient’s permanent health record.</p>



<p>At Meditech, Sofia works on use cases that assist providers and nurses in the transition of care. While traditional clinical summaries are notoriously time-consuming, Generative AI provides Hospital Courses and Hand-Off notes in seconds instead of hours.</p>



<p>For example, there is a clinical difference between saying a patient “is experiencing” a symptom versus saying a patient “has a history of” that same symptom. If an ungoverned model interprets a past condition as an acute, present emergency, it’s a clinical error with consequences, not just a creative flourish or a “model inference.”</p>



<p>At this level of risk, treating prompts as clinical-grade assets becomes a fundamental requirement, elevating them from simple instructions to the strategic center of context engineering. By implementing a pipeline that prioritizes specifications, versioning and rigorous evaluation, raw AI potential is turned into a reliable enterprise-grade engine.</p>



<h2 class="wp-block-heading">From “vibe check” to version control: The production pipeline</h2>



<p>When a prompt influences a patient’s permanent record or a mission-critical schedule, it can no longer live in a black box of unversioned GChat histories.</p>



<p>The shift from creative flexibility of Use Case 1 to the clinical precision of Meditech’s clinical-grade assets in Use Case 3 illustrates a hard truth: the tolerance for prompting by intuition drops to zero.</p>



<p>To move from ad-hoc experimentation to enterprise-grade reliability, prompt writing is replaced by a prompt production pipeline: a structural, repeatable discipline that mirrors software delivery. And it starts with simple questions: What and Why?</p>



<h3 class="wp-block-heading">The functional spec</h3>



<p>Just as data governance requires a schema, prompt governance requires a definition of what “good” looks like. We identify the problem before the AI solution by establishing exactly what we are trying to accomplish and why.</p>



<p>The functional spec determines our expected shape, tone and structure. It also identifies the sections of the prompt that shouldn’t vary. These are called “prompt partials,” and they can include the core role, the brand voice, safety wrappers, etc. In other words, the mission and vision of the prompt are an asset.</p>



<h3 class="wp-block-heading">The design</h3>



<p>With the spec as our blueprint, the full set of instructions follows. This is where ownership is assigned. To prevent unowned and invisible sprawl, every prompt needs a person or team responsible for its logic, ensuring the design meets the goals laid out in the spec.</p>



<h3 class="wp-block-heading">The prompt bundle</h3>



<p>Once designed, we lock the prompt together with the specific model version and configuration parameters (like Temperature or Top-P). This bundle belongs in a shared repository, not a private folder or a DM. This creates an audit trail that turns a black box into a transparent history of who changed what and why. It also allows for decoupling—the ability to update the AI “brain” without having to redeploy our entire application’s code.</p>



<h3 class="wp-block-heading">Testing</h3>



<p>Once we have our what and why (spec), the who (ownership) and the where (Bundle), we move on to testing.</p>



<p>Testing shouldn’t and can’t be a one-time event. It must happen with every iteration. This is why we determine model configurations early. By locking in the Seed, Top P, Top K, Temperature, etc., we drastically reduce the random “AI magic” factor. When these configurations are set correctly, any variation in results can be attributed to prompt changes, not just the model having a “creative” day.</p>



<h3 class="wp-block-heading">The evaluation loop</h3>



<p>Keeping our Functional Spec in mind, we develop an evaluation threshold. We ask the hard questions: What is a non-negotiable requirement in the output? Is it a specific length? A strict JSON format? A grounding in clinical truth?</p>



<p>Once these standards are set, we evaluate a reasonable number of high-variance test cases and document the results. It isn’t enough to just see if V5 “looks good.” We must track how prompts behave in relation to themselves and previous versions to identify drift before it enters production. Custom AI agents can assist in evaluating generated outputs as well by creating a continuous automated loop.</p>



<h3 class="wp-block-heading">Review &amp; deployment</h3>



<p>This is a fundamental step to ensure prompt governance. Just like code, no prompt hits production without a dual-check, where a third, unbiased, human-in-the-loop audits and approves the proposed changes that will eventually become the new prompt version.</p>



<h2 class="wp-block-heading">Prompts are infrastructure now</h2>



<p>Across creative publishing, production systems and clinical documentation, we have seen the same pattern repeat. As GenAI moves closer to decision-making, prompts stop being experiments and start being infrastructure.</p>



<p>What changes is not the need for governance but the cost of getting it wrong.</p>



<p>The sooner prompts are treated as governed digital assets — owned, versioned, tested and measured — the easier it becomes to scale safely. Not because governance slows innovation, but because it makes trust possible.</p>



<p>For CIOs, the practical shift is simple: any prompt that is reused, shared or relied upon should be treated as a governed digital asset, not an improvisation.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What CIOs must get right for the AI era]]></title>
<description><![CDATA[In an era defined by AI, automation, cloud scale, and rising customer expectations, today’s CIOs are navigating a once-in-a-generation strategic inflection point. The pressure to modernize legacy environments has never been higher. The demand for speed, innovation, and business value has never be...]]></description>
<link>https://tsecurity.de/de/3283579/it-security-nachrichten/what-cios-must-get-right-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3283579/it-security-nachrichten/what-cios-must-get-right-for-the-ai-era/</guid>
<pubDate>Thu, 12 Feb 2026 10:36:07 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In an era defined by AI, automation, cloud scale, and rising customer expectations, today’s CIOs are navigating a once-in-a-generation strategic inflection point. The pressure to modernize legacy environments has never been higher. The demand for speed, innovation, and business value has never been greater. And the challenge of getting it all right at the same time has never been more complex.</p>



<p>Shelia Anderson, chief information and digital officer at Unum Group, describes this moment as “managing the dance”: the dance between stabilizing and modernizing the core while accelerating new digital capabilities; between protecting the enterprise and empowering it; and between delivering for customers today and architecting a future where AI and automation fundamentally reshape how work gets done.</p>



<p>In a recent episode of <a href="https://linktr.ee/techwhisperers" rel="nofollow">the Tech Whisperers podcast</a>, Anderson shared what CIOs must get right architecturally, operationally, culturally, and strategically to lead effectively in this AI-powered era. Afterwards, she expanded on the essential questions shaping the CIO agenda as enterprises reinvent themselves for the future.</p>



<p>As Anderson makes clear, this moment requires more than technical strategy. It demands leaders who can architect for the future while modernizing the past, who can move fast without breaking trust, and who can balance innovation with empathy. What follows is our conversation, edited for length and clarity.</p>



<p><strong>Dan Roberts: When you</strong><strong> think about the architecture of the future, what are the non-negotiables CIOs must get right to support AI, automation, cloud scale, security, and faster innovation? </strong> </p>



<p><strong>Shelia Anderson:</strong> You have to get a vision of where you are today and where you’re going. You have to get that foundationally right. It’s about establishing a future target and making sure that you have an understanding of your current state as well — that’s table stakes for me.</p>



<p>You’ll often hear me talk about multi-year planning. I am a big believer in a three-year plan. <a href="https://www.cio.com/article/3618308/whatever-happened-to-the-three-year-it-roadmap.html">It’s tough right now to have a three-year plan</a>. Still, establishing a solid outlook for even the next 12 months is important. We have to find balance between the legacy technology that we have — and we’re all still dealing with it — and the new emerging technology and disruption that’s coming.</p>



<p>There has to be enough rigor and focus on how to get from where we are today to the new. That’s one of the things that’s going to challenge most of us: How do we think about the blocking and tackling, the modernizing, and the reality that “<a href="https://www.cio.com/article/3954989/massive-modernization-tips-for-overhauling-it-at-scale.html">modernizing</a>” may look very different with all the new capabilities we have coming? A multi-year plan is the tool that can help us balance priorities and get from here to there.</p>



<p>Also table stakes for me is the talent approach to all of this as you think about the future. You have a roadmap based upon a rigorous architecture discipline. How are you thinking about aligning your talent to that? Because it all anchors back to your vision of the future, the timing of that transformation, and a multi-year plan and roadmap. And layered on top of that are your organization’s constraints — capacity for change, investment strategy, whatever they are — all these things come together.</p>



<p><strong>Modern architecture works only if the operating model evolves with it. How do you think about designing the operating model of the future to move at the speed the business now demands?</strong></p>



<p>We’ve got to learn how to put a little jet fuel beneath what’s called agile today to drive it forward at yet another level of speed, particularly when it comes to speed to value and speed to outcomes. More teams are going to ask for that. It’s a clear ask from our CEO, so it’s always top of mind for me.</p>



<p>We’re working in close partnership with our business to reimagine how to solve for an end-to-end view of our business while enabling speed, agility, and adaptability. For example, we’re exploring how to design our operating model of the future around end‑to‑end value streams rather than the core capabilities we use today. It’s about organizing around the customer lifecycle, putting the customer front and center, while creating clear accountability and clear ownership around decision‑making as well.</p>



<p>Then, focus on the governance aspect: How do you make sure you are prioritizing the work and making sure it’s aligned to those priorities? Next, look at the constraints you have. As much as things are changing, the familiar constraints still exist: people, process, and technology. If you have a constraint around your investment processes, for example, then you have to address how to balance those across the others.</p>



<p>Ultimately, I think success depends on collaboration, continuous learning, an integrated approach, and process, process, process. With AI and the pace of innovation, we have to totally rethink our business processes, and it’s not always going to be about iterative or evolutionary change. It’s going to be revolutionary in many situations.</p>



<p><strong>Every CIO I talk with is trying to find that Goldilocks zone where the balance between modernization, innovation, speed, value, and risk is not too much, not too little, but just right. How do you approach that balancing act? And how do you help your organization understand the choreography behind the decisions you make?</strong></p>



<p>First, you have to have a foundational understanding of the current situation within your business. I always follow the dollars in the beginning, because that tells you a lot about where the business sees the opportunity to get value and whether your investments are really achieving that. Then, I look at the balance of investment between run‑the‑business and change‑the‑business activities. It’s a balancing act to reduce run costs to free up funds for value creation on the change-the-business side.</p>



<p>Getting that foundational view of what that situation is first will help you make better investment decisions around everything — for example, how you source work for everything from tier 1, mission-critical capabilities to commodity services. Those are the things that we have to make very intentional decisions around. I’m going to put my best, most innovative, probably higher-dollar and skilled people on that mission-critical piece of work, and maybe I’m going to source that commodity service differently so I can free up those dollars to drive them more towards value creation.</p>



<p>Transparency in the decision‑making is key. You have to explain the choreography behind the dance and the trade‑offs. That’s not a science; it’s a muscle that allows you to navigate through stop, start, continue decisions. If we want to start shifting investment dollars to higher value creation, then that also implies that you’re actively making choices to deprioritize other things. That’s where those relationships and the ability to adapt and trade off are going to matter, so you can get alignment around the decisions.</p>



<p>And then I always like to say, use the data to help you to make informed decisions. Use your governance, use your metrics, to help you in making your decision so you can get into that Goldilocks zone. As long as you’re aligned with your business — if your business is saying, “We’re at a point where we want to invest more for this period of time in this one capability, and we’re going to minimize investment in another” — that’s fine. You can support the decision and align to that if that’s where your business wants to take it.</p>



<p><strong>What does workforce transformation look like in this AI-driven era, and how are you helping your 2,000 technologists navigate disruption, build confidence, and develop the skills needed to thrive in the future of work?</strong></p>



<p>There’s a massive amount of change and expectations coming at all people, especially those of us in technology. There’s all this new emerging technology, a lot coming with AI, that brings expectations around how you shift from ways of working today to a level of productivity expectation tomorrow from leveraging these new capabilities.</p>



<p>One thing I’m doing to take fear out of the equation is to help teams see a path forward. I do that by setting goals for the organization and having a vision around those goals. That gives you confidence — as an individual sitting in a chair — that there’s a vision not to replace me here but to help me be prepared with the skills needed for the future. Jobs will change a bit, and in the engineering space, definitely, you’re going to see a higher dependency upon leveraging these capabilities to help you get more work done. That’s the expectation. We’ll have the capacity to say “yes” more often. We’ve already proven that out in some early pilots and tests. So, I’m excited about the future opportunity, and I think when the success comes, we’ll all be celebrating that.</p>



<p>At the same time, I think about the broader AI‑ready workforce. Regardless of where you’re at in the organization, all people are going to have to learn how to leverage these new tools effectively. To do that, identifying things like skill gaps and targeting future growth skills is going to be important. Creating learning pathways and, more than anything, reinforcing that culture of continuous learning, change, and adaptability is going to be key. Offering targeted training and upskilling to help people learn the new tools, plus transparency about how those capabilities will change and, ultimately, augment or enhance their jobs, will build confidence for the future.</p>



<p><strong>You’ve been recognized with some of the most prestigious awards in our profession, including <a href="https://www.cio.com/article/236876/cio-hall-of-fame-honorees.html">the CIO Hall of Fame</a> and Constellation’s BT150, which highlights the world’s most influential business technology leaders. What do they represent to you about your career and leadership journey?</strong></p>



<p>I feel like I’ve gone viral in the last quarter of my career. I haven’t necessarily changed, but there’s an awareness factor that has come through — maybe through my network, through participating in some of these organizations, for getting out there and sharing the stories of my companies.</p>



<p>As a female leader in technology, I feel a tremendous opportunity and commitment to set a precedence so other leaders can see this as a role that they could aspire to be in as well. That’s what it really means to me, and I don’t take the responsibility lightly. It’s representing a future path for other women, and other technology leaders as well. Sharing my story is important, and I think these recognitions definitely do that. The awards also help to highlight some of the wins across the whole industry and the great teams that I’ve had the opportunity to be a part of. It represents all that work across all the years.</p>



<p><strong>What advice would you offer the next generation of leaders stepping into this AI-driven future?</strong></p>



<p>You won’t always know how developing new skills and early experiences will pay off later.</p>



<p>The role I probably disliked the most was when I was running a global network for American Airlines. I was an applications leader, and my leader asked me to take on the network responsibility. I didn’t enjoy it; it was painful. But I learned how to optimize business. Then 9/11 happened and I learned how to reimagine how I work with every supplier, renegotiate contracts, things I never imagined I’d do and that I use today. I am a shrewd contract negotiator, and I credit that skill all the way back to when I was a senior director in that role.</p>



<p>You never know what will happen. Take those opportunities, the stretch roles, raise your hand, and pivot when you can. Don’t focus on going up; focus on horizontal expansion. That’s where you’re going to build the toolkit you will carry for your whole career. It’ll help you be successful in the later years, when you are moving up into senior roles.</p>



<p>There’s also the power of context, which I relate to that broader view of strategy and vision and understanding larger opportunities and outcomes. When you’re early in your career, if you laser focus on the thing in front of you, you’re going to miss what I call the fringe opportunities. So, from a career perspective, broaden your horizons. Think of the broader view of whatever it is, whether you’re solving a problem or seeking advice. Context gives you a perspective of situational details, and all of those things come together to help you see if something is really significant, or how much weight you should give it. Context helps you pick your battles.</p>



<p>Finally, make <a href="https://www.cio.com/article/4085392/5-business-concepts-it-leaders-should-master.html">business fluency</a> a big part of what you focus on. Don’t focus just on the technology of the moment. Technology comes and goes, which means you need to be continually learning new technical skills. Be a continuous learner, have curiosity, ask great questions, and focus the early part of your career on skill-building and building a great breadth of experience.</p>



<p><em>As organizations confront the realities of AI, shifting operating models, and rising expectations, Anderson offers a blueprint for leading with clarity, courage, and a deep commitment to people, the true engine of every transformation. For more insights from her leadership playbook, tune in to </em><a href="https://linktr.ee/techwhisperers" rel="nofollow"><em>the Tech Whisperers podcast</em></a><em>.</em></p>



<p><strong>See also:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4120226/rethinking-it-leadership-to-unlock-the-agility-of-teamship.html">Rethinking IT leadership to unlock the agility of ‘teamship’</a></li>



<li><a href="https://www.cio.com/article/4110735/tiaas-sastry-durvasula-offers-cios-a-blueprint-for-engineering-whats-next.html">TIAA’s Sastry Durvasula offers CIOs a blueprint for engineering what’s next</a></li>



<li><a href="https://www.cio.com/article/4104358/decision-intelligence-the-new-currency-of-it-leadership.html">Decision intelligence: The new currency of IT leadership</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw and Claude Opus 4.6: Where is AI agent security headed?]]></title>
<description><![CDATA[Author: IBM Technology - Bewertung: 0x - Views:20 Explore the podcast → https://ibm.biz/BdpHsU

Are enterprises moving too fast with AI—and breaking security in the process? 

In this episode of Security Intelligence, host Matt Kosinski is joined by Sridhar Muppidi, Nick Bradley and Jeff Crume to...]]></description>
<link>https://tsecurity.de/de/3281434/it-security-video/openclaw-and-claude-opus-46-where-is-ai-agent-security-headed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3281434/it-security-video/openclaw-and-claude-opus-46-where-is-ai-agent-security-headed/</guid>
<pubDate>Wed, 11 Feb 2026 12:17:03 +0100</pubDate>
<content:encoded><![CDATA[<p>Author: IBM Technology - Bewertung: 0x - Views:20 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/g9LO9M1ZLIk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Explore the podcast → https://ibm.biz/BdpHsU<br />
<br />
Are enterprises moving too fast with AI—and breaking security in the process? <br />
<br />
In this episode of Security Intelligence, host Matt Kosinski is joined by Sridhar Muppidi, Nick Bradley and Jeff Crume to unpack a pivotal moment in cybersecurity. <br />
<br />
The panel dives into the rapid rise of AI agents and the growing risks of shadow AI in the enterprise, comparing open-source agent platforms like OpenClaw with proprietary models such as Claude Opus 4.6 and its new agent teams. We explore how speed-first AI adoption, unsecured agent implementations and weak separation of duties are creating new attack surfaces—and why executives may be unintentionally fueling the problem. <br />
<br />
The conversation also examines the recent Notepad++ supply chain breach as a warning sign of broader software inventory and supplier risk failures, and analyzes DragonForce’s attempt to reinvent ransomware as a scalable cartel business. <br />
<br />
Along the way, we keep returning to a key theme: Have we optimized for velocity at the expense of security? <br />
<br />
00:00 -- Intro <br />
01:18 -- OpenClaw vs. Claude Opus 4.6 <br />
15:05 -- Move fast. Break security? <br />
27:29 -- Notepad++ breach <br />
38:55 -- DragonForce ransomware cartel <br />
<br />
The opinions expressed in this podcast are solely those of the participants and do not necessarily reflect the views of IBM or any other organization or entity. <br />
<br />
Subscribe to the IBM Think newsletter → https://ibm.biz/BdpHs5<br />
<br />
#OpenClaw #ClaudeOpus #shadowAI<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ways AI proves its worth at Avnet]]></title>
<description><![CDATA[Electronic components distributor Avnet oversees supply chains for major corporations, but more importantly, the Phoenix-based multinational leverages intelligence insight from its data to help understand what’s important for customers to move product for maximum profitability.



“Everything we ...]]></description>
<link>https://tsecurity.de/de/3281268/it-security-nachrichten/ways-ai-proves-its-worth-at-avnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3281268/it-security-nachrichten/ways-ai-proves-its-worth-at-avnet/</guid>
<pubDate>Wed, 11 Feb 2026 11:07:51 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Electronic components distributor Avnet oversees supply chains for major corporations, but more importantly, the Phoenix-based multinational leverages intelligence insight from its data to help understand what’s important for customers to move product for maximum profitability.</p>



<p>“Everything we do from an AI standpoint helps to fulfil that philosophy,” says <a href="https://www.linkedin.com/in/ljchan/" rel="nofollow">CIO Max Chan</a>. “Leveraging AI means <a href="https://www.cio.com/article/4113707/when-it-comes-to-ai-not-all-data-is-created-equal.html?utm=hybrid_search">cleansing data</a> so customers can make the right decisions.”</p>



<p>With over 100 years of history to look back on, Avnet has always been able to prioritize technological investment as its ecosystem has grown more complex. Fundamentally important is adhering to what’s most important to the business. “Instead of having my own technology or approach to digital AI, the strategy is how do we enable the business,” he says. “So every capability we have, we look at technology, digital enablement, and AI transformation to help accelerate, redesign, or reimagine them. It’s all about helping to transform the business.”</p>



<p>Of course, ROI from AI can be elusive, but Chan sees missteps or flawed strategies as evidence oflooking at the wrong place. “Some people look for ROI from an investment in AI itself,” he says. “It’s like the traditional ways of looking at FinOps, for instance, to look at how much you’re spending, improving, and making out of it. We look at it differently. To us, AI is transformational, so when we implement something with AI in mind, we look at what business outcome are we hoping to drive. We get the right pricing and a more complete quote to the customer to help them learn what that converts to in terms of top and bottom line.”</p>



<p>But just like everything else regarding technology investment or digital enablement, success comes down to <a href="https://www.cio.com/article/221699/7-change-management-certifications-to-boost-your-it-career.html?utm=hybrid_search">change management</a> and governance. “Change management is key, but the overall governance of going back to whether something is contributing to a business outcome, or is directly supporting a business strategy, is essential,” he adds. “Otherwise, people will look at different POCs and use cases. We’re only looking for what directly links to strategic capabilities and the business outcome we’re looking for.”</p>



<p>Chan also details modernizing legacy systems with greenfield architectures, and partnerships that build resilience and customer value across industries. Watch the full video below for more insights, and be sure to subscribe to the monthly Center Stage newsletter by clicking <a href="https://www.cio.com/newsletters/signup/">here</a>.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<p><strong>How AI helps distribution: </strong>We see very strong leverage in the sales enablement site, engineering design, managing inventory and forecasting, and orchestrating the supply chain. The common thread across all these areas is the actionable insight and data we have. So from a sales enablement perspective, what comes to mind is quoting, which is the most important thing as a distributor in terms of being informed and passing that on as quickly as we can to customers. For them, they’re able to get their products at the point they need. For us, we’re able to win the business and improve conversion. AI has helped us with pricing, getting the right information on end of life and country of origins, and putting it all together so the customer can make the best decision for what they do. It’s also about how we can help our customer service agents have readily available information to advise people. So we use it internally and externally.</p>



<p><strong>On the heavy lift of legacy systems: </strong>This has been a long journey we’ve been on. Avnet continues to reinvent and apply the same mentality to modernize with technology. Over 30 years ago, we decided we wanted to go to a major <a href="https://www.cio.com/article/4121113/erp-in-2026-more-ai-more-best-of-breed-add-ons.html?utm=hybrid_search">ERP</a> to run everything, but within the last 10 years, we realized that such a monolithic environment isn’t good enough. So we started building, just like everyone else, to get benefit from cloud transformations and build on top of it. But what my team and I quickly learned was that wasn’t going to cut it. We had support from the organization to start from scratch, and build a modern architecture that’s digital and AI first, which allows us to leverage different capabilities. The mentality of continuous improvement, and not to get hung up on what we’ve built over the last 30 years, has helped us with that success in driving AI and the transformation we see today.</p>



<p><strong>On the changes AI brings: </strong>It comes back to <a href="https://www.cio.com/article/4049233/5-actions-to-build-an-ai-ready-data-culture.html?utm=hybrid_search">the culture and learning agility</a> we want everyone in the organization to have. Interestingly, AI is probably a lot easier than most other technologies that came before it because of ChatGPT, gen AI, and the many different tools that suddenly came up in the last few years. Everyone got excited. Trying to create that learning pathway, and getting people systematically upskilled to be able to approach and leverage AI the right way, is what we’re doing across the organization. We see it like there are three different types of AI to grapple with. One is productivity tools like ChatGPT that we give people to do what they need to do. The second is what comes with all the software you have, since all major software comes with AI components. Then last are the things my team would develop and build in accordance with what we want in order to drive the company forward, and how we transform. So we have more than enough tools that we allow the organization to leverage, and we have a governance process to request what people can use, or we give them an alternative. If it comes with the software we own, if we already have the license, then go for it since it’s embedded and will help us better leverage the software. The focus we have on AI is what we’re doing to transform the way we work, the workforce, the work itself, and in some cases, the business and how we can better serve our customers and employees. One way is reimagining some end-to-end processes to see if they can be fully autonomous. If so, what would it look like? Once that’s done, we bring people back in the loop to augment it and make it even more powerful for our business.</p>



<p><strong>On AI impacting workflows: </strong>As far as disruption and resiliency from a supply chain standpoint, focus is on relationships with customers, both upstream and downstream, and understanding what they are, what they have, what they need to do, and what they want to do. And the signals we send around the industry help strengthen that resiliency. We get asked how can we help avoid the next supply chain debacle, and it comes down to partnerships, availability of data, and connectivity. In order for us to do that internally, from a tech stack standpoint, we need to target the modern architecture that drives microservices and allows us to have <a href="https://www.cio.com/article/4018578/why-cios-see-apis-as-vital-for-agentic-ai-success.html?utm=hybrid_search">strong API connections</a>. We created a platform called the Partner Digital Exchange, which helps bring data downstream, and combines it with what we have to drive orchestration. And that allows us to bring AI into the mix and help customers with the information they need. It also helps Avnet create that stickiness in the ecosystem.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone 18 Charger Rumors: Bigger Battery and Support for Apple’s Foldable iPhone]]></title>
<description><![CDATA[Apple’s next flagship, the iPhone 18, is shaping up to be one of the biggest iPhone releases in years. While Apple has not officially confirmed detailed specifications, industry leaks suggest changes around power delivery, charging, and battery performance.



Apple has moved all recent iPhone mo...]]></description>
<link>https://tsecurity.de/de/3249355/ios-mac-os/iphone-18-charger-rumors-bigger-battery-and-support-for-apples-foldable-iphone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3249355/ios-mac-os/iphone-18-charger-rumors-bigger-battery-and-support-for-apples-foldable-iphone/</guid>
<pubDate>Tue, 03 Feb 2026 00:19:59 +0100</pubDate>
<content:encoded><![CDATA[Apple’s next flagship, the iPhone 18, is shaping up to be one of the biggest iPhone releases in years. While Apple has not officially confirmed detailed specifications, industry leaks suggest changes around power delivery, charging, and battery performance.



Apple has moved all recent iPhone models to USB-C charging, following global regulatory shifts. The iPhone 18 series is expected to continue with this standard. USB-C may offer faster wired charging speeds than previous Lightning ports. Exact wattage figures for the iPhone 18 are not yet confirmed, but improvements are likely given Apple’s focus on efficiency and battery performance.



Wireless charging remains an important part of Apple’s ecosystem. Current MagSafe wireless chargers deliver up to 25 W to recent iPhones when paired with a compatible adapter. This standard is expected to carry over to the iPhone 18 line. Apple could also refine MagSafe alignment and efficiency.



These are the more or less expectations around charging and power delivery for the iPhone 18:




USB-C Port for wired charging, data transfer, and accessory support.



Faster Wired Charging potential compared with earlier models.



MagSafe Wireless Charging, likely up to 25 W with Qi2 standard support.



Better Battery Management through hardware and software optimizations.




Battery technology across the iPhone 18 lineup may see incremental boosts. The Pro Max version of the iPhone 17 had a battery around 4823–5088 mAh depending on configuration. Apple normally increases capacity slightly or tunes efficiency with each generation. Leaks also point to new silicon-carbon cell types that can hold more energy without increasing thickness.



Rumors around the iPhone foldable coming with a 5500 mAh battery show that Apple is pushing capacity higher in devices with larger screens.



Charging performance often depends on the power adapter as well. For peak wired speeds, Apple recommends a 30 W or higher USB-C adapter for current MagSafe charging and USB-C performance.



Final Word



Early details suggest that iPhone 18 models will build on existing charging technology rather than reinvent it. USB-C and improved MagSafe standards should make everyday charging smoother. Incremental battery improvements promise longer use between charges. Exact numbers for charging rates and battery sizes will become clearer as launch details firm up later this year.]]></content:encoded>
</item>
<item>
<title><![CDATA[Plenty of talent, too little readiness: How AI is forcing CIOs to rethink hiring]]></title>
<description><![CDATA[After spending a decade helping shape talent strategy as a business professor and now working inside an AI-first organization, I see hiring very differently than I did even a few years ago. Managing people, evaluating fit and understanding how teams evolve have always been central to my work, but...]]></description>
<link>https://tsecurity.de/de/3241383/it-security-nachrichten/plenty-of-talent-too-little-readiness-how-ai-is-forcing-cios-to-rethink-hiring/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3241383/it-security-nachrichten/plenty-of-talent-too-little-readiness-how-ai-is-forcing-cios-to-rethink-hiring/</guid>
<pubDate>Thu, 29 Jan 2026 11:06:17 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>After spending a decade helping shape talent strategy as a business professor and now working inside an AI-first organization, I see hiring very differently than I did even a few years ago. Managing people, evaluating fit and understanding how teams evolve have always been central to my work, but the pace at which expectations have shifted in the age of AI has been unlike anything I have seen before.</p>



<p>Across the past years, I have interviewed candidates in product, analytics, engineering, operations and strategy. One thing is clear: hiring the right people today is more challenging than it was even two years ago. And it is not because there are fewer applicants. It is because there is less alignment between what modern AI-driven organizations actually need and what traditional education, resumes and interviews were designed to evaluate. What follows is my firsthand perspective on why hiring has become more complex and how leaders can rethink their approach.</p>



<h2 class="wp-block-heading">The talent mismatch: Plenty of applicants, not enough readiness</h2>



<p>A major shift I continue to observe is the growing gap between traditional training and what AI-era roles expect. Many candidates come with strong conceptual knowledge but limited exposure to working with AI tools or navigating environments where systems evolve faster than processes can catch up.</p>



<p>The <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai-how-organizations-are-rewiring-to-capture-value?utm_source=chatgpt.com">McKinsey State of AI report</a> supports this shift, noting that AI adoption is advancing faster than most organizations can reskill their workforce.</p>



<p>I see the same thing in interviews. Candidates understand concepts, but applying them in fast-changing, ambiguous environments is where the gap reveals itself.</p>



<p>This is where mindset becomes a decisive factor. In AI-influenced settings, adaptability and curiosity matter as much as domain expertise. The professionals who thrive are the ones who experiment, explore and stay hands-on with new tools even when the roadmap is unclear. One question I often ask is simple but revealing: When technology shifts, how do you keep up? The strongest candidates talk about tinkering, testing and learning by doing.</p>



<h2 class="wp-block-heading">The AI polish effect: Why evaluating true capability is harder</h2>



<p>Generative AI has made it incredibly easy for people to present themselves as polished and prepared. With AI-drafted resumes, refined stories and rehearsed interview answers, candidates can sound more impressive than ever before. This creates what I call the AI polish effect. It blurs the boundary between genuine capability and AI-assisted presentation.</p>



<p>I have met candidates who articulate AI concepts eloquently yet struggle when asked to break down an unfamiliar problem independently. Because of this, the way I evaluate talent has evolved. I listen less for confidence and more for thinking patterns. I look for willingness to take things apart to understand them, comfort in admitting what they do not know, the ability to reason through new situations and initiative in exploring emerging tools.</p>



<p>This aligns strongly with insights from <a href="https://www.bcg.com/publications/2025/ai-is-outpacing-your-workforce-strategy-are-you-ready?utm_source=chatgpt.com">BCG’s “AI Is Outpacing Your Workforce Strategy”</a>, which highlights that adaptive learning and experimentation are becoming key differentiators among high-performing talent. BCG’s broader perspective in “AI Is Changing Recruitment” reinforces the growing mismatch between traditional hiring practices and the realities of AI-powered organizations.</p>



<h2 class="wp-block-heading">A revealing insight: Many professionals still misunderstand AI</h2>



<p>Another theme that shows up consistently is how often candidates underestimate the influence AI will have on their roles. Many still view AI as an optional enhancement rather than a core part of future workflows.</p>



<p><a href="https://www.gallup.com/workplace/694682/manager-support-drives-employee-adoption.aspx?utm_source=chatgpt.com">Gallup’s “Manager Support Drives Employee Adoption”</a> illustrates this gap clearly, showing that many employees who do not use AI believe it simply would not help their work, while only a small minority cite lack of access as the real barrier. Discomfort with change and uncertainty about how to use AI safely remain common.</p>



<p>This shows up clearly in interviews. Some candidates imagine AI will sit on the sidelines, while in reality it is reshaping speed, expectations and decision-making across every function. For CIOs and technology leaders, this insight matters. Hiring now involves evaluating not just technical fluency, but a candidate’s awareness of how AI will shape their daily work and their willingness to grow with it.</p>



<h2 class="wp-block-heading">Why interview coherence matters more than ever</h2>



<p>As roles evolve, alignment among interviewers has become essential. When one interviewer expects deep AI expertise and another values learning potential, feedback becomes misaligned and promising talent can slip through the cracks. A shared hiring philosophy is no longer a nice-to-have. It is becoming a significant competitive advantage.</p>



<h2 class="wp-block-heading">Evolving expectations: What strong candidates want today</h2>



<p>Across roles, high-performing candidates increasingly look for autonomy, clarity, speed and meaningful work. They want to contribute to something that matters and see results quickly.</p>



<p>Culture also plays a major role. Skilled talent hesitates when an organization feels rigid or unclear. Many candidates now ask more about decision-making, ways of working and team dynamics than they do about day-to-day tasks. They want to understand how work gets done, not just what the job description says.</p>



<p>This is consistent with <a href="https://www.deloitte.com/us/en/insights/topics/talent/ai-in-the-workplace.html">Deloitte’s insights on AI’s impact on careers</a>, which emphasize the growing importance of helping workers continually reinvent themselves to keep pace with technological change.</p>



<h2 class="wp-block-heading">What CIOs can do next</h2>



<p>As AI shifts the definition of talent readiness, CIOs are uniquely positioned to reshape hiring strategy. Three actions stand out:</p>



<h3 class="wp-block-heading">1. Redefine what “qualified” means</h3>



<p>Instead of filtering for exact tool proficiency, evaluate candidates on reasoning, adaptability and their ability to learn at the pace AI evolves. The most future-ready hires are often those who lean into ambiguity rather than avoid it.</p>



<h3 class="wp-block-heading">2. Build interview teams that reflect the skills you want to hire</h3>



<p>Ensure that interviewers understand the organization’s AI maturity level and the differentiators that matter most. When interview panels are aligned, candidates receive clearer signals and hiring decisions become more consistent.</p>



<h3 class="wp-block-heading">3. Treat AI literacy as a cultural expectation, not a niche capability</h3>



<p>Hiring candidates who acknowledge AI’s inevitability and who are willing to expand their workflows with it accelerates organizational readiness and reduces friction during transformation.</p>



<p>These actions help CIOs avoid the misalignment that slows down hiring and creates onboarding challenges later.</p>



<h2 class="wp-block-heading"><a></a>Looking ahead: Hiring for adaptability, not perfection</h2>



<p>AI is evolving so quickly that nobody can be fully prepared for every tool or workflow. This makes adaptability one of the most valuable traits to evaluate. The candidates who stand out are the ones who say, “I haven’t done this yet, but I can figure it out.”</p>



<p>Ambiguity is now part of most modern job descriptions. Some people thrive in it. Others find it destabilizing. Identifying this early helps build teams that are naturally suited to AI-driven environments. Hiring well in this era means prioritizing adaptability, curiosity, experimentation, cultural clarity and coherent evaluation. Problem-solving now matters more than polish. Learning speed matters more than perfect experience.</p>



<h2 class="wp-block-heading">Evolving how we hire</h2>



<p>Hiring in the age of AI is more complex, not because talent is lacking, but because what organizations need has fundamentally changed. The professionals who succeed today are curious, adaptable and comfortable navigating ambiguity. They value culture, clarity and purpose. They flourish under leaders who understand the pace at which technology is reshaping work.</p>



<p>Adaptability is now as important as skill. Curiosity is just as valuable as capability.</p>



<p>If we want to build teams ready for the future, we must evolve how we hire in the present.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Citigroup Mandates AI Training For 175,000 Employees To Help Them 'Reinvent Themselves']]></title>
<description><![CDATA[Citigroup has rolled out mandatory AI training for all 175,000 of its employees across 80 locations worldwide, a sweeping initiative that CEO Jane Fraser describes as helping workers "reinvent themselves" before the technology permanently alters what they do for a living. 

The $205 billion bank ...]]></description>
<link>https://tsecurity.de/de/3238100/it-security-nachrichten/citigroup-mandates-ai-training-for-175000-employees-to-help-them-reinvent-themselves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3238100/it-security-nachrichten/citigroup-mandates-ai-training-for-175000-employees-to-help-them-reinvent-themselves/</guid>
<pubDate>Tue, 27 Jan 2026 22:35:04 +0100</pubDate>
<content:encoded><![CDATA[Citigroup has rolled out mandatory AI training for all 175,000 of its employees across 80 locations worldwide, a sweeping initiative that CEO Jane Fraser describes as helping workers "reinvent themselves" before the technology permanently alters what they do for a living. 

The $205 billion bank sent out an internal memo last year requiring staffers to learn prompting skills specifically. Fraser told the Washington Post at Davos that AI "will change the nature of what people do every day" and "will take some jobs away." The adaptive training platform lets experts complete the course in under 10 minutes while beginners need about 30 minutes. Citi reported last year that employees had entered more than 6.5 million prompts into its built-in AI tools, and Q4 2025 data shows a 70% adoption rate for the bank's proprietary AI tools.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Citigroup+Mandates+AI+Training+For+175%2C000+Employees+To+Help+Them+'Reinvent+Themselves'%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F01%2F27%2F1825244%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F01%2F27%2F1825244%2Fcitigroup-mandates-ai-training-for-175000-employees-to-help-them-reinvent-themselves%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/01/27/1825244/citigroup-mandates-ai-training-for-175000-employees-to-help-them-reinvent-themselves?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ERP in 2026: More AI, more best-of-breed add-ons]]></title>
<description><![CDATA[Enterprise resource planning (ERP) systems are poised for major disruption in 2026, with AI taking over some capabilities and modular, best-of-breed apps replacing some functionality in all-in-one ERP solutions, IT leaders and industry observers say.



The biggest impact will be AI, with more fu...]]></description>
<link>https://tsecurity.de/de/3234320/it-security-nachrichten/erp-in-2026-more-ai-more-best-of-breed-add-ons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3234320/it-security-nachrichten/erp-in-2026-more-ai-more-best-of-breed-add-ons/</guid>
<pubDate>Mon, 26 Jan 2026 10:35:43 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.cio.com/article/272362/what-is-erp-key-features-of-top-enterprise-resource-planning-systems.html">Enterprise resource planning (ERP) systems</a> are poised for major disruption in 2026, with AI taking over some capabilities and modular, best-of-breed apps replacing some functionality in all-in-one ERP solutions, IT leaders and industry observers say.</p>



<p>The biggest impact will be AI, with more functionality within ERP systems becoming automated and less dependent on human interaction. Some experts see <a href="https://www.cio.com/article/4033751/what-parts-of-erp-will-be-left-after-ai-takes-over.html?utm=hybrid_search">AI increasingly taking over</a> several ERP functions, including invoicing, employee onboarding, and balancing books, as well as ERP systems using AI to drive better data insights.</p>



<p>“The ERP market in general is shifting from being a purely transactional system to an intelligent, data-driven platform,” says <a href="https://newsroom.southernglazers.com/press-releases/press-release-details/2025/Southern-Glazers-Wine--Spirits-Names-Steve-Bronson-as-Chief-Information-Officer/default.aspx" rel="nofollow">Steve Bronson</a>, CIO at beverage distributor Southern Glazer’s Wine &amp; Spirits. “We’re seeing AI and predictive analytics embedded into core processes, tighter integration with data lakes for real-time insights, and a strong push toward flexible and modular architectures that allow businesses to adapt quickly without full-scale replacements as in the past.”</p>



<p>AI will increasingly become an intelligence layer in ERP systems, Bronson adds, with <a href="https://www.cio.com/article/3833003/startup-opkey-launches-agentic-ai-platform-for-erp-lifecycle-optimization.html?utm=hybrid_search">agentic AI</a> allowing more automation of workflows in finance, procurement, and supply chain management. AI will also allow users to plan for scenarios using risk profiles in real-time, he predicts.</p>



<p>“AI will shift from transactional systems of record to autonomous, insight-driven engines, which will propose levers for optimization to business leaders that will empower them to make faster, smarter decisions in more real-time,” he adds.</p>



<h2 class="wp-block-heading">Deep AI integration</h2>



<p>The coming year will see deep integration of AI into core ERP systems, adds <a href="https://isg-one.com/about-us/people/kirk-teal" rel="nofollow">Kirk Teal</a>, a partner at IT analyst firm Information Services Group. “Embedded AI and machine learning are moving beyond analytics to actively automate routine processes, detect anomalies in real-time, forecast outcomes, and increasingly recommend — or even execute — decisions within defined guardrails,” he says.</p>



<p>AI agents will stop being a novelty within ERP systems in 2026, adds <a href="https://www.linkedin.com/in/lassekalkar/" rel="nofollow">Lasse Kalkar</a>, CEO and co-founder of AI-powered accounting software provider LiveFlow. At the same time, finance teams are skeptical of AI and will demand human-in-the-loop workflows, he adds.</p>



<p>“Finance and accounting teams are done with manual data entry, reconciliations, invoice processing, and transactional busywork,” he says.  “The shift we’re now seeing is from finance teams doing everything themselves to delegating repetitive work to AI agents and acting as the final reviewers and decision-makers.”</p>



<h2 class="wp-block-heading">More modular systems</h2>



<p>While many experts see an AI takeover of ERP systems, there’s some disagreement about the potential for ERP users to embrace modular, best-of-breed apps to squeeze out parts of standalone, all-in-one solutions.</p>



<p>Some observers see a move away from monolithic ERP solutions that cover financial management, supply chain management, human resources management, customer relationship management, business intelligence, and myriad other functions, and toward modular apps that may work better for specific functionality.</p>



<p>Other IT leaders believe all-in-one ERP systems will remain popular because of the relative ease of purchasing and deploying them.</p>



<p>While there’s still a market for all-in-one ERP solutions, AI has made it easier for organizations to build their own ERP-related apps, says <a href="https://www.linkedin.com/in/senandy" rel="nofollow">Andy Sen</a>, CIO and CTO at B2B software marketplace provider AppDirect. He sees a trend toward using AI-assisted <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html?utm=hybrid_search">vibe coding</a> to quickly build ERP apps that meet specific needs.</p>



<p>AppDirect has built several ERP apps itself, he says. “We are not planning to replace any of our ERPs, but we already have successful in-house implementations of some functions that used to be either done by an ERP or were modules that ERP vendors were advertising,” he adds.</p>



<p>While Sen doesn’t expect an end to all-in-one ERP solutions, he does believe vendors need to rethink their pricing models.</p>



<p>“There are going to be more and more companies that just don’t require a monolithic ERP with thousands of functions, 90% of which my company will never use,” he says. “If that’s the way they want to build software, great, but you just can’t price software that way.”</p>



<p>ERP users seem to be moving toward hybrid ecosystems, with core ERP platforms paired with integrated, best-in-class solutions for specialized compliance needs, adds <a href="https://www.linkedin.com/in/christopherzangrilli/" rel="nofollow">Chris Zangrilli</a>, vice president of technology strategy at tax technology company Vertex. ERP vendors are responding by emphasizing ecosystem interoperability and partnerships, he adds.</p>



<p>“The ERPs will provide the foundation for these solutions to connect into and user experiences that help to blend the flow of work,” he says. “This approach provides the ability for innovation to be delivered faster to customers and provide deep expertise in their solutions, especially those backed by specialized data feeds.”</p>



<h2 class="wp-block-heading">The convenience of all-in-one</h2>



<p>But ISG’s Teal sees all-in-one ERP platforms to remain the primary choice for most organizations, due to the value of vendor-maintained, end-to-end integration across core functions.</p>



<p>“That said, organizations with specialized or differentiating requirements will continue to complement core ERP with best-of-breed solutions, particularly where functionality needs exceed core ERP capabilities,” he adds.</p>



<p>Southern Glazer’s Bronson also sees room for both all-in-one solutions and specialized modular add-ons. All-in-one systems will appeal to smaller organizations, while flexibility and speed matter most at scale, he says.</p>



<p>The momentum at large retailers and direct-to-consumer companies is shifting toward modular, best-of-breed solutions, and his organization values the ability to add tools on top of a core ERP system.</p>



<p>“A flexible ecosystem surrounding a core ERP lets us integrate specialized capabilities and customize close to our customers without having to reinvent standard ERP processes,” he says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nova Launcher Gets a New Owner and Ads]]></title>
<description><![CDATA[Nova Launcher has been acquired by Instabridge, which says it will keep the app maintained but is evaluating ad-supported options for the free version. Android Authority reports: Today, Nova Launcher announced that the Swedish company Instabridge has acquired it from Branch Metrics. Instabridge c...]]></description>
<link>https://tsecurity.de/de/3226923/it-security-nachrichten/nova-launcher-gets-a-new-owner-and-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3226923/it-security-nachrichten/nova-launcher-gets-a-new-owner-and-ads/</guid>
<pubDate>Wed, 21 Jan 2026 23:50:18 +0100</pubDate>
<content:encoded><![CDATA[Nova Launcher has been acquired by Instabridge, which says it will keep the app maintained but is evaluating ad-supported options for the free version. Android Authority reports: Today, Nova Launcher announced that the Swedish company Instabridge has acquired it from Branch Metrics. Instabridge claims it wants to be a responsible owner of Nova and does not want to reinvent the launcher overnight. However, the launcher still needs a sustainable business model to support ongoing development and maintenance. To this end, Instabridge is exploring different options, including paid tiers and ad-supported options for the free version. The new owners claim that if ads are introduced, Nova Prime will remain ad-free. However, this is misleading, as ads are already here for some users. Last year, the founder and original programmer of Nova Launcher left the company, signaling its "death" as he had been the sole developer working on the launcher for the past year.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Nova+Launcher+Gets+a+New+Owner+and+Ads%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F01%2F21%2F2055248%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F01%2F21%2F2055248%2Fnova-launcher-gets-a-new-owner-and-ads%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/01/21/2055248/nova-launcher-gets-a-new-owner-and-ads?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple may reinvent Siri as a conversational AI in iOS 27]]></title>
<description><![CDATA[Forget the old, nearly useless Siri — Apple will reportedly upgrade the iPhone’s voice assistant into an AI-powered chatbot with iOS 27. Users will supposedly be able to converse with the new Siri, not just give it orders. If true, this will let Apple compete directly against Android and Windows ...]]></description>
<link>https://tsecurity.de/de/3226856/ios-mac-os/apple-may-reinvent-siri-as-a-conversational-ai-in-ios-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3226856/ios-mac-os/apple-may-reinvent-siri-as-a-conversational-ai-in-ios-27/</guid>
<pubDate>Wed, 21 Jan 2026 22:21:30 +0100</pubDate>
<content:encoded><![CDATA[<div><img width="780" height="439" src="https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot.jpg.webp" class="attachment-large size-large wp-post-image" alt="Apple may reinvent Siri as a conversational AI in iOS 27" decoding="async" fetchpriority="high" srcset="https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot.jpg.webp 1365w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-400x225.jpg 400w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-350x197.jpg 350w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-768x432.jpg.webp 768w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-1020x574.jpg.webp 1020w, https://www.cultofmac.com/wp-content/uploads/2026/01/Apple-Siri-AI-chatbot-400x225@2x.jpg 800w" sizes="(max-width: 780px) 100vw, 780px"></div>
<p>Forget the old, nearly useless Siri — Apple will reportedly upgrade the iPhone’s voice assistant into an AI-powered chatbot with iOS 27. Users will supposedly be able to converse with the new Siri, not just give it orders. If true, this will let Apple compete directly against Android and Windows computers with built-in AI chatbots. […]</p>
<p>(via <a href="https://www.cultofmac.com/">Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise AI investments are forging ahead despite elusive ROI]]></title>
<description><![CDATA[The question many enterprises are asking themselves in 2026 is whether they are transforming their businesses fast enough to see the benefits of new technologies, most notably AI.



The answer, according to PwC’s 29th Global CEO Survey: Not really — at least, not yet.



In fact, the majority of...]]></description>
<link>https://tsecurity.de/de/3224907/it-security-nachrichten/enterprise-ai-investments-are-forging-ahead-despite-elusive-roi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3224907/it-security-nachrichten/enterprise-ai-investments-are-forging-ahead-despite-elusive-roi/</guid>
<pubDate>Wed, 21 Jan 2026 07:35:32 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The question many enterprises are asking themselves in 2026 is whether they are transforming their businesses fast enough to see the benefits of new technologies, most notably AI.</p>



<p>The answer, according to PwC’s 29th Global CEO Survey: Not really — at least, not yet.</p>



<p>In fact, the majority of enterprises aren’t seeing any real revenue increase or cost reduction as the result of AI deployments; only about one-third have seen any tangible benefits from AI in the last 12 months.</p>



<p>“CEOs are forging ahead with investment in AI even though immediate returns are often elusive,” PwC said in its report based on <a href="https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html" target="_blank" rel="nofollow">a survey</a> of 4,450 CEOs across 95 countries and territories.</p>



<h2 class="wp-block-heading">CEOs eager, but approaching AI tentatively</h2>



<p>AI is advancing at an unparalleled pace, causing “excitement and anxiety in equal measure,” PwC noted. </p>



<p>The majority (69%) of CEOs surveyed agreed or strongly agreed that their organizational culture and technical environment enable AI adoption, and 51% agreed or strongly agreed that they had a clearly-defined <a href="https://www.cio.com/article/4116514/agentic-ai-poised-for-progress-in-2026-if-cios-get-it-right.html" target="_blank">roadmap for AI initiatives</a>. However, “there is a gap emerging between leadership, aspiration, and execution,” PwC’s global chairman, <a href="https://www.pwc.com/gx/en/contacts/m/mohamed-kande.html" target="_blank" rel="nofollow">Mohamed Kande</a>, observed in a video accompanying the survey.</p>



<p>Some examples:</p>



<ul class="wp-block-list">
<li>More than half (56%) of CEOs have not realized either revenue or cost benefits from AI. Roughly one-third (30%) have measured tangible revenue increases, and just one-quarter (26%) are seeing lower costs thanks to AI;</li>



<li>Only 40% say their level of investment is sufficient to meet their AI goals;</li>



<li>Just over half have formal responsible AI and risk processes;</li>



<li>Only about 30% grant their main AI tool access to all their documents and data;</li>



<li>Just 42% believe they have the ability to attract high-quality technical AI talent;</li>
</ul>



<p>PwC identified just one in eight companies as being in the “vanguard,” meaning they are achieving both additional revenues and lower costs as they apply AI extensively across their business. A “relatively small portion” of CEOs are applying AI to a significant extent to demand generation (22%); support services (20%); products, services, and experiences (19%); direction-setting (15%); or demand fulfilment (13%).</p>



<h2 class="wp-block-heading">Guard against ‘innovation theater’</h2>



<p>“Isolated, tactical AI projects often <a href="https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf" target="_blank" rel="nofollow">don’t deliver measurable value</a>,” PwC noted. Measurable returns come from enterprise-scale deployment consistent with corporate strategy, and CEOs need to guard against what’s known as “innovation theater:” activities that “resemble innovation but produce no tangible value.”</p>



<p>To gauge innovation maturity, PwC asked CEOs about six “innovation-friendly practices.”</p>



<p>Do they:</p>



<ul class="wp-block-list">
<li>View innovation as a critical component of their overall business strategy?</li>



<li>Collaborate with external partners to accelerate innovation?</li>



<li>Test new ideas rapidly with customers or end-users?</li>



<li>Tolerate high risk in innovation projects?</li>



<li>Have routine processes to stop underperforming R&amp;D projects?</li>



<li>Have a defined innovation center, incubator, or corporate venturing division</li>
</ul>



<p>Alarmingly, less than one in ten (8%) said their company had adopted at least five of those six practices to a large or very large extent.</p>



<p>“If innovation is part of your strategy, put real structure behind it, from how you test new ideas to how you scale what works,” said Kande. “Don’t do it alone: Partnerships and new forms of collaboration can speed up what you are able to bring to market.”</p>



<h2 class="wp-block-heading">Issues with trust, concerns around cybersecurity</h2>



<p>Trust is a cornerstone of business, but it can be increasingly difficult to come by due to a multitude of factors. Two-thirds (66%) of CEOs surveyed by PwC dealt with trust concerns in the last year around topics such as data use and privacy (38%), transparency (38%), and responsible AI and AI safety (37%).</p>



<p>At the same time, CEOs have become increasingly concerned about a range of near-term threats, notably technology disruption and cyber risk. About one third (31%) see their company as highly or extremely exposed to significant financial loss from <a href="https://www.csoonline.com/article/4116992/7-top-cybersecurity-projects-for-2026.html" target="_blank">cybersecurity threats</a>. This is up 10% from just two years ago. As a result, about eight in 10 say they plan to improve their enterprise’s cybersecurity practices.</p>



<p>“Trust isn’t an intangible soft topic,” PwC emphasized. “Value is at stake.” Therefore, it should be prioritized as a boardroom topic and built and preserved through investments in data, processes, and controls.</p>



<h2 class="wp-block-heading">CEOs need to rethink their calendars</h2>



<p>There’s no doubt that CEOs have a lot to think about, and they must <a href="https://www.cio.com/article/4117023/10-top-priorities-for-cios-in-2026.html" target="_blank">divide their time</a> between short, medium, and long-term issues. But, according to PwC, they may not be using their time all that wisely.</p>



<p>CEOs surveyed said they spend almost half (47%) of their time on issues with horizons of less than a year. They then focus about a third of their time on activities with one to less than five year horizons, and just 16% on those with longer-term horizons of five years or more.</p>



<p>“Are they striking the right balance? It’s a question CEOs should ask themselves as they strive to build organizations to thrive both today and tomorrow,” PwC advised.</p>



<p>Dovetailing with this, just 30% of CEOs are confident about their company’s revenue growth over the next 12 months. That’s down from 38% last year and almost half of the peak of 56% in 2022.</p>



<p>Many leaders struggle with what PwC calls “the tyranny of the urgent,” leading them to spend too much time looking through a microscope, rather than through a telescope centered on <a href="https://www.cio.com/article/4114004/7-challenges-it-leaders-will-face-in-2026.html" target="_blank">long-term business goals</a>.</p>



<p>It’s impossible to generalize how <a href="https://www.cio.com/article/4117078/digital-transformation-2026-whats-in-whats-out.html" target="_blank">CEOs should focus their time</a>, PwC conceded, and crisis situations are inevitable. But leaders are counterintuitively focusing on short-term activities even as they clearly identify that mid- to long-term enterprise viability is one of their most pressing issues.</p>



<p>“If these leaders are serious about reinvention, they may need to reinvent how they invest their time,” PwC noted. “The challenge facing CEOs at this critical moment is to decide, in conjunction with their top team and board, how the company’s value-creation recipe needs to change for the decade of innovation and industry reconfiguration ahead.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 top priorities for CIOs in 2026]]></title>
<description><![CDATA[A CIO’s wish list is typically long and costly. Fortunately, by establishing reasonable priorities, it’s possible to keep pace with emerging demands without draining your team or budget.



As 2026 arrives, CIOs need to take a step back and consider how they can use technology to help reinvent th...]]></description>
<link>https://tsecurity.de/de/3221049/it-security-nachrichten/10-top-priorities-for-cios-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3221049/it-security-nachrichten/10-top-priorities-for-cios-in-2026/</guid>
<pubDate>Mon, 19 Jan 2026 11:20:17 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A CIO’s wish list is typically long and costly. Fortunately, by establishing reasonable priorities, it’s possible to keep pace with emerging demands without draining your team or budget.</p>



<p>As 2026 arrives, CIOs need to take a step back and consider how they can use technology to help reinvent their wider business while running their IT capabilities with a profit and loss mindset, advises <a href="https://www.linkedin.com/in/koenraad-schelfaut/?originalSubdomain=be" rel="nofollow">Koenraad Schelfaut</a>, technology strategy and advisory global lead at business advisory firm Accenture. “The focus should shift from ‘keeping the lights on’ at the lowest cost to using technology … to drive topline growth, create new digital products, and bring new business models faster to market.”</p>



<p>Here’s an overview of what should be at the top of your 2026 priorities list.</p>



<h2 class="wp-block-heading">1. Strengthening cybersecurity resilience and data privacy</h2>



<p>Enterprises are increasingly integrating generative and agentic AI deep into their business workflows, spanning all critical customer interactions and transactions, says <a href="https://www.linkedin.com/in/yogeshaj/" rel="nofollow">Yogesh Joshi</a>, senior vice president of global product platforms at consumer credit reporting firm TransUnion. “As a result, CIOs and CISOs must expect bad actors will use these same AI technologies to disrupt these workflows to compromise intellectual property, including customer sensitive data and competitively differentiated information and assets.”</p>



<p>Cybersecurity resilience and data privacy must be top priorities in 2026, Joshi says. He believes that as enterprises accelerate their digital transformation and increasingly integrate AI, <a href="https://www.csoonline.com/article/3988355/8-security-risks-overlooked-in-the-rush-to-implement-ai.html">the risk landscape will expand dramatically</a>. “Protecting sensitive data and ensuring compliance with global regulations is non-negotiable,” Joshi states.</p>



<h2 class="wp-block-heading">2. Consolidating security tools</h2>



<p>CIOs should prioritize re-baselining their foundations to capitalize on the promise of AI, says <a href="https://www.deloitte.com/us/en/about/people/profiles.aperinkolam+c41e2fb8.html" rel="nofollow">Arun Perinkolam</a>, Deloitte’s US cyber platforms and technology, media, and telecommunications industry leader. “One of the prerequisites is consolidating fragmented security tools into unified, integrated, cyber technology platforms — also known as platformization.”</p>



<p>Perinkolam says <a href="https://www.csoonline.com/article/2515727/6-tips-for-consolidating-your-it-security-tool-set.html">a consolidation shift</a> will move security from a patchwork of isolated solutions to an agile, extensible foundation fit for rapid innovation and scalable AI-driven operations. “As cyber threats become increasingly sophisticated, and the technology landscape evolves, integrating cybersecurity solutions into unified platforms will be crucial,” he says.</p>



<p>“Enterprises now face a growing array of threats, resulting in a sprawling set of tools to manage them,” Perinkolam notes. “As adversaries exploit fractured security postures, delaying platformization only amplifies these risks.”</p>



<h2 class="wp-block-heading">3. Ensuring data protection</h2>



<p>To take advantage of enhanced efficiency, speed, and innovation, organizations of all types and sizes are now racing to adopt new AI models, says <a href="https://www.linkedin.com/in/ppearson/" rel="nofollow">Parker Pearson</a>, chief strategy officer at data privacy and preservation firm Donoma Software.</p>



<p>“Unfortunately, many organizations are failing to take the basic steps necessary to protect their sensitive data before unleashing new AI technologies that could potentially be left exposed,” she warns, adding that in 2026 “data privacy should be viewed as an urgent priority.”</p>



<p>Implementing new AI models can raise <a href="https://www.csoonline.com/article/4049373/how-the-generative-ai-boom-opens-up-new-privacy-and-cybersecurity-risks.html">significant concerns around how data is collected, used, and protected</a>, Pearson notes. These issues arise across the entire AI lifecycle, from how the data used for initial training to ongoing interactions with the model. “Until now, the choices for most enterprises are between two bad options: either ignore AI and face the consequences in an increasingly competitive marketplace; or implement an LLM that could potentially expose sensitive data,” she says. Both options, she adds, can result in an enormous amount of damage.</p>



<p>The question for CIOs is not whether to implement AI, but how to derive optimal value from AI without placing sensitive data at risk, Pearson says. “Many CIOs confidently report that their organization’s data is either ‘fully’ or ‘end to end’ encrypted.” Yet Pearson believes that true data protection requires continuous encryption that keeps information secure during all states, including when it’s being used. “Until organizations address this fundamental gap, they will continue to be blindsided by breaches that bypass all their traditional security measures.”</p>



<p>Organizations that implement privacy-enhancing technology today will have a distinct advantage in implementing future AI models, Pearson says. “Their data will be structured and secured correctly, and their AI training will be more efficient right from the start, rather than continually incurring the expense, and risk of retraining their models.”</p>



<h2 class="wp-block-heading">4. Focusing on team identity and experience</h2>



<p>A top priority for CIOs in 2026 should be resetting their enterprise identity and employee experience, says <a href="https://www.linkedin.com/in/technologistmichaelwetzel/" rel="nofollow">Michael Wetzel</a>, CIO at IT security software company Netwrix. “Identity is the foundation of how people show up, collaborate, and contribute,” he states. “When you get identity and experience right, everything else, including security, productivity, and adoption, follows naturally.”</p>



<p>Employees expect a consumer-grade experience at work, Wetzel says. “If your internal technology is clunky, they simply won’t use it.” When people work around IT, the organization loses both security and speed, he warns. “Enterprises that build a seamless, identity-rooted experience will innovate faster while organizations that don’t will fall behind.”</p>



<h2 class="wp-block-heading">5. Navigating increasingly costly ERP migrations</h2>



<p>Effectively navigating costly ERP migrations should be at the top of the CIO agenda in 2026, says <a href="https://www.linkedin.com/in/barrettschiwitz/" rel="nofollow">Barrett Schiwitz</a>, CIO at invoice lifecycle management software firm Basware. “SAP S/4HANA migrations, for instance, <a href="https://www.cio.com/article/3851772/sap-users-struggle-with-s4-hana-migration.html">are complex and often take longer than planned</a>, leading to rising costs.” He notes that upgrades can cost enterprises upwards of $100 million, rising to as much as $500 million depending on the ERP’s size and complexity.</p>



<p>The problem is that while ERPs try to do everything, they rarely perform specific tasks, such as invoice processing, really well, Schiwitz says. “Many businesses overcomplicate their ERP systems, customizing them with lots of add-ons that further increase risk.” The answer, he suggests, is adopting a “clean core” strategy that lets SAP do what it does best and then supplement it with best-in-class tools to drive additional value.</p>



<h2 class="wp-block-heading">6. Doubling-down on innovation — and data governance</h2>



<p>One of the most important priorities for CIOs in 2026 is architecting a foundation that makes innovation scalable, sustainable, and secure, says <a href="https://www.linkedin.com/in/stephenfranchetti/" rel="nofollow">Stephen Franchetti</a>, CIO at compliance platform provider Samsara.</p>



<p>Franchetti says he’s currently building a loosely coupled, <a href="https://www.cio.com/article/656514/3-commandments-that-should-drive-every-api-strategy.html">API-first architecture</a> that’s designed to be modular, composable, and extensible. “This allows us to move faster, adapt to change more easily, and avoid vendor or platform lock-in.” Franchetti adds that in an era where workflows, tools, and even AI agents are increasingly dynamic, a tightly bound stack simply won’t scale.</p>



<p>Franchetti is also continuing to evolve his enterprise data strategy. “For us, data is a long-term strategic asset — not just for AI, but also for business insight, regulatory readiness, and customer trust,” he says. “This means doubling down on data quality, lineage, governance, and accessibility across all functions.”</p>



<h2 class="wp-block-heading">7. Facilitating workforce transformation</h2>



<p>CIOs must prioritize workforce transformation in 2026, says <a href="https://www.linkedin.com/in/scott-thompson-56b34618/" rel="nofollow">Scott Thompson</a>, a partner in executive search and management consulting company Heidrick &amp; Struggles. “Upskilling and reskilling teams will help develop the next generation of leaders,” he predicts. “The technology leader of 2026 needs to be a product-centric tech leader, ensuring that product, technology, and the business are all one and the same.”</p>



<p>CIOs can’t hire their way out of the talent gap, so <a href="https://www.cio.com/article/652678/the-great-retraining-it-upskills-for-the-future.html">they must build talent internally</a>, not simply buy it on the market, Thompson says. “The most effective strategy is creating a digital talent factory with structured skills taxonomies, role-based learning paths, and hands-on project rotations.”</p>



<p>Thompson also believes that CIOs should redesign job roles for an AI-enabled environment and use automation to reduce the amount of specialized labor required. “Forming fusion teams will help spread scarce expertise across the organization, while strong career mobility and a modern engineering culture will improve retention,” he states. “Together, these approaches will let CIOs grow, multiply, and retain the talent they need at scale.”</p>



<h2 class="wp-block-heading">8. Improving team communication</h2>



<p>A CIO’s top priority should be developing sophisticated and nuanced approaches to communication, says <a href="https://www.linkedin.com/in/jamesstanger/" rel="nofollow">James Stanger</a>, chief technology evangelist at IT certification firm CompTIA. “The primary effect of uncertainty in tech departments is anxiety,” he observes. “Anxiety takes different forms, depending upon the individual worker.”</p>



<p>Stanger suggests working closer with team members as well as managing anxiety through more effective and relevant training.</p>



<h2 class="wp-block-heading">9. Strengthening drive agility, trust, and scale</h2>



<p>Beyond AI, the priority for CIOs in 2026 should be strengthening the enabling capabilities that drive agility, trust, and scale, says <a href="https://www.linkedin.com/in/mianders/" rel="nofollow">Mike Anderson</a>, chief digital and information officer at security firm Netskope.</p>



<p>Anderson feels that the product operating model will be central to this shift, expanding beyond traditional software teams to include foundational enterprise capabilities, such as identity and access management, data platforms, and integration services.</p>



<p>“These capabilities must support both human and non-human identities — employees, partners, customers, third parties, and AI agents — through secure, adaptive frameworks built on least-privileged access and zero trust principles,” he says, noting that CIOs who invest in these enabling capabilities now will be positioned to move faster and innovate more confidently throughout 2026 and beyond.</p>



<h2 class="wp-block-heading">10. Addressing an evolving IT architecture</h2>



<p>In 2026, today’s IT architecture will become a legacy model, unable to support the autonomous power of AI agents, predicts <a href="https://www.linkedin.com/in/emingerba/" rel="nofollow">Emin Gerba</a>, chief architect at Salesforce. He believes that in order to effectively scale, enterprises will have to pivot to a new agentic enterprise blueprint with four new architectural layers: a shared semantic layer to unify data meaning, an integrated AI/ML layer for centralized intelligence, an agentic layer to manage the full lifecycle of a scalable agent workforce, and an enterprise orchestration layer to securely manage complex, cross-silo agent workflows.</p>



<p>“This architectural shift will be the defining competitive wedge, separating companies that achieve end-to-end automation from those whose agents remain trapped in application silos,” Gerba says.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How can we defend ourselves from the new plague of ‘human fracking’?]]></title>
<description><![CDATA[Big tech treats our attention like a resource to be mercilessly extracted. The fightback begins hereIn the last 15 years, a linked series of unprecedented technologies have changed the experience of personhood across most of the world. It is estimated that nearly 70% of the human population of th...]]></description>
<link>https://tsecurity.de/de/3219864/it-nachrichten/how-can-we-defend-ourselves-from-the-new-plague-of-human-fracking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3219864/it-nachrichten/how-can-we-defend-ourselves-from-the-new-plague-of-human-fracking/</guid>
<pubDate>Sun, 18 Jan 2026 13:16:35 +0100</pubDate>
<content:encoded><![CDATA[<p>Big tech treats our attention like a resource to be mercilessly extracted. The fightback begins here</p><p>In the last 15 years, a linked series of unprecedented technologies have changed the experience of personhood across most of the world. It is estimated that<a href="https://www.testmyspeed.com/insights/smartphone-statistics-you-need-to-know#:~:text=In%202025%2C%20it's%20anticipated%20that,expected%20to%20follow%20suit%20soon."> nearly 70% of the human population of the Earth currently possesses a smartphone</a>, and these devices constitute about<a href="https://explodingtopics.com/blog/smartphone-stats"> 95% of internet access-points on the planet.</a> Globally, on average, people seem to spend close to<a href="https://www.mastermindbehavior.com/post/average-screen-time-statistics"> </a><em><a href="https://www.mastermindbehavior.com/post/average-screen-time-statistics">half their waking hours</a></em> looking at screens, and among young people in the rich world the number is a good deal higher than that.</p><p>History teaches that new technologies always make possible new forms of exploitation, and this basic fact has been spectacularly exemplified by the rise of society-scale digital platforms. It has been driven by a remarkable new way of extracting money from human beings: call it “human fracking”. Just as petroleum frackers pump high-pressure, high-volume detergents into the ground to force a little monetisable black gold to the surface, human frackers pump high-pressure, high-volume detergent into our faces (in the form of endless streams of addictive slop and maximally disruptive user-generated content), to force a slurry of human attention to the surface, where they can collect it, and take it to market.</p> <a href="https://www.theguardian.com/books/2026/jan/18/how-can-we-defend-ourselves-from-the-new-plague-of-human-fracking">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Virgin River Season 7: Release Window, Season 8 Plans, and What’s Ahead]]></title>
<description><![CDATA[Season 7 of Virgin River is officially locked in, and this time there’s no guessing involved. Netflix has confirmed both the release date and where the story picks up. If you’ve been waiting to see what married life looks like for Mel and Jack, the countdown is on.



Table of contentsVirgin Rive...]]></description>
<link>https://tsecurity.de/de/3212537/ios-mac-os/virgin-river-season-7-release-window-season-8-plans-and-whats-ahead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3212537/ios-mac-os/virgin-river-season-7-release-window-season-8-plans-and-whats-ahead/</guid>
<pubDate>Wed, 14 Jan 2026 13:21:03 +0100</pubDate>
<content:encoded><![CDATA[Season 7 of Virgin River is officially locked in, and this time there’s no guessing involved. Netflix has confirmed both the release date and where the story picks up. If you’ve been waiting to see what married life looks like for Mel and Jack, the countdown is on.



Table of contentsVirgin River Season 7 Release DateWhere Season 7 Picks UpMarried Life Won’t Be QuietParenthood and the Adoption StorylineVirgin River Is Returning for Season 8Why the Show Keeps Working



Virgin River Season 7 Release Date



Netflix has confirmed that Virgin River Season 7 will premiere on March 12, 2026.



The season arrives in spring, continuing the show’s steady release pattern and keeping its long-running momentum intact. A first-look photo already shows Mel and Jack in their newlywed glow, setting the tone for what comes next.



For something completely different in tone, Euphoria is inching closer to its long-awaited return, with its release timeline finally starting to take shape.



Where Season 7 Picks Up



Season 7 begins immediately after the Season 6 finale, which ended with Mel and Jack finally getting married. After years of buildup, viewers got not one but two weddings. A private commitment by the river, followed by a full ceremony surrounded by friends and family.



Now comes the part that the show has been working toward all along. Life after the vows.



Married Life Won’t Be Quiet



According to showrunner Patrick Sean Smith, Season 7 will explore the honeymoon phase of Mel and Jack’s relationship. That includes building a life together on the farm, adjusting expectations, and dealing with the small but meaningful frictions that come with marriage.



Mel thought she was getting a cozy cabin. Instead, she’s living a full farmhouse life. That contrast matters, because it keeps her slightly off balance, still learning, still growing, and still stepping outside her comfort zone.



Parenthood and the Adoption Storyline



Season 6 ended with a major emotional turn. One of Mel’s pregnant patients considers placing her baby with Mel and Jack after her initial adoption plan falls through.



Season 7 will continue that thread.



After the miscarriage in Season 5 and Mel’s decision to stop trying to conceive, adoption opens a new door. It keeps the couple’s dream of parenthood alive, just in a different form. That shift isn’t treated lightly, and it’s expected to be a central storyline moving forward.



Virgin River Is Returning for Season 8



Netflix has already confirmed that Virgin River will return for Season 8.



That confirmation matters. It means Season 7 isn’t written as an ending or a slowdown. The story is still expanding, with room to explore married life, parenthood, and the wider town dynamics without rushing toward closure.



Why the Show Keeps Working



Here’s the thing. Virgin River doesn’t try to reinvent itself.



It focuses on emotional continuity, familiar faces, and long-term character arcs. Netflix knows exactly what this show delivers, and so does its audience. That consistency is why it keeps getting renewed, and why Season 7 feels like a natural next chapter instead of a reset.



If you’re behind, now’s the time to catch up. Seasons 1 through 6 are streaming on Netflix, and Season 7 lands March 12, 2026.



Mel and Jack are married. Their future is open. And Virgin River isn’t done telling their story yet.



You might also want to keep an eye on other major releases coming up. Silo is gearing up for its next season, with new episodes expected to push deeper into the mystery behind the underground world. And Outlander is approaching a turning point as it heads toward its final chapters, with release plans now coming into focus.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mac Studio with M5 Ultra: release date and what to expect]]></title>
<description><![CDATA[The Mac Studio is quietly becoming Apple’s most important desktop. With the Mac Pro fading into the background, the Studio now carries the weight for people who need serious performance without a full rackmount workstation. That’s why the upcoming M5 Ultra version matters. A lot.



Here’s what w...]]></description>
<link>https://tsecurity.de/de/3209910/ios-mac-os/mac-studio-with-m5-ultra-release-date-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3209910/ios-mac-os/mac-studio-with-m5-ultra-release-date-and-what-to-expect/</guid>
<pubDate>Tue, 13 Jan 2026 12:06:36 +0100</pubDate>
<content:encoded><![CDATA[The Mac Studio is quietly becoming Apple’s most important desktop. With the Mac Pro fading into the background, the Studio now carries the weight for people who need serious performance without a full rackmount workstation. That’s why the upcoming M5 Ultra version matters. A lot.



Here’s what we know so far about when the Mac Studio with M5 Ultra is likely to arrive and what kind of upgrade it’s shaping up to be.



Table of contentsExpected release date: spring to early summer 2026Why the M5 Ultra matters more than usualWhat we expect from the M5 Ultra chipA new chip layoutBig performance gainsStronger AI and memory bandwidthSpecs we expect to stay familiarDesign: no changes comingPricing expectationsWhat this says about Apple’s desktop strategyShould you wait?The bottom line



Expected release date: spring to early summer 2026







The most realistic window for the Mac Studio with M5 Ultra is between March and June 2026.



Here’s why that timing makes sense:




Apple launched the base M5 chip in October 2025



Pro and Max versions typically follow a few months later



Ultra chips always arrive last, once Max silicon is finalized



Past Mac Studio releases landed in March or June




Bloomberg’s Mark Gurman has already said the M5 Max and M5 Ultra Mac Studio are on Apple’s 2026 schedule. A March launch would be typical. A June WWDC launch would not be surprising either, especially if Apple pairs it with new displays.



Why the M5 Ultra matters more than usual







Here’s the thing. The current Mac Studio lineup is a little awkward.



The 2025 model shipped with an M4 Max and an M3 Ultra. That mismatch confused buyers and made it clear Apple skipped an M4 Ultra entirely. The M5 generation is expected to fix that.



Reports suggest the next Mac Studio will use M5 Max and M5 Ultra from the same generation, restoring a clean performance ladder. That alone makes the upgrade more compelling for buyers who skipped the last refresh.



What we expect from the M5 Ultra chip



Apple hasn’t shared official specs, but the direction is clear.



A new chip layout







Multiple reports say Apple is moving to a separate CPU and GPU block design for higher-end M5 chips. That could allow more flexible configurations, like pairing a base CPU with a maxed-out GPU.



For Mac Studio buyers, that’s huge. It means better customization for workloads like 3D, video, and machine learning.



Big performance gains



Ultra chips are essentially two Max chips fused together. With the M5 generation bringing notable GPU and AI gains already, the M5 Ultra should deliver a sizable jump over the M3 Ultra, especially in graphics-heavy tasks.



Stronger AI and memory bandwidth







The M5 architecture improves Neural Engine throughput and memory efficiency. On an Ultra chip, those gains scale fast. This is the kind of silicon aimed squarely at professionals who push systems all day.



Specs we expect to stay familiar



Don’t expect Apple to reinvent the rest of the machine.



Likely starting configurations:




M5 Max with around 36GB unified memory



M5 Ultra with around 96GB unified memory



SSD options up to 8TB or 16TB



Thunderbolt 5 across the board




Ports should remain unchanged, including front USB-C or Thunderbolt, rear Thunderbolt 5, HDMI, USB-A, SD card slot, audio jack, and 10Gb Ethernet.



Design: no changes coming



The Mac Studio design is only a few years old, and Apple appears happy with it. No leaks or reports suggest a redesign.



Expect the same compact aluminum box, same airflow, same footprint. This update is about power, not aesthetics.



Pricing expectations



This part is still fuzzy.



Current pricing starts around $1,999 for the Max model and $3,999 for the Ultra. Apple is unlikely to lower those numbers. If anything, pricing pressure from tariffs or component costs could push prices slightly higher.



Still, Apple tends to keep Mac Studio pricing stable generation to generation.



What this says about Apple’s desktop strategy



Multiple reports suggest Apple now sees the Mac Studio as its flagship desktop. The Mac Pro hasn’t seen meaningful movement, and insiders say Apple believes the Studio covers most professional needs.



If that’s true, the M5 Ultra Mac Studio won’t be a minor update. It’s the machine Apple expects power users to buy.



Should you wait?



If you rely on GPU-heavy workflows or need maximum headroom, waiting makes sense. The M5 Ultra should be a meaningful step up, not a routine bump.



If you need a desktop now, the current Mac Studio is still extremely capable. But it’s also the most awkwardly positioned version Apple has shipped so far.



The bottom line



The Mac Studio with M5 Ultra is expected to arrive in spring or early summer 2026. It should bring a cleaner chip lineup, a stronger Ultra option, and meaningful gains where professionals actually feel them. No redesign. No fluff. Just a much better version of Apple’s most serious desktop.]]></content:encoded>
</item>
<item>
<title><![CDATA[Paint has been part of Windows for decades, yet in 2026 Microsoft faces a choice: reinvent it, retire it, or let it quietly linger]]></title>
<description><![CDATA[Paint is getting a new collapsible toolbar in the latest Insider builds. Is Microsoft finally finding the right balance between "classic" simplicity and modern power?]]></description>
<link>https://tsecurity.de/de/3208976/windows-tipps/paint-has-been-part-of-windows-for-decades-yet-in-2026-microsoft-faces-a-choice-reinvent-it-retire-it-or-let-it-quietly-linger/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3208976/windows-tipps/paint-has-been-part-of-windows-for-decades-yet-in-2026-microsoft-faces-a-choice-reinvent-it-retire-it-or-let-it-quietly-linger/</guid>
<pubDate>Mon, 12 Jan 2026 21:22:54 +0100</pubDate>
<content:encoded><![CDATA[Paint is getting a new collapsible toolbar in the latest Insider builds. Is Microsoft finally finding the right balance between "classic" simplicity and modern power?]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.20 adds the ntsync driver to help improve some game performance]]></title>
<description><![CDATA[Valve have released SteamOS 3.7.20 Beta coming with just two changes, and one of them is very interesting to see arrive on SteamOS..Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3203465/linux-tipps/steamos-3720-adds-the-ntsync-driver-to-help-improve-some-game-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3203465/linux-tipps/steamos-3720-adds-the-ntsync-driver-to-help-improve-some-game-performance/</guid>
<pubDate>Fri, 09 Jan 2026 10:20:27 +0100</pubDate>
<content:encoded><![CDATA[Valve have released SteamOS 3.7.20 Beta coming with just two changes, and one of them is very interesting to see arrive on SteamOS.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt>.</p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/01/steamos-3-7-20-adds-the-ntsync-driver-to-help-improve-some-game-performance/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Foldable iPhone Might Feel More Like a Mini iPad Than a Phone]]></title>
<description><![CDATA[Recent iPhone Fold leaks raise a basic but important question. Will this device feel like an iPhone that unfolds, or an iPad that folds shut? Based on current mockups, Apple seems to be leaning toward the second idea.



Unlike foldables from Samsung and Google, the rumored iPhone Fold does not f...]]></description>
<link>https://tsecurity.de/de/3202928/ios-mac-os/foldable-iphone-might-feel-more-like-a-mini-ipad-than-a-phone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3202928/ios-mac-os/foldable-iphone-might-feel-more-like-a-mini-ipad-than-a-phone/</guid>
<pubDate>Fri, 09 Jan 2026 00:35:02 +0100</pubDate>
<content:encoded><![CDATA[Recent iPhone Fold leaks raise a basic but important question. Will this device feel like an iPhone that unfolds, or an iPad that folds shut? Based on current mockups, Apple seems to be leaning toward the second idea.



Unlike foldables from Samsung and Google, the rumored iPhone Fold does not follow the usual shape. Competing models look like normal phones when closed and stretch taller when opened. The iPhone Fold appears to take a different path. When folded, it looks short and wide. When unfolded, it looks closer to an iPad mini than a phone.



That design choice changes how the device feels before you even turn it on.



A strange shape that starts to make sense



At first glance, the leaked shape looks unusual. Folded up, the device looks squat, almost like a small notebook rather than a tall phone. It does not resemble any iPhone Apple sells today.



But the design starts to make sense once you imagine it opened. The inner display reportedly uses a 4:3 aspect ratio. That is the same shape Apple has used on iPads for years. Unfolded, the screen size reportedly lands just under the iPad mini, making it feel more like a compact tablet than a stretched phone.



Stephen Hackett created 3D-printed mockups based on these leaks, which helped visualize the idea in physical form. Jason Snell later discussed those mockups and framed the core question clearly: “Will the iPhone Fold be a phone you open, or an iPad you close?”



Apple’s risk and Apple’s advantage







Apple takes a real risk if this device does not look like an iPhone. A strange shape can turn people away, especially at a price expected to cross $2,000. Apple likely knows this.



The rumored strategy seems clear. If you want a normal-looking iPhone, Apple already sells several. The iPhone Fold exists for a different reason. It matters less how it looks when closed. It matters much more what it becomes when opened.



When it opens, it becomes an iPad.



That matters because Apple dominates tablets in a way no other company does. Android tablets still struggle with apps that feel stretched and awkward. iPad apps feel designed for larger screens because they are.



This gives Apple a major advantage. A folding phone that opens into an iPad-shaped display plays directly to Apple’s strengths.



iOS on a folded display







The bigger question is software. A wide, nontraditional screen would force Apple to rethink parts of iOS. Interface elements would need to stretch wider. Multitasking would need to feel natural, not forced.



It is unclear how far Apple will go. Will the iPhone Fold support windowed multitasking? Will it allow basic tiling only? Could it support Apple Pencil? Could it drive an external display?



Apple controls all of that.



The idea of carrying something close to an iPad mini in your pocket is exciting. But it also raises doubts. Adapting iOS to such an unusual shape would require serious design work. That alone makes some people skeptical that these mockups reflect the final product.



An iPad you can fold and pocket



Still, the core idea stands out. Based on current mockups, the iPhone Fold does not look like two phones joined together. It looks like a small iPad that happens to fold. That may be the point.



If these leaks prove accurate, Apple is not trying to reinvent the iPhone. It is trying to shrink the iPad just enough to make it portable in a new way. Whether that gamble pays off will depend on how well Apple adapts iOS to this new form.



For now, the leaks suggest one clear direction. The iPhone Fold looks less like a phone you open and more like an iPad you close.]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.19 arrives with a bunch of essential bug fixes]]></title>
<description><![CDATA[Valve have released the latest stable update for SteamOS version 3.7.19, bringing a bunch of bug fixes to improve the Linux gaming platform..Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3199441/linux-tipps/steamos-3719-arrives-with-a-bunch-of-essential-bug-fixes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3199441/linux-tipps/steamos-3719-arrives-with-a-bunch-of-essential-bug-fixes/</guid>
<pubDate>Wed, 07 Jan 2026 12:37:07 +0100</pubDate>
<content:encoded><![CDATA[Valve have released the latest stable update for SteamOS version 3.7.19, bringing a bunch of bug fixes to improve the Linux gaming platform.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt>.</p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/01/steamos-3-7-19-arrives-with-a-bunch-of-essential-bug-fixes/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accenture to acquire UK AI startup Faculty]]></title>
<description><![CDATA[Accenture has announced that it has agreed to acquire UK AI startup Faculty for an undisclosed sum, a potentially significant move in a consultancy sector currently scrambling to add greater artificial intelligence expertise.



According to Accenture, Faculty’s UK-based workforce of 400 “AI nati...]]></description>
<link>https://tsecurity.de/de/3198332/it-security-nachrichten/accenture-to-acquire-uk-ai-startup-faculty/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3198332/it-security-nachrichten/accenture-to-acquire-uk-ai-startup-faculty/</guid>
<pubDate>Tue, 06 Jan 2026 21:20:32 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Accenture has announced that it has agreed to acquire UK AI startup Faculty for an undisclosed sum, a potentially significant move in a consultancy sector currently scrambling to add greater artificial intelligence expertise.</p>



<p><a href="https://newsroom.accenture.com/news/2026/accenture-to-acquire-faculty-to-scale-ai-capabilities" target="_blank" rel="nofollow">According to Accenture</a>, Faculty’s UK-based workforce of 400 “AI native professionals” will be integrated with its consulting teams, allowing the company to offer its customer base “world‑class AI capabilities.” The company will also integrate Faculty’s AI decision intelligence platform, Frontier, into its services.</p>



<p>“With Faculty, we will further accelerate our strategy to bring trusted, advanced AI to the heart of our clients’ businesses,” commented Accenture chair and CEO, Julie Sweet.</p>



<p>One detail that marks the acquisition as unusual is that Faculty’s current CEO, Marc Warner, will <a href="https://www.bloomberg.com/news/articles/2026-01-06/accenture-plans-to-buy-uk-palantir-rival-faculty-in-consultancy-s-ai-push" target="_blank" rel="nofollow">reportedly</a> join Accenture’s Global Management Committee as chief technology officer (CTO). If confirmed, this means that a company employing a few hundred people will take a key board position in a huge consulting outfit with nearly 800,000 employees worldwide.</p>



<p>Accenture still lists its CTO as <a href="https://www.accenture.com/us-en/about/leadership/rajendra-prasad" target="_blank" rel="nofollow">Rajendra Prasad</a>, who will presumably step back from this role to focus on his other day job as the company’s Group Chief Executive – Technology. <em>CIO.com</em> contacted Accenture and Faculty to confirm the new roles, but had no response by publication time.</p>



<h2 class="wp-block-heading">AI reinvention</h2>



<p>Traditional tech acquisitions are usually motivated by the value offered by a company’s patents, products and customers. With AI companies, just as important right now is human expertise.</p>



<p>Faculty offers all of these. Co-founded in 2014 as ASI Data Science by then Harvard quantum physics research fellow Warner, it was renamed Faculty in 2019. This might have been an attempt to disassociate it from allegations, which it <a href="https://faculty.ai/insights/articles/cambridge-analytica-a-clarification" target="_blank" rel="nofollow">strenuously denied</a>, that it was part of the same internship program as scandal-hit company <a href="https://www.csoonline.com/article/573505/facebook-agrees-to-settle-class-action-lawsuit-related-to-cambridge-analytica-data-breach.html" target="_blank">Cambridge Analytica</a>, through the latter’s parent company, SCL Group.</p>



<p>Since then, Faculty has established a solid reputation through its work with the UK government, including the creation of an <a href="https://faculty.ai/ourwork/nhs-ews" target="_blank" rel="nofollow">NHS Early Warning System</a> (EWS) system used to predict hospital admissions and ventilator requirements during the Covid pandemic.</p>



<p>This dovetails well with Accenture’s direction; it has spent the last year undergoing an AI makeover. In June, the company folded five business units into a single division, <a href="https://newsroom.accenture.com/news/2025/accenture-changes-growth-model-to-reinvent-itself-for-the-age-of-ai" target="_blank" rel="nofollow">Reinvention Services</a>, as part of a plan to “re-invent Itself for the Age of AI.” At the same time, it started calling its employees “reinventors”.</p>



<p>The company has also formed alliances with OpenAI and Anthropic which will see tens of thousands of its employees trained to use and promote both companies’ chatbot and agentic technologies.</p>



<p>“We are writing the playbook for how to be the most AI-enabled, client-focused professional services company in the world,” said Accenture CEO Sweet in this week’s announcement of the acquisition.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] The difficulty of safe path traversal]]></title>
<description><![CDATA[Aleksa Sarai, as the maintainer of the
runc container runtime, faces a
constant battle against security problems. Recently, runc has seen

another
instance of a security vulnerability that can be traced back to the difficulty
of handling file paths on Linux. Sarai spoke at the 2025
Linux Plumbers...]]></description>
<link>https://tsecurity.de/de/3198038/linux-tipps/the-difficulty-of-safe-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3198038/linux-tipps/the-difficulty-of-safe-path-traversal/</guid>
<pubDate>Tue, 06 Jan 2026 18:22:08 +0100</pubDate>
<content:encoded><![CDATA[<p>
Aleksa Sarai, as the maintainer of the
<a href="https://github.com/opencontainers/runc?tab=readme-ov-file#runc">runc container runtime</a>, faces a
constant battle against security problems. Recently, runc has seen
<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52565">
another
instance</a> of a security vulnerability that can be traced back to the difficulty
of handling file paths on Linux. Sarai spoke at the 2025
<a href="https://lpc.events/event/19">Linux Plumbers Conference</a>
(<a href="https://lpc.events/event/19/contributions/2065/attachments/1851/3964/Path%20Safety%20in%20the%20Trenches%20%5BLPC%202025%5D.pdf">slides</a>;
<a href="http://www.youtube.com/watch?v=z8v7ovIeDRM">video</a>)
about
some of the problems runc has had with path-traversal vulnerabilities, and to
ask people to please use
<a href="https://github.com/cyphar/libpathrs/?tab=readme-ov-file#libpathrs">
libpathrs</a>, the library that he has been developing for
safe path traversal.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI transforms agriculture in the rural world]]></title>
<description><![CDATA[It all started with a sewing machine. Ramón Álvarez de Arriba was one of the many Asturian immigrants who sought their fortunes in America in the 19th century. When he returned to Spain, he was the official distributor of Singer sewing machines, and upon his death in 1920, he dedicated his great ...]]></description>
<link>https://tsecurity.de/de/3190502/it-security-nachrichten/how-ai-transforms-agriculture-in-the-rural-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3190502/it-security-nachrichten/how-ai-transforms-agriculture-in-the-rural-world/</guid>
<pubDate>Fri, 02 Jan 2026 11:07:13 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It all started with a sewing machine. Ramón Álvarez de Arriba was one of the many Asturian immigrants who sought their fortunes in America in the 19th century. When he returned to Spain, he was the official distributor of Singer sewing machines, and upon his death in 1920, he dedicated his great wealth to creating a foundation in the nearby Peón Valley to strengthen agricultural education and innovation.</p>



<p>Fast forward to 2019 and the foundation developed the CTIC RuralTech innovation center, a branch of the Information and Communication Technology Center Foundation (CTIC). </p>



<p>The CTIC’s headquarters in Gijón now include a quantum simulator, data hub, and an expanded reality experience generator. “We’ve been around for 22 years, and from the beginning, we’ve had a very close connection with rural areas,” says Fidel Díaz, CTIC’s R&amp;D director. When the opportunity came up a few years ago to take over assets of the Ramón Álvarez de Arriba Foundation, they embraced it and opened a center that explores cutting-edge technologies, and shares space with the school that opened a century ago.</p>



<p>RuralTech remains focused on the enduring ideal to revitalize rural areas, and applies cutting-edge tools to address major challenges facing these territories, like climate change, which greatly impacts agriculture. “Many crops will no longer be able to be grown in the regions where they’re currently cultivated,” says Díaz. So it’s necessary to discover which varieties are most resistant to change, and to gather data to understand the new context. “We can control that,” he adds, emphasizing that technology makes it possible to perform analyses, better understand the soil, and differentiate what is and isn’t more resilient.</p>



<h2 class="wp-block-heading">A time machine for the countryside</h2>



<p>Cutting-edge IT tools now available include climate simulation systems and land-use intelligence, so crops can be monitored, and changes in the landscape can be understood. And thanks to the collected data, models are created that are applicable to other regions. As Díaz points out, the problems of the Asturian countryside aren’t unique and are repeated in other parts of Spain and throughout Europe. So applied to specific elements, these tools help improve the sustainability and efficiency of agricultural and livestock operations.</p>



<p>It’s like a time machine, says Fernando Ruenes, who, along with Ángela Campo, runs strawberry production company Asturiana de Fresas, and uses the CTIC simulator. They divide it into different planting zones and apply varying conditions to each. This way, they can predict outcomes in different contexts, and anticipate the effects of potential diseases, climate change, and water stress. “With the simulator, we have an advantage,” says Ruenes. “It’s about anticipating real-life situations.”</p>



<p>Thanks to these tests, you can even determine the optimal planting date or identify which species and crops not yet grown in the area might thrive, like olives or pistachios. A better understanding of the impact of different conditions also helps reduce pesticide use and increase crop profitability. Without AI and other emerging technology, these types of tests and simulations would take years, but with it, they can be completed in just one.</p>



<h2 class="wp-block-heading">AI ​​and the big cheese</h2>



<p>Enrique López, CEO of Spanish cheese producer Industrias Lácteas Monteverde, was once asked why they weren’t using the data generated by their cheese tastings and production. “We might have the data, but who’s going to develop this?” he recalls thinking. The solution lay with the technology center. They were the ones who could do the development. They started in 2020 when the pandemic upended the market and forced cheesemakers to reinvent production to adapt to different consumption habits. After the disruption, things got back on track, and now AI understands cheese, and which milk is best suited for which type of cheese.</p>



<p>“We knew the ideal cheese that had to be produced,” López says. But the milk isn’t always the same. Many variables affect it, from truck routes through different farms to cow diets. The quality is always high but different nuances impact the final result. Also, the way the product is presented or consumed requires changes to the maturation process. But now AI takes that entire pool of incoming milk and determines which is suitable for which purpose.</p>



<p>The AI ​​provides a recommendation, and López says more variables need to be included, such as registered orders and estimated working time. “This is a continuous learning process,” he says. The order book, stock levels, and estimates of milk and cheese price fluctuations would also allow for even greater efficiency. </p>



<p>So the overall result is positive. They’ve already seen return rates approach zero and achieved collateral benefits, such as lowering the costs of comparative analyses.</p>



<h2 class="wp-block-heading">Tech potential for the field</h2>



<p>Although people often associate large urban environments with innovation, the rural world has always been in contention. “We’ve been innovating for many years,” López says. Industrias Lácteas Monteverde, in fact, is currently in the middle of a project with the University of Oviedo to convert whey from cheese production into plastic, and to use technology to help them reduce water consumption in the cleaning process.</p>



<p>It’s just one example of how tech potential in agriculture is limitless, especially for addressing crucial challenges of the future that already shape the present. “It’s very important to combine agricultural expertise with technological expertise,” adds Asturiana de Fresas’ Ruenes. They contribute their knowledge of the land, plants, and agricultural cycles, and the technology center provides the IT tools to overcome boundaries.</p>



<p>But adding tech for the sake of it is pointless. ICT tools can’t be superfluous and must offer solutions that add business value. “There’s no better way to innovate rural areas than from within rural areas,” Díaz says. “You have to endure it. Being in the countryside allows you to understand the real problems of those areas in real time, the context, and be in direct contact with key decision-makers.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[When scaling AI means foundational reform]]></title>
<description><![CDATA[AI pilot projects are often executed quickly and successfully. But the real challenge is scaling the solution across the entire enterprise, says Mauro Macchi, Accenture’s EMEA CEO. And for AI to contribute genuine added value, a company-wide redesign, including processes, systems, skills, and way...]]></description>
<link>https://tsecurity.de/de/3180220/it-security-nachrichten/when-scaling-ai-means-foundational-reform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3180220/it-security-nachrichten/when-scaling-ai-means-foundational-reform/</guid>
<pubDate>Fri, 26 Dec 2025 11:06:47 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI pilot projects are often executed quickly and successfully. But the real challenge is scaling the solution across the entire enterprise, says Mauro Macchi, Accenture’s EMEA CEO. And for AI to contribute genuine added value, a company-wide redesign, including processes, systems, skills, and ways of working, is often necessary.</p>



<p>Macchi adds that <a href="https://www.cio.com/article/4089704/what-to-look-for-in-an-ai-implementation-partner.html?utm=hybrid_search">AI implementation</a> should start with the problem that needs solving, not the technology. Use cases here from London-based beauty startup Noli, Spanish energy company Repsol, and supply chain specialist Kion illustrate the diverse challenges companies can face, whether it’s the data, processes, or regulations.</p>



<h2 class="wp-block-heading">Using AI to combat beauty burnout</h2>



<p>Noli, a personalized beauty platform backed by the L’Oréal Group, uses AI to reinvent the beauty industry with the help of an app to address the growing problem of skin anxiety and beauty burnout.</p>



<p>The aim is to end the feeling of being overwhelmed by beauty products. As a result, in the UK alone, such products worth over £1 billion ($1.35 billion) are wasted annually because they don’t deliver desired results.</p>



<p>So Noli aims to combat this with a vertical expert AI deeply rooted in beauty science, and based on a robust, multi-layered architecture that encompasses scientific research and multimodal consumer signals, including one million anonymized facial scan data points.</p>



<p>The biggest challenge for Noli wasn’t the AI but the data. <a href="https://www.cio.com/article/2510043/ulta-beauty-embraces-low-code-to-deliver-better-cx.html?utm=hybrid_search">Beauty data</a> is so fragmented, with scientific research data, formulation information, insights from facial scans, user behavior, and sensory attributes all coming in different formats from various sources.</p>



<p>This complex mix needed to be transformed into something structured, trustworthy, and scalable. So the proprietary Beauty Knowledge Graph was developed, which structures raw data, validates outputs to prevent hallucinations, and matches products to the right needs in real time.</p>



<p>The name Noli, “No one like I,” is also the mission statement. Users can determine their personal beauty DNA profile by answering a questionnaire, undergoing an expert facial scan, or contacting <a href="https://noli.com/" rel="nofollow">Noli</a> directly.</p>



<p>The company then creates personalized recommendations for trusted, scientifically sound beauty brands. To achieve this, Noli uses continuous learning loops as every match, review, purchase, or return improves the system.</p>



<p>The conversion rate seems to confirm the success of this approach. According to Noli CEO and co-founder Amos Susskind, website visitors are nearly four times more likely to make a purchase, and also buy more than usual. And the number of <a href="https://www.cio.com/article/4091106/want-ai-that-actually-works-start-by-designing-it-around-people-not-tickets.html?utm=hybrid_search">repeat customers</a> has doubled in five months.</p>



<h2 class="wp-block-heading">A multi-energy approach to AI</h2>



<p>Repsol’s approach to AI is quite different. The gen AI journey for the multi-energy multinational, with over 25,000 employees, began as part of a broader digital transformation initiated in 2018.</p>



<p>The strategy comprises three main areas: personal productivity, improving current processes, and Gold Mine, considered key to redesign and reinvent projects and processes.</p>



<p>To achieve everything laid out, the company uses <a href="https://www.cio.com/article/4109167/cios-top-10-takeaways-from-the-year-ai-got-practical.html?utm=hybrid_search">multi-agent systems</a> designed to solve complex processes or workflows by enabling specialized agents to collaborate. Agents require skills such as knowledge, planning, reasoning, coordination, and execution, all supported by a shared short- and long-term memory.</p>



<p>The system also operates via an orchestrator that receives requests. It identifies the appropriate planner, who in turn defines the plan and selects suitable, highly specialized agents from a catalog. The system is currently operational and comprises 34 agents, with whom over 100 employees collaborate in a hybrid work environment.</p>



<p>Besides data quality, Repsol CIO Juanma García faced the key challenge of recognizing that AI is not a standard technology. Company executives had to learn that AI initiatives can fail if they’re implemented haphazardly, and their experience considered cognitive infrastructure.</p>



<p>Another ongoing priority is change management and helping users adapt to a new way of working, driven by AI. In order to be more effective and avoid problems, Repsol also defines agents with limited scope for specialized tasks instead of creating large agents that cover too much.</p>



<p>Repsol’s advice for other companies trying to get value from AI investments is to define a clear strategy. While increasing personal productivity, like through Copilot, is difficult to demonstrate in a profit and loss statement, completely redesigning processes is key to achieving significant added value.</p>



<h2 class="wp-block-heading">Using physical AI to create new supply chains</h2>



<p>As a provider of supply chain solutions, Kion aims to bring physical AI to the warehousing and distribution market. Given the significant pressure on global supply chains due to geopolitical tensions and disruptions, Kion is forced to rethink its approach to warehouse automation. The goal is to make them more real-time capable and resilient, replacing rigid structures with flexible, adaptable, and intelligent solutions.</p>



<p>Kion has Mega, an Omniverse blueprint from Nvidia, for this purpose, enabling large-scale development, testing, and optimization of physical AI and robot fleets using a <a href="https://www.cio.com/article/3994397/digital-twins-combine-with-ai-to-help-manage-complex-systems-2.html?utm=hybrid_search">digital twin</a>. To quickly transfer physical locations into the digital system, Kion uses a scanner that captures a distribution or fulfillment center, and feeds the data into the Nvidia Omniverse. Subsequently, replicas of all AMRs, AGVs, and bots are integrated into the digital system.</p>



<p>The digital twin then allows Kion to simulate an unlimited number of scenarios and measure operational KPIs, such as throughput and utilization, before making changes to the physical warehouse. From there, the digital twin can instruct the physical twin on optimal steps to take.</p>



<p>While Kion CEO Rob Smith sees the company as technologically well-positioned, the regulatory environment in the EU is a headache as he feels it stifles <a href="https://www.cio.com/article/4101091/the-trick-to-balancing-governance-with-innovation-in-the-age-of-ai.html?utm=hybrid_search">innovation</a>. This, he says, is one reason why the pace of AI adoption is significantly faster in North America and China, so he advocates allowing innovation first and regulating it later, rather than the other way around.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What the AWS outage taught CIOs about preparedness]]></title>
<description><![CDATA[When the AWS US East 1 region went dark in October, it created a ripple effect that reached far beyond cloud workloads. Atlassian tools, home monitoring systems, communication platforms and even school websites became unavailable within minutes. None of these failures resulted from an attack nor ...]]></description>
<link>https://tsecurity.de/de/3173707/it-security-nachrichten/what-the-aws-outage-taught-cios-about-preparedness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3173707/it-security-nachrichten/what-the-aws-outage-taught-cios-about-preparedness/</guid>
<pubDate>Mon, 22 Dec 2025 11:06:40 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When the AWS US East 1 region went dark in October, it created a ripple effect that reached far beyond cloud workloads. Atlassian tools, home monitoring systems, communication platforms and even school websites became unavailable within minutes. None of these failures resulted from an attack nor reflected a lack of backup architecture. They represented a growing challenge for CIOs stemming from the unseen dependencies that now sit underneath critical business functions.</p>



<p>For many organizations, the event felt like a cyber incident even though it wasn’t, but it raised a difficult question for CIOs about how to prepare for a disruption that lives outside your infrastructure, yet carries the same operational and reputational consequences as a security breach.</p>



<p>That has been top of mind for Yogs Jayaprakasam, the chief information, technology and digital officer at business payments and financial tech services provider Deluxe. The 110-year-old company relies on a mix of cloud platforms, SaaS products, and enterprise systems, and Jayaprakasam says the AWS outage reinforced something he’s been observing for years. Following the event, he traced more than a dozen public cloud outages across the three major hyperscalers in the past 12 months, each lasting six hours or more.</p>



<p>Beyond strong cloud architecture, “Preparedness is the real differentiator,” he says. “Even the best technology teams can’t compensate for gaps in scenario planning, coordination, and governance.”</p>



<h2 class="wp-block-heading">The convergence of operational and cyber failures</h2>



<p>Jayaprakasam’s perspective began to shift as he studied recent incidents, from the Meta BGP misconfiguration in 2021 to last year’s widespread CrowdStrike update failure. He explained that although these events weren’t cyber attacks, the customer impact, communication challenges, and recovery complexity mirrored major security breaches. “We treated disaster recovery and cyber response like two different problems,” he says. “But when something like a bad update takes down millions of machines, it behaves exactly like a ransomware event.”</p>



<p>Within Deluxe, disaster recovery tests historically focused on applications the company controlled, while cyber tabletops focused on simulated intrusions. The AWS outage exposed the gap between those exercises and real-world conditions. Shifting its applications from AWS East to AWS West was swift, and the technology team considered the recovery a success. Yet it was far from business as usual, as developers still couldn’t access critical tools like GitHub or Jira. “We thought we’d recovered, but the day-to-day work couldn’t continue because the tools we depend on were down,” he says. That experience reshaped how his team defines resilience.</p>



<h2 class="wp-block-heading"><a></a>Seeing the full dependency chain</h2>



<p>In response, Deluxe began mapping system dependencies in far greater detail. One of the simplest but most important changes, Jayaprakasam says, was adding a question to every SaaS intake process about where the application actually runs, since knowing whether a tool operates on AWS West, Azure East, or another region allows the team to simulate real failure scenarios, and plan coordinated recovery steps with vendors.</p>



<p>“It’s a shift in data collection that makes you better prepared,” he says. “Once you see which SaaS platforms share the same cloud region, you start to think very differently about how the business comes back online during an outage.”</p>



<p>This visibility allows Deluxe to extend tabletop scenarios beyond the boundaries of owned infrastructure. The company now includes operational failures, cloud region outages, and third-party disruptions in its joint cyber and DR exercises, rather than running them in separate tracks. This unified approach, called ResilienceONE, delivers a more realistic understanding of how failures propagate across the ecosystem, strengthening both resilience and preparedness.</p>



<h2 class="wp-block-heading">Coordination over investment</h2>



<p>Spending more money on additional infrastructure or redundant cloud providers isn’t the answer. After all, following every major outage, Jayaprakasam says sales pitches arrive promising zero downtime if organizations spend more on new platforms. He pushes back on those claims. In a well-architected hybrid cloud setup, he says resilience is more often a coordination problem than a spending problem, and distributing workloads across two cloud providers doesn’t guarantee better outcomes if the clouds rely on the same power grid, or experience the same regional failure event.</p>



<p>He argues that the more effective approach is strengthening coordination between IT, cybersecurity, business continuity, and third-party vendors. “The real question is whether you have the right contacts, process, and response patterns in place,” he says. That coordination includes creating a single view of dependencies, practicing joint response exercises, and ensuring that vendors can be reached and escalated during an incident. You can gradually develop advanced dependency mapping of your assets across boundaries to simulate potential impact radius scenarios.</p>



<p>In addition, Jayaprakasam believes that many organizations already have strong response processes but they simply apply them too narrowly. Legal and compliance teams, for example, have well established playbooks for cyber incidents, and those playbooks can also apply to operational disruptions. </p>



<p>“You don’t need to reinvent the wheel,” he says. “You need to make the process holistic and complementary instead of creating separate paths.” So when advising peers, Jayaprakasam recommends starting with the scenarios used in tabletop exercises. He encourages CIOs to ask whether they’re testing for operational disruptions and third party outages in addition to cyber attacks, and whether those exercises reflect the actual dependencies that keep the business running. Plus, he suggests reviewing where existing playbooks can be unified rather than creating new ones, focusing on coordination across teams and partners instead of new investments.</p>



<h2 class="wp-block-heading"><a></a>The leadership challenge: motivating the work no one sees</h2>



<p>Jayaprakasam is candid about the cultural challenge that comes with resilience work. He says that in an era dominated by AI initiatives and digital strategy, the toughest part of leadership is motivating teams to focus on the routines that seem unexciting but are critical to a company’s ability to recover during a crisis. “Most of the work that prepares you for these moments is boring,” he says. “But that boring work is what changes the business outcome.”</p>



<p>He believes CIOs must reward that discipline, not just the innovation work that receives more headlines. And he’s clear about the stakes. AI may define the long-term value of a technology organization, but reliability defines its credibility in the present. “Your ability to be seen as a strategic partner can be taken away in a second if the systems aren’t available,” he says. “Striking the balance is what matters.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your RPA is Mine: Complete Takeover of RPA Ecosystems]]></title>
<description><![CDATA[Author: OWASP Foundation - Bewertung: 0x - Views:1 Presentation Slides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/ee/Alon%20Dankner%20-%20Your%20RPA%20is%20Mine%20-%20OWASP%20DC%202025.pdf

Our research uncovers a new threat vector for enterprises in the realm of Robotic Proc...]]></description>
<link>https://tsecurity.de/de/3161605/it-security-video/your-rpa-is-mine-complete-takeover-of-rpa-ecosystems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3161605/it-security-video/your-rpa-is-mine-complete-takeover-of-rpa-ecosystems/</guid>
<pubDate>Tue, 16 Dec 2025 08:48:58 +0100</pubDate>
<content:encoded><![CDATA[<p>Author: OWASP Foundation - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OImAVe14WUQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Presentation Slides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/ee/Alon%20Dankner%20-%20Your%20RPA%20is%20Mine%20-%20OWASP%20DC%202025.pdf<br />
<br />
Our research uncovers a new threat vector for enterprises in the realm of Robotic Process Automation (RPA), challenging the assumption that RPA automations are inherently secure. We demonstrate the first-ever RPA malware capable of infecting automations built in UiPath—a leading RPA development platform—while evading traditional security measures. By compromising automation environments, this attack triggers a devastating domino effect across an entire enterprise.<br />
<br />
Across industries and departments, RPA adoption skyrockets in enterprises pursuing digital transformation. RPA development platforms like UiPath, Microsoft Power Automate, and ServiceNow enable non-technical business users to create and deploy powerful automations by composing drag-and-drop components (e.g., sending email and executing SQL query). These automations handle and manipulate critical enterprise data.<br />
<br />
We demonstrate an innovative malware that allows attackers to infect all UiPath automations and establish persistence. By stealing keys and tokens from the automation’s runtime environment, our malware infects UiPath automations and rapidly spreads to all available feeds. As a result, the malicious payload runs on every connected runtime environment, compromising any desktop and cloud.<br />
<br />
This malware's unique ability to perform only UiPath actions allows it to evade traditional security measures. Our malware can gain initial access to the enterprise, either by a malicious actor leveraging the UiPath public marketplace or by the automation developer overlooking implementation vulnerabilities such as command injection.<br />
<br />
Our findings demonstrate a novel malware propagation avenue that bypasses traditional defences; a route that proves effective for deploying any malware, including ransomware. The dangerous misconception that RPA is secure by design has persisted for years, lulling security teams and leaving organizations vulnerable to emerging threats. To address these critical issues, we provide essential, actionable mitigations to secure RPA automations and protect against this evolving internal and external attack surface.<br />
<br />
Alon Dankner<br />
Nokod Security<br />
Security Researcher<br />
<br />
Alon Dankner is a security researcher at Nokod Security, a low-code/no-code cybersecurity startup. He holds a B.Sc. in Computer Science from the University of Haifa (cum laude) and an M.Sc. from the Technion (cum laude). Computers and network security have always been a topic of interest to him, and his research focuses on the security of low-code/no-code systems and industrial control systems.<br />
<br />
alon@nokodsecurity.com<br />
linkedin.com/in/alon-dankner/<br />
<br />
Managed by the OWASP® Foundation<br />
https://owasp.org/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS re:Invent: Von der Cloud zur KI-Plattform]]></title>
<description><![CDATA[AWS re:Invent: Von der Cloud zur KI-Plattform

      
      
        
          
            
                



            
          
        
              
    
  Dr. Jens Söldner
Di., 16.12.2025 - 07:00


            Die AWS re:Invent 2025 setzte klare Schwerpunkte: autonome KI-Agenten, ve...]]></description>
<link>https://tsecurity.de/de/3161409/server/aws-reinvent-von-der-cloud-zur-ki-plattform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3161409/server/aws-reinvent-von-der-cloud-zur-ki-plattform/</guid>
<pubDate>Tue, 16 Dec 2025 07:15:40 +0100</pubDate>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">AWS re:Invent: Von der Cloud zur KI-Plattform</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/aws-reinvent-2025-cloud-ki-plattform"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/News_AWS-reinvent-2025.jpg?itok=962SfRtl" width="480" height="319" alt="Besucher der AWS re:Invent 2025 bewegen sich in der Veranstaltungshalle. An einer Wand hängt ein großes, weißes AWS-Logo." title="Besucher auf der AWS re:Invent 2025 in Las Vegas: Die jährliche Konferenz zeigte, wie AWS Cloud-Infrastruktur, KI und Automatisierung weiter verzahnt. (Quelle: AWS)" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/153" lang about="https://www.it-administrator.de/user/153" typeof="schema:Person" property="schema:name" datatype class="username">Dr. Jens Söldner</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2025-12-16T07:00:00+01:00" title="Dienstag, Dezember 16, 2025 - 07:00" class="datetime">Di., 16.12.2025 - 07:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Die AWS re:Invent 2025 setzte klare Schwerpunkte: autonome KI-Agenten, vereinfachte Modellanpassung und spürbare Kostensenkungen. Der Cloudanbieter richtet seine Plattform damit stärker auf Automatisierung und operative Effizienz aus. Wir zeigen, welche interessanten Neuerungen auf Admins in mittelständischen Unternehmen warten.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/news" hreflang="en">News</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/aws-reinvent-2025-cloud-ki-plattform" rel="tag" title="AWS re:Invent: Von der Cloud zur KI-Plattform" hreflang="en">Weiterlesen<span class="visually-hidden"> über AWS re:Invent: Von der Cloud zur KI-Plattform</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Privacy by Design: What Are Engineers Supposed to Do With That?]]></title>
<description><![CDATA[Author: OWASP Foundation - Bewertung: 0x - Views:1 Presentation slides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/55/OWASP%20DC%202025%20Privacy%20Project.pdf

Ask ten engineers what "privacy by design" means, and you’ll get ten different answers—and most of them won’t help y...]]></description>
<link>https://tsecurity.de/de/3161270/it-security-video/privacy-by-design-what-are-engineers-supposed-to-do-with-that/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3161270/it-security-video/privacy-by-design-what-are-engineers-supposed-to-do-with-that/</guid>
<pubDate>Tue, 16 Dec 2025 06:01:56 +0100</pubDate>
<content:encoded><![CDATA[<p>Author: OWASP Foundation - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/AJTxH00ia4w?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Presentation slides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/55/OWASP%20DC%202025%20Privacy%20Project.pdf<br />
<br />
Ask ten engineers what "privacy by design" means, and you’ll get ten different answers—and most of them won’t help you ship both secure and privacy-aware software. The focus in AppSec has been on securing the design with Threat Modeling, securing the code, and addressing third-party risk management challenges. But what does privacy mean to software engineers? It’s fuzzy, vague, and *‘someone else’s problem’*.<br />
<br />
This talk unpacks why privacy engineering is broken for builders—and how we're changing that. We'll share early insights from the new OWASP Privacy Reference Project, which aims to translate privacy into practical guidance for security teams, architects, and developers. AppSec voices are critical to getting this right—come help us turn privacy from a vague ideal into a usable engineering discipline.<br />
<br />
Kim Wuyts<br />
PwC<br />
Privacy Engineer<br />
<br />
Dr. Kim Wuyts is a leading privacy engineer with over 15 years of experience in security and privacy. Before joining PwC Belgium as Manager Cyber & Privacy, Kim was a senior researcher at KU Leuven where she led the development and extension of LINDDUN, a popular privacy threat modeling framework. Her mission is to raise privacy awareness and get organizations to embrace privacy engineering best practices. She is a guest lecturer, experienced speaker, and invited keynote at international privacy and security conferences such as OWASP Global AppSec, BruCON, RSA, Troopers, CPDP, and IAPP DPC. In the last few years, Kim has been delivering privacy awareness and privacy threat modeling training at many events, including academic guest lectures and corporate training. Kim is also a co-author of the Threat Modeling Manifesto+Capabilities, industry co-chair of the International Workshop on Privacy Engineering (IWPE), and a member of ENISA’s working group on Data Protection Engineering.<br />
<br />
Matthew Coles<br />
<br />
Matthew Coles is a Product Security Architect and Technologist with 20+ years experience working with business leaders and developers to secure hardware and software systems and processes. He is a technical contributor to community standard initiatives such as OpenSSF and OWASP, a mentor and educator, and is a maintainer of the PyTM project for threat modeling as code. Matt is a co-author of a book on Threat Modeling, a white paper on Threat Modeling through SAFECode, and the Threat Modeling Manifesto and Capabilities.<br />
<br />
Managed by the OWASP® Foundation<br />
https://owasp.org/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Defend Your PKI Estate: Lessons Learned from Eight Years of CAA and Certificate Transparency]]></title>
<description><![CDATA[Author: OWASP Foundation - Bewertung: 0x - Views:0 Presentation slides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/74/How%20to%20Defend%20Your%20PKI%20Estate%20%28Ivan%20Ristic%2C%20November%202025%29%20FINAL.pdf

On the Internet, all security is controlled by digital certific...]]></description>
<link>https://tsecurity.de/de/3161247/it-security-video/how-to-defend-your-pki-estate-lessons-learned-from-eight-years-of-caa-and-certificate-transparency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3161247/it-security-video/how-to-defend-your-pki-estate-lessons-learned-from-eight-years-of-caa-and-certificate-transparency/</guid>
<pubDate>Tue, 16 Dec 2025 05:31:47 +0100</pubDate>
<content:encoded><![CDATA[<p>Author: OWASP Foundation - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/szeG5_a6zVU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Presentation slides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/74/How%20to%20Defend%20Your%20PKI%20Estate%20%28Ivan%20Ristic%2C%20November%202025%29%20FINAL.pdf<br />
<br />
On the Internet, all security is controlled by digital certificates, but there is a critical flaw at the heart of our Public Key Infrastructure (PKI) ecosystem: any Certification Authority can issue a certificate for any of your properties without your consent. Recent years have seen development of some mitigation technologies, such as Certification Authority Authorization (CAA) and Certificate Transparency (CT). Together, these technologies enable you to regain control of your digital identities. We've spent several years securing digital estates for a wide range of customers; in this talk, we'll share our experiences to help you understand the threats and give you actionable advice to raise your defenses.<br />
<br />
Ivan Ristic<br />
Red Sift<br />
Chief Scientist<br />
<br />
Ivan Ristić writes computer security books and builds security products. His book Bulletproof TLS and PKI, the result of more than a decade of research and study, is widely recognised as the de facto SSL/TLS and PKI reference manual. His work on SSL Labs made millions of web sites more secure. Before that, he created ModSecurity, a leading open-source web application firewall. More recently, Ivan founded Hardenize—now part of Red Sift—as a platform for continuous discovery and monitoring of network and PKI infrastructure. He works as Chief Scientist at Red Sift.<br />
@ivanristic<br />
linkedin.com/in/ivanr<br />
<br />
Managed by the OWASP® Foundation<br />
https://owasp.org/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese PRC shenanigans in the npm mirror ecosystem]]></title>
<description><![CDATA[Author: OWASP Foundation - Bewertung: 1x - Views:1 Presentation slides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/b2/PRC%20Shenanigans%20-%20OWASP%20Global%20AppSec%202025.pptx

npm is the world's largest and most popular software registry. Unfortunately, attackers target npm...]]></description>
<link>https://tsecurity.de/de/3161169/it-security-video/chinese-prc-shenanigans-in-the-npm-mirror-ecosystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3161169/it-security-video/chinese-prc-shenanigans-in-the-npm-mirror-ecosystem/</guid>
<pubDate>Tue, 16 Dec 2025 03:16:57 +0100</pubDate>
<content:encoded><![CDATA[<p>Author: OWASP Foundation - Bewertung: 1x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/fHV2mhP0N2w?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Presentation slides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/b2/PRC%20Shenanigans%20-%20OWASP%20Global%20AppSec%202025.pptx<br />
<br />
npm is the world's largest and most popular software registry. Unfortunately, attackers target npm packages because they know existing security tools like SCA or EDR don't protect developers from malicious npm packages<br />
<br />
When a researcher or the GitHub security team identifies a malicious package, npm removes it from the registry to prevent further downloads. All servers in the npm mirror ecosystem are then supposed to remove the malicious package from their local copies of the npm database.<br />
<br />
Of the 8 global npm mirrors worldwide, five are located in China, representing 63% of all npm mirrors. During my in-depth research of the npm ecosystem, particularly the Chinese npm mirrors, I discovered something concerning: while Chinese npm mirrors appear to remove malware from their registries, they continue to serve it, albeit hidden. Why is it that only Chinese npm servers do this?!<br />
<br />
I’ve been using this bug for two years to get access to malware that almost no one else has seen. In this presentation, I will show exactly how I do this with the audience so they can enjoy the same supply of tasty, npm malware!<br />
<br />
Paul McCarty<br />
Safety<br />
Head of Research at Safety. Founder of SecureStack, GitHax and SourceCodeRED. Software supply chain offensive security crazy person.<br />
Gold Coast, Queensland<br />
<br />
https://twitter.com/eastsidemccarty<br />
https://www.linkedin.com/in/mccartypaul/<br />
<br />
Paul is the Head of Research at Safety (safetycli.com) and a well-known researcher in the malicious packages space, as well as being a DevSecOps OG. He founded multiple startups including SecureStack in 2017, SourceCodeRED in 2023 and GitHax in 2024 . Paul has worked for NASA, Boeing, Blue Cross/Blue Shield, John Deere, the US military, and Australian government amongst others.  Paul is a frequent contributor to open source and is the author of several DevSecOps, software supply chain and threat modelling projects. He’s currently writing a book entitled “Hacking NPM” and when he’s not doing that he’s snowboarding with his wife and 3 amazing kids.  <br />
<br />
@eastsidemccarty<br />
linkedin.com/in/mccartypaul/<br />
safetycli.com (company)<br />
sourcecodered.com/blog (blog)<br />
<br />
Managed by the OWASP® Foundation<br />
https://owasp.org/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP Top 10 Annoucement]]></title>
<description><![CDATA[Author: OWASP Foundation - Bewertung: 0x - Views:2 Presentation sides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/35/DC2025%20-%20OWASP%20Top%20Ten%202025.pptx

The OWASP Top 10:2025 provides an updated view of modern applications' most common and impactful security risks. Bas...]]></description>
<link>https://tsecurity.de/de/3159488/it-security-video/owasp-top-10-annoucement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3159488/it-security-video/owasp-top-10-annoucement/</guid>
<pubDate>Mon, 15 Dec 2025 11:32:34 +0100</pubDate>
<content:encoded><![CDATA[<p>Author: OWASP Foundation - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/yGOXewm3DsA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Presentation sides: https://static.sched.com/hosted_files/owaspglobalappsecusa2025/35/DC2025%20-%20OWASP%20Top%20Ten%202025.pptx<br />
<br />
The OWASP Top 10:2025 provides an updated view of modern applications' most common and impactful security risks. Based on both industry data and community survey input, the Top 10 is designed as an awareness tool, helping teams baseline the most relevant security concerns. This talk will walk through the changes since the 2021 edition, highlighting where categories have shifted, merged, or expanded to reflect the changes over the last four years. Each risk category will be introduced at a high level, covering its main issues and offering context for how organizations can use the list as a reference point in their security programs.<br />
<br />
Tanya Janca<br />
Victoria, Canada<br />
https://twitter.com/shehackspurple<br />
https://www.linkedin.com/in/tanya-janca<br />
<br />
Tanya Janca, aka SheHacksPurple, is the best-selling author of 'Alice and Bob Learn Secure Coding', 'Alice and Bob Learn Application Security’ and the ‘AppSec Antics’ card game. Over her 28-year IT career she has won countless awards (including OWASP Lifetime Distinguished Member and Hacker of the Year), spoken all over the planet, and is a prolific blogger. Tanya has trained thousands of software developers and IT security professionals, via her online academies (We Hack Purple and Semgrep Academy), and her live training programs. Having performed counter-terrorism, led security for the 52nd Canadian general election, developed or secured countless applications, Tanya Janca is widely considered an international authority on the security of software.<br />
<br />
Neil Smithline<br />
<br />
Neil Smithline has been an OWASP Top 10 Co-Leader since 2016, driving development of the globally recognized security standard through multiple release cycles. With 25 years in application security, he has created numerous application security programs at companies ranging from startups to well-established enterprises.For the past 7 years, Neil has been focusing on running security programs for cryptocurrency companies. He created and led the security program at the Poloniex cryptocurrency exchange and is now contracting as the lead for two startup crypto companies.<br />
<br />
Brian Glas<br />
Union University<br />
Department Chair and Assistant Professor of Computer Science and Cybersecurity<br />
Jackson, TN<br />
https://pgsecurityadvisors.com/blog<br />
https://twitter.com/infosecdad<br />
<br />
Brian Glas has worked in IT for 25 years and in information/application security for the last two decades. He started as an enterprise Java developer, then transitioned to helping build an application security program as both tech lead and manager. He later played the role of enterprise architect and did a little incident response and reverse engineering malware for fun. Glas then spent a number of years as a consultant helping clients build AppSec programs, create/update SDLCs, and other related initiatives. He has worked on the Trustworthy Computing team at Microsoft and is now chair and assistant professor of Computer Science at Union University, building and reimagining the Computer Science and Cybersecurity programs. He has also been a co-lead for SAMM v1.1-2.0+ and the OWASP Top 10 since 2017, along with helping develop the RABET-V program to assess non-voting election technology.<br />
<br />
Managed by the OWASP® Foundation<br />
https://owasp.org/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Admin-Leitfaden: IT-Dokumentation 2025]]></title>
<description><![CDATA[Der Admin-Leitfaden: IT-Dokumentation 2025

      
      
        
          
            
                



            
          
        
              
    
  Oliver Altvater
Mo., 15.12.2025 - 11:22


            Lesen Sie im neuen Admin-Leitfaden, wie Sie IT-Dokumentation professionell um...]]></description>
<link>https://tsecurity.de/de/3159472/server/der-admin-leitfaden-it-dokumentation-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3159472/server/der-admin-leitfaden-it-dokumentation-2025/</guid>
<pubDate>Mon, 15 Dec 2025 11:30:27 +0100</pubDate>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Der Admin-Leitfaden: IT-Dokumentation 2025</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/admin-leitfaden-it-dokumentation"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Titel_Der%20Admin-Leitfaden%20IT-Dokumentation%202025.jpg?itok=EYoLz9aq" width="480" height="319" alt="Ein physisches Druckdokument als Sinnbild für die IT-Dokumentation " title="Der Admin-Leitfaden: IT-Dokumentation 2025" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/146" lang about="https://www.it-administrator.de/user/146" typeof="schema:Person" property="schema:name" datatype class="username">Oliver Altvater</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2025-12-15T11:22:00+01:00" title="Montag, Dezember 15, 2025 - 11:22" class="datetime">Mo., 15.12.2025 - 11:22</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Lesen Sie im neuen Admin-Leitfaden, wie Sie IT-Dokumentation professionell umsetzen: von der Basisstruktur bis zur automatisierten CMDB, inklusive Virtualisierung, Cloud und KI-Unterstützung.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/grundlagen" hreflang="en">Grundlagen</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/admin-leitfaden-it-dokumentation" rel="tag" title="Der Admin-Leitfaden: IT-Dokumentation 2025" hreflang="en">Weiterlesen<span class="visually-hidden"> über Der Admin-Leitfaden: IT-Dokumentation 2025</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WhatsApp is trying to reinvent voicemail]]></title>
<description><![CDATA[WhatsApp says it's making "voicemails a thing of the past" by introducing a new feature that pretty much works like voicemail. Missed call messages are rolling out as part of WhatsApp's latest feature drop, which makes it easier for you to leave voice or video notes in chats after you've called s...]]></description>
<link>https://tsecurity.de/de/3153485/it-nachrichten/whatsapp-is-trying-to-reinvent-voicemail/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3153485/it-nachrichten/whatsapp-is-trying-to-reinvent-voicemail/</guid>
<pubDate>Thu, 11 Dec 2025 18:01:41 +0100</pubDate>
<content:encoded><![CDATA[WhatsApp says it's making "voicemails a thing of the past" by introducing a new feature that pretty much works like voicemail. Missed call messages are rolling out as part of WhatsApp's latest feature drop, which makes it easier for you to leave voice or video notes in chats after you've called someone who doesn't answer […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Escaping the transformation trap: Why we must build for continuous change, not reboots]]></title>
<description><![CDATA[BCG research has found that over 70% of digital transformations fail to meet their goals. While digital transformation leaders outperform their competitors to reap the rewards, the typical digital transformation effort flounders on the sheer complexity of using technology to increase a company’s ...]]></description>
<link>https://tsecurity.de/de/3153211/it-security-nachrichten/escaping-the-transformation-trap-why-we-must-build-for-continuous-change-not-reboots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3153211/it-security-nachrichten/escaping-the-transformation-trap-why-we-must-build-for-continuous-change-not-reboots/</guid>
<pubDate>Thu, 11 Dec 2025 16:04:41 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>BCG research has found that over <a href="https://www.afr.com/technology/five-ways-to-beat-the-odds-on-digital-transformation-20230905-p5e26o" target="_blank" rel="nofollow">70% of digital transformations fail to meet their goals</a>. While digital transformation leaders outperform their competitors to reap the rewards, the typical digital transformation effort <a href="https://www.bain.com/insights/orchestrating-a-successful-digital-transformation/" target="_blank" rel="nofollow">flounders on the sheer complexity of using technology to increase a company’s speed and learning at scale.</a>   As initiatives become increasingly complex, the likelihood of a successful outcome goes down.</p>



<p>The reason lies in a growing paradox: technology is advancing exponentially, but the enterprise’s ability to change remains largely fixed. Each new wave of innovation accelerates faster than organizational structures, governance and culture can adapt, creating a widening gap between the speed of technological progress and the pace of enterprise evolution.</p>



<p>Each new wave of innovation demands faster decisions, deeper integration and tighter alignment across silos.  Yet, most organizations are still structured for linear, project-based change. As complexity compounds, the gap between what’s possible and what’s operationally sustainable continues to widen.</p>



<p>The result is a growing <em>adaptation gap</em> — the widening distance between the speed of innovation and the enterprise’s capacity to absorb it. CIOs now sit at the fault line of this imbalance, confronting not only relentless technological disruption but also the limits of their organizations’ ability to evolve at the same pace. The underlying challenge isn’t adopting new technology; it’s architecting enterprises capable of continuous adaptation.</p>



<h2 class="wp-block-heading">The innovation paradox</h2>



<p>Ray Kurzweil’s <a href="https://en.wikipedia.org/wiki/The_Law_of_Accelerating_Returns" target="_blank" rel="nofollow">Law of Accelerating Returns</a> tells us that innovation compounds. Each breakthrough accelerates the next, shrinking the interval between waves of disruption. Where the move from client–server to cloud once took years, AI and automation now reinvent business models in months. Yet most enterprises remain structured around quarterly cycles, annual plans and five-year strategies — linear rhythms in an exponential world.</p>



<p>This mismatch between accelerating innovation and a slow organizational metabolism is the Transformation Trap. It emerges when the enterprise’s capacity to adapt is constrained by a legacy architecture, culture and governance designed for control rather than learning, and accumulated debt that slows down reinvention.</p>



<h2 class="wp-block-heading">3 structural fault lines</h2>



<h3 class="wp-block-heading">1. Outpaced architecture</h3>



<p>Most enterprises were built around periodic reboots aligned to <a href="https://onlinelibrary.wiley.com/doi/10.1111/isj.12307" target="_blank" rel="nofollow">the renewal of new technology</a>, not continuous renewal. Legacy systems and delivery models offer stability but are not resilient to change.  When architecture is treated as documentation rather than a living capability, agility decays. Each new wave of innovation arrives before the last one stabilizes, creating fatigue rather than resilience.</p>



<h3 class="wp-block-heading">2. Compounding debt</h3>



<p><a href="https://www.cai.io/media/documents/CAI-White-Paper-Technical-Debt.pdf" target="_blank" rel="nofollow">Technical debt has been rapidly amassing</a> in three areas: accumulated (legacy systems, brittle integrations and semantic inconsistencies that have been layered through mergers and upgrades), acquired (trade-offs leaders make in the name of speed such as mergers, platform swaps or modernization sprints that prioritize short-term delivery over long-term coherence.), and emergent (AI, automation and advanced analytics without the suitable frameworks or governance to integrate them sustainably). The result destabilizes transformation efforts. Without a coherent architectural foundation, every modernization effort simply layers new fragility atop the old.</p>



<h3 class="wp-block-heading">3. Governance built for yesterday</h3>



<p>Traditional governance models reward completion, not adaptation. They measure compliance with the plan, not readiness for change. As innovation cycles shorten, this rigidity creates blind spots, slowing reinvention even as investment increases.</p>



<h2 class="wp-block-heading">Why reboots keep failing</h2>



<p>Most modernization programs change the surface, not the supporting systems. New digital interfaces and analytics layers often sit atop legacy data logic and brittle integration models. Without rearchitecting the semantic and process foundations, the shared meaning behind data and decisions, enterprises modernize their appearance without improving their fitness.</p>



<p>As companies struggle to keep up with technology innovation, emergent debt will become an increasingly significant challenge: the cost of speed without an underlying architecture. Agile teams move fast but in isolation, creating redundant APIs, divergent data models and inconsistent semantics. Activity replaces alignment. Over time, delivery accelerates, but enterprise coherence erodes as new technologies are adopted on brittle systems.</p>



<p>Governance, meanwhile, remains static. Review boards and compliance gates were built for predictability, not velocity. They create the illusion of control but operate on a delay that makes true adaptation increasingly impossible in our accelerating world.</p>



<h2 class="wp-block-heading">The CIO’s dilemma</h2>



<p>CIOs today stand between two diverging curves: the exponential rise of technology and the linear pace of enterprise adaptation. This gap defines the Transformation Trap. It’s not about delivering more change.  It’s about building systems and structures that can evolve continuously without the start and stop of a project mindset.</p>



<p>The new question is not, ‘How do we transform again?’ but ‘How do we build so we never need to?’ That requires architectures capable of sustaining and sharing meaning across every system and process, which technologists refer to as semantic interoperability. For CIOs, it’s the ability to ensure data, workflows and AI models all speak the same language — enabling trust, agility and decision‑ready intelligence.</p>



<h2 class="wp-block-heading">CIO insight: Semantic interoperability</h2>



<p>The next era of transformation depends on shared meaning across systems. Without it, AI and analytics amplify noise instead of insight. Building semantic interoperability is not just a technical exercise.  It’s the foundation of decision trust, adaptive automation and continuous reinvention.</p>



<p>Leaders like Palantir <a href="https://dorians.medium.com/unlocking-the-power-of-palantir-foundry-18da0995af0" target="_blank" rel="nofollow">have unlocked the power of the Palantir Foundry platform</a> to demonstrate what’s possible when data from thousands of systems is unified through a shared ontology. In platforms like Foundry, meaning becomes the connective tissue that links operational reality to executive insight, enabling enterprises to reason, predict and act with confidence.</p>



<p>For CIOs, this is the next frontier: not just integrating systems but integrating <em>understanding</em>.</p>



<h2 class="wp-block-heading">5 imperatives for continuous change</h2>



<ol class="wp-block-list">
<li><strong>Make governance a living system.</strong> Governance must evolve from control to continuity. Instrument your enterprise with telemetry and policy‑as‑code guardrails that guide rather than gate. Governance should act like a gyroscope, stabilizing the course while enabling movement.</li>



<li><strong>Treat architecture as the enterprise’s metabolism.</strong> Architecture is not a static blueprint; it’s a living system that must refresh continuously. Embed architects directly in delivery teams. Evolve models and ontologies alongside code. A healthy enterprise architecture metabolizes change rather than resists it.</li>



<li><strong>Measure system fitness, not project velocity.</strong> Stop measuring completion speed and start measuring adaptability. Track how quickly your organization can absorb new technologies without needing a reboot. Key indicators include shorter time‑to‑adapt, fewer redundant integrations and higher semantic interoperability across systems.</li>



<li><strong>Cultivate a bold learning culture.</strong> Continuous change requires continuous learning. Foster a culture that rewards curiosity, experimentation and the courage to retire what no longer works. Encourage teams to test, learn and share insights quickly, turning every iteration into institutional wisdom. Boldness in adopting what works, and humility in letting go of what doesn’t, is the human engine of transformation.  Don’t neglect architectural understanding in the race to learn new technologies.</li>



<li><strong>Orchestrate intent through continuous feedback.</strong> Today’s enterprise requires constant calibration between <em>intent</em> and <em>impact</em>.  Build a feedback architecture that senses, interprets and responds in real-time — linking business objectives to operational signals and system behavior. This creates a dynamic enterprise that doesn’t just execute plans but continuously evolves its direction through insight. Feedback becomes the compass that turns movement into momentum.</li>
</ol>



<h2 class="wp-block-heading">A closing reflection</h2>



<p>Kurzweil’s law tells us the future accelerates exponentially, but enterprises still plan in straight lines. Transformation cannot remain episodic; it must become a living process of continuous design. CIOs are now the custodians of continuity, tasked with building architectures that learn, evolve and adapt at the speed of change.</p>



<p>In a world where technology doubles, only architecture that evolves continuously both semantically and operationally can endure. </p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing Saved Searches in Google Threat Intelligence (GTI) and VirusTotal (VT): Enhance Collaboration and Efficiency]]></title>
<description><![CDATA[We are excited to announce the launch of Saved Searches in Google Threat Intelligence (GTI) and VirusTotal (VT), a powerful new feature designed to streamline your threat hunting workflows and foster seamless collaboration across your security team.From Campaign to Feature: Better Search Efficien...]]></description>
<link>https://tsecurity.de/de/3150094/malware-trojaner-viren/introducing-saved-searches-in-google-threat-intelligence-gti-and-virustotal-vt-enhance-collaboration-and-efficiency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3150094/malware-trojaner-viren/introducing-saved-searches-in-google-threat-intelligence-gti-and-virustotal-vt-enhance-collaboration-and-efficiency/</guid>
<pubDate>Wed, 10 Dec 2025 11:31:59 +0100</pubDate>
<content:encoded><![CDATA[<br><p>We are excited to announce the launch of <b>Saved Searches</b> in Google Threat Intelligence (GTI) and VirusTotal (VT), a powerful new feature designed to streamline your threat hunting workflows and foster seamless collaboration across your security team.</p><div><h2>From Campaign to Feature: Better Search Efficiency</h2><p>For the last month, we’ve highlighted the critical importance of mastering search in our ongoing <b>#monthofgoogletisearch</b> campaign. We saw how security teams rely on complex, highly-tuned queries to identify threats, track adversaries, and perform deep-dive investigations.</p>This campaign emphasized a key challenge: once you craft the perfect query - a cornerstone of your investigation - it should be easy to reuse and share. Saved Searches is the direct answer to this need, turning successful, repeatable threat-hunting logic into a shared institutional asset.</div><div><br></div><div><h2>Collaboration, Simplified: Save and Share Your Queries</h2><p>With this initial launch of Saved Searches, we’re delivering two foundational capabilities that will immediately improve your team’s efficiency:</p><ol><li><b>Save Searches:</b> Instantly save any complex or frequently used query directly within GTI. This ensures your best investigative logic is always accessible, eliminating the need to rebuild queries from scratch or store them externally.</li><li><b>Share with Users:</b> Critical insights are often time-sensitive. You can now easily share your saved searches with any other user in your organization with access to GTI. Whether you’re escalating a finding or establishing a standard workflow, sharing the exact query ensures consistency and accelerates joint analysis.</li></ol>This means that a newly onboarded analyst can instantly access the expertise of senior members, and teams can maintain a unified approach to monitoring high-priority threats. It’s collaboration built right into your investigation tool.</div><div><br></div><div><h2>Get Started Today with Campaign Searches</h2>The Saved Searches feature is live now in Google Threat Intelligence and VirusTotal.<br><br>To help you hit the ground running, we have made the most impactful searches used throughout the <b>#monthofgoogletisearch</b> campaign public and available to all intelligence users! You can find these expert-crafted queries in <a href="https://www.virustotal.com/gui/saved-searches">your Saved Searches section</a> today - a perfect starting point for your investigations.<br><br><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu9WOjYRnAV4cmW_LMbBiJrICl-gzjGqsMf5wlQ6eiWBzNvra9iN8GV6MzbIrs7HAyHjxGunz-nnLad-KL2bGOTsbRU-6-whuZUbu8zxGpLHCJsYp60xkaHhd6tDOA0LrqFJfLkorie2Lpk3Qth5xMVg07akdwVixBZ9aqtwRGRcd9rdcZNv5IQQphpoRm/s1880/Screenshot%202025-12-10%2011.04.36.png"><img border="0" data-original-height="815" data-original-width="1880" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu9WOjYRnAV4cmW_LMbBiJrICl-gzjGqsMf5wlQ6eiWBzNvra9iN8GV6MzbIrs7HAyHjxGunz-nnLad-KL2bGOTsbRU-6-whuZUbu8zxGpLHCJsYp60xkaHhd6tDOA0LrqFJfLkorie2Lpk3Qth5xMVg07akdwVixBZ9aqtwRGRcd9rdcZNv5IQQphpoRm/s16000/Screenshot%202025-12-10%2011.04.36.png"></a><br><br>Start by exploring these campaign searches and then easily save and share your own complex search queries. Look for the option to Save and Share your searches to transform your investigative logic into a shared asset.<br><br><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuZyifO8h5qc-hWzkPVo2Jr5FMAZp_Zwh0PONPgaMYkrf8KU4X4MhzLcLu_P4hXEzAQMXtEI4qRd7PZuiDooEsRy-yC5bEj-sV0vdo_wQYY4xReKXunpEeIWpv8KiD5J8pNhVIZ8gQg1B21UFyyb_qAVK1PBeG_Gz4YsSNu19fYK9UcijM7R35yx-QY-6D/s1600/s-blob-v1-IMAGE-dpsBMg6pUfc.gif" imageanchor="1"><img border="0" data-original-height="839" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuZyifO8h5qc-hWzkPVo2Jr5FMAZp_Zwh0PONPgaMYkrf8KU4X4MhzLcLu_P4hXEzAQMXtEI4qRd7PZuiDooEsRy-yC5bEj-sV0vdo_wQYY4xReKXunpEeIWpv8KiD5J8pNhVIZ8gQg1B21UFyyb_qAVK1PBeG_Gz4YsSNu19fYK9UcijM7R35yx-QY-6D/s16000/s-blob-v1-IMAGE-dpsBMg6pUfc.gif"></a><br><br>This is just the first phase of enhancing search capabilities within GTI. We are committed to building on this foundation to provide even more robust tools that make your threat intelligence actionable and collaborative.<br><br>You can get more info by exploring our documentation page:</div><div><br><ul><li><a href="https://gtidocs.virustotal.com/docs/saved-searches-guide">Saved Searches documentation page</a></li></ul><ul><li><a href="https://gtidocs.virustotal.com/reference/list-saved-searches">API documentation</a></li></ul>Thank you for your feedback during the <b>#monthofgoogletisearch</b> campaign - your input directly fueled this launch. <br><br>Happy Hunting! ^_^<span><br><br></span></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS is still chasing a cohesive enterprise AI story after re:Invent]]></title>
<description><![CDATA[AWS kicked off re:Invent 2025 with a defensive urgency that is unusual for the cloud leader, arriving in Las Vegas under pressure to prove it can still set the agenda for enterprise AI.



With Microsoft and Google tightening their grip on CIOs’ mindshare through integrated AI stacks and workflow...]]></description>
<link>https://tsecurity.de/de/3148233/it-security-nachrichten/aws-is-still-chasing-a-cohesive-enterprise-ai-story-after-reinvent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3148233/it-security-nachrichten/aws-is-still-chasing-a-cohesive-enterprise-ai-story-after-reinvent/</guid>
<pubDate>Tue, 09 Dec 2025 16:06:43 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AWS kicked off re:Invent 2025 with a defensive urgency that is unusual for the cloud leader, arriving in Las Vegas under pressure to prove it can still set the agenda for enterprise AI.</p>



<p>With Microsoft and Google tightening their grip on CIOs’ mindshare through integrated AI stacks and workflow-ready agent platforms, AWS CEO <a href="https://www.linkedin.com/m/in/mattgarman" rel="nofollow">Matt Garman</a> and his lieutenants rolled out new chips, models, and platform enhancements, trying to knit the updates into a tighter pitch that AWS can still offer CIOs the broadest and most production-ready AI foundation.</p>



<p>Analysts remain unconvinced that AWS succeeded.</p>



<p>“We are closer, but not done,” said <a href="https://davidlinthicum.com/" rel="nofollow">David Linthicum</a>, independent consultant and retired chief cloud strategy officer at Deloitte.</p>



<h2 class="wp-block-heading">Big swing but off target</h2>



<p>Garman’s biggest swing, at least the one that got it “closer”, came in the form of <a href="https://www.cio.com/article/4100305/aws-offers-new-service-to-make-ai-models-better-at-work.html">Nova Forge</a>,  a new service with which <a href="https://www.cio.com/article/4098792/four-things-aws-needs-to-fix-at-reinvent-this-week.html">AWS is attempting to confront one of its strategic weaknesses</a>: the absence of a unified narrative that ties data, analytics, AI, and agents into a single, coherent pathway for enterprises to adopt.</p>



<p>It’s this cohesion that Microsoft has been selling aggressively to CIOs with its recently launched <a href="https://www.infoworld.com/article/4093181/microsoft-fabric-iq-adds-semantic-intelligence-layer-to-fabric.html">IQ set of offerings</a>.</p>



<p>Unlike Microsoft’s IQ stack, which ties agents to a unified semantic data layer, governance, and ready-made business-context tools, Nova Forge aims to provide enterprises raw frontier-model training power in the form of a toolkit to build custom models with proprietary data, rather than a pre-wired, workflow-ready AI platform.</p>



<p>But it still requires too much engineering lift to adopt, analysts say.</p>



<p>AWS is finally positioning agentic AI, <a href="https://www.infoworld.com/article/4008135/amazon-bedrock-faces-revamp-pressure-amid-rising-enterprise-demands.html%5D">Bedrock</a>, and the data layer as a unified stack instead of disconnected services, but according to Linthicum, “It’s still a collection of parts that enterprises must assemble.”</p>



<p>There’ll still be a lot of work for enterprises wanting to make use of the new services AWS introduced, said <a href="https://www.hfsresearch.com/team/philfersht/" rel="nofollow">Phil Fersht</a>, CEO of HFS Research.</p>



<p>“Enterprise customers still need strong architecture discipline to bring the parts together. If you want flexibility and depth, AWS is now a solid choice. If you want a fully packaged, single-pane experience, the integration still feels heavier than what some competitors offer,” he said.</p>



<h2 class="wp-block-heading">Powerful tools instead of turnkey solutions</h2>



<p>The engineering effort needed to make use of new features and services echoed across other AWS announcements, with the risk that they will confuse CIOs rather than simplify their AI roadmap.</p>



<p>On day two of the event, <a href="https://www.infoworld.com/article/4102632/aws-takes-aim-at-the-poc-to-production-gap-holding-back-enterprise-ai.html">Swami Sivasubramanian’s announced</a> new features across <a href="https://www.infoworld.com/article/4024311/aws-previews-agentcore-services-to-ease-ai-agent-deployment.html">Bedrock AgentCore</a>, Bedrock, and <a href="https://aws.amazon.com/sagemaker/ai/" rel="nofollow">SageMaker AI</a> to help enterprises move their agentic AI pilots to production, but still focused on providing tools that accelerate tasks for developers rather than offering “plug-and-play agents” by default, Linthicum said.</p>



<p>The story didn’t change when it came to AWS’s <a href="https://www.infoworld.com/article/4099811/aws-introduces-powers-for-ai-powered-kiro-ide.html">update</a> to vibe-coding tool <a href="https://www.infoworld.com/article/4026617/first-look-guided-code-generation-with-kiro.html">Kiro</a> or the new <a href="https://www.infoworld.com/article/4099528/aws-unveils-frontier-ai-agents-for-software-development.html">developer-focused agents</a> it introduced to simplify<a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html"> devops</a>, said <a href="https://thecuberesearch.com/analysts/paul-nashawaty/" rel="nofollow">Paul Nashawaty</a>, principal analyst at The Cube Research.</p>



<p>“AWS clearly wants to line up against <a href="https://www.infoworld.com/article/3989489/microsoft-aims-to-improve-agent-versatility-with-copilot-studio-updates.html">Copilot Studio</a> and Gemini Agents. Functionally, the gap is closing,” said Nashawaty. “The difference is still the engineering lift. Microsoft and Google simply have tighter productivity integrations. AWS is getting there, but teams may still spend a bit more time wiring things together depending on their app landscape.”</p>



<p>Similarly, AWS made very little progress toward delivering a more unified AI platform strategy. Analysts had looked to the hyperscaler to address complexity around the fragmentation of its tools and services by offering more opinionated <a href="https://www.infoworld.com/article/2259608/mlops-the-rise-of-machine-learning-operations.html">MLops</a> paths, deeper integration between Bedrock and SageMaker, and ready-to-use patterns that help enterprises progress from building models to deploying real agents at scale.</p>



<p>Linthicum was dissatisfied with efforts by AWS to better document and support the connective tissue between Bedrock, SageMaker, and the data plane. “The fragmentation hasn’t vanished,” he said. “There are still multiple ways to do almost everything.”</p>



<p>The approach taken by AWS contrasts sharply with those of Microsoft and Google to present more opinionated end-to-end stories, Linthicum said, calling out Azure’s tight integration around Fabric and Google’s around its data and Vertex AI stack.</p>



<h2 class="wp-block-heading">Build or buy?</h2>



<p>For CIOs who were waiting to see what AWS delivered before finalizing their enterprise AI roadmap, they are back at a familiar fork: powerful primitives versus turnkey platforms.</p>



<p>They will need to assess whether their teams have the architectural discipline, MLops depth, and data governance foundation to fully capitalize on AWS’s latest additions to its growing modular stack, said <a href="https://www.gartner.com/en/experts/jim-hare" rel="nofollow">Jim Hare</a>, VP analyst at Gartner.</p>



<p>“For CIOs prioritizing long-term control and customization, AWS offers unmatched flexibility; for those seeking speed, simplicity, and seamless integration, Microsoft or Google may remain the more pragmatic choice in 2026,” Hare said.</p>



<p>The decision, as so often, comes down to whether the enterprise wants to build its AI platform or just buy one.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS launches AI-enhanced security innovations at re:Invent 2025]]></title>
<description><![CDATA[At re:Invent 2025, AWS unveiled its latest AI- and automation-enabled innovations to strengthen cloud security for customers to grow their business. Organizations are likely to increase security spending from $213 billion in 2025 to $377 billion by 2028 as they…
Read more →
The post AWS launches ...]]></description>
<link>https://tsecurity.de/de/3146392/it-security-nachrichten/aws-launches-ai-enhanced-security-innovations-at-reinvent-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3146392/it-security-nachrichten/aws-launches-ai-enhanced-security-innovations-at-reinvent-2025/</guid>
<pubDate>Mon, 08 Dec 2025 20:05:47 +0100</pubDate>
<content:encoded><![CDATA[<p>At re:Invent 2025, AWS unveiled its latest AI- and automation-enabled innovations to strengthen cloud security for customers to grow their business. Organizations are likely to increase security spending from $213 billion in 2025 to $377 billion by 2028 as they…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/aws-launches-ai-enhanced-security-innovations-at-reinvent-2025/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/aws-launches-ai-enhanced-security-innovations-at-reinvent-2025/">AWS launches AI-enhanced security innovations at re:Invent 2025</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Architecting Security for Agentic Capabilities in Chrome]]></title>
<description><![CDATA[Posted by Nathan Parker, Chrome security team


Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome to keep them safe by default, and this is a responsibility we take seriousl...]]></description>
<link>https://tsecurity.de/de/3146361/it-security-nachrichten/architecting-security-for-agentic-capabilities-in-chrome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3146361/it-security-nachrichten/architecting-security-for-agentic-capabilities-in-chrome/</guid>
<pubDate>Mon, 08 Dec 2025 19:49:23 +0100</pubDate>
<content:encoded><![CDATA[<span class="byline-author">Posted by Nathan Parker, Chrome security team</span>

<p>
Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome to keep them safe by default, and this is a responsibility we take seriously. Following the <a href="https://blog.google/products/chrome/new-ai-features-for-chrome/">recent launch of Gemini in Chrome</a> and the <a href="https://www.youtube.com/watch?v=khX5-VHoYds&amp;t=206s">preview of agentic capabilities</a>, we want to share our approach and some new innovations to improve the safety of agentic browsing. 
</p>
<p>
The primary new threat facing all agentic browsers is <a href="https://storage.googleapis.com/deepmind-media/Security%20and%20Privacy/Gemini_Security_Paper.pdf">indirect prompt injection</a>. It can appear in malicious sites, third-party content in iframes, or from user-generated content like user reviews, and can cause the agent to take unwanted actions such as initiating financial transactions or exfiltrating sensitive data. Given this open challenge, we are investing in a <a href="https://security.googleblog.com/2025/06/mitigating-prompt-injection-attacks.html">layered defense</a> that includes both deterministic and probabilistic defenses to make it difficult and costly for attackers to cause harm. 
</p>
<p>
Designing safe agentic browsing for Chrome has involved deep collaboration of security experts across Google. We built on Gemini's <a href="https://deepmind.google/blog/advancing-geminis-security-safeguards/">existing protections</a> and <a href="https://storage.googleapis.com/gweb-research2023-media/pubtools/1018686.pdf">agent security principles</a> and have implemented several new layers for Chrome.
</p>
<p>
We’re introducing a<strong> user alignment critic</strong> where the agent’s actions are vetted by a separate model that is isolated from untrusted content. We’re also extending Chrome’s<strong> origin-isolation capabilities</strong> to constrain what origins the agent can interact with, to just those that are relevant to the task. Our layered defense also includes <strong>user confirmations</strong> for critical steps, <strong>real-time detection of threats</strong>, and <strong>red-teaming and response</strong>. We’ll step through these layers below.
</p>
<h3>Checking agent outputs with User Alignment Critic </h3>


<p>
The main planning model for Gemini uses page content shared in Chrome to decide what action to take next. Exposure to untrusted web content means it is inherently vulnerable to indirect prompt injection. We use techniques like <a href="https://arxiv.org/abs/2403.14720">spotlighting</a> that direct the model to strongly prefer following user and system instructions over what’s on the page, and we’ve upstreamed known attacks to train the Gemini model to avoid falling for them. 
</p>
<p>
To further bolster model alignment beyond spotlighting, we’re introducing the <em>User Alignment Critic</em> — a separate model built with Gemini that acts as a high-trust system component. This architecture is inspired partially by the <a href="https://simonwillison.net/2023/Apr/25/dual-llm-pattern/">dual-LLM pattern</a> as well as <a href="https://arxiv.org/abs/2503.18813">CaMeL research</a> from Google DeepMind.
</p>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1Sn5LE1RT2D6PyymaKQp6xGCZVhmRPE8C6E3CVeBavcvPvmSaiR34120lA8K9RyaF15RJKr5uWUN3BY2yh72iYKxyHMTjipNuM_K16Kie_Km4ZRykXqvEFgHxpRUWWJt1sayb0aLC3hI-wHSofrzC-SABFC4zSUXIQVfN0SZE8IlGEQQ5NVbFrR2DrafO/s1600/Screenshot%202025-12-08%20at%2011.06.25%E2%80%AFAM.png"><img alt="" border="0" data-original-height="619" data-original-width="1269" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1Sn5LE1RT2D6PyymaKQp6xGCZVhmRPE8C6E3CVeBavcvPvmSaiR34120lA8K9RyaF15RJKr5uWUN3BY2yh72iYKxyHMTjipNuM_K16Kie_Km4ZRykXqvEFgHxpRUWWJt1sayb0aLC3hI-wHSofrzC-SABFC4zSUXIQVfN0SZE8IlGEQQ5NVbFrR2DrafO/s1600/Screenshot%202025-12-08%20at%2011.06.25%E2%80%AFAM.png"></a></div>
<p>
<em>A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.</em>
</p>
<p>
The User Alignment Critic runs after the planning is complete to double-check each proposed action. Its primary focus is task alignment: determining whether the proposed action serves the user’s stated goal. If the action is misaligned, the Alignment Critic will veto it. This component is architected to see only metadata about the proposed action and not any unfiltered untrustworthy web content, thus ensuring it cannot be poisoned directly from the web. It has less context, but it also has a simpler job — just approve or reject an action.
</p>
<p>
This is a powerful, extra layer of defense against both goal-hijacking and data exfiltration within the action step. When an action is rejected, the Critic provides feedback to the planning model to re-formulate its plan, and the planner can return control to the user if there are repeated failures. 
</p>
<h3>Enforcing stronger security<strong> bound</strong>aries with Origin Sets </h3>


<p>
<a href="https://www.chromium.org/Home/chromium-security/site-isolation/">Site Isolation</a> and the <a href="https://web.dev/articles/same-origin-policy">same-origin policy</a> are fundamental boundaries in Chrome’s security model and we’re carrying forward these concepts into the agentic world. By their nature, agents must operate across websites (e.g. collecting ingredients on one site and filling a shopping cart on another). But if an unrestricted agent is compromised and can interact with arbitrary sites, it can create what is effectively a Site Isolation bypass. That can have a severe impact when the agent operates on a local browser like Chrome, with logged-in sites vulnerable to data exfiltration. To address this, we’re extending those principles with <em>Agent Origin Sets</em>. Our design architecturally limits the agent to only access data from origins that are related to the task at hand, or data that the user has chosen to share with the agent. This prevents a compromised agent from acting arbitrarily on unrelated origins.
</p>
<p>
For each task on the web, a trustworthy <em>gating function</em> decides which origins proposed by the planner are relevant to the task. The design is to separate these into two sets, tracked for each session:
</p>
<ul>

<li><strong>Read-only origins</strong> are those from which Gemini is permitted to consume content. If an iframe’s origin isn’t on the list, the model will not see that content.</li>

<li><strong>Read-writable origins </strong>are those on which the agent is allowed to actuate (e.g., click, type) in addition to reading from. </li>
</ul>
<p>
This delineation enforces that only data from a limited set of origins is available to the agent, and this data can only be passed on to the writable origins. This bounds the threat vector of cross-origin data leaks. This also gives the browser the ability to enforce some of that separation, such as by not even sending to the model data that is outside the readable set. This reduces the model’s exposure to unnecessary cross-site data. Like the Alignment Critic, the gating functions that calculate these origin sets are not exposed to untrusted web content. The planner can also use context from pages the user explicitly shared in that session, but it cannot add new origins without the gating function’s approval. Outside of web origins, the planning model may ingest other non-web content such as from tool calls, so we also delineate those into read-vs-write calls and similarly check that those calls are appropriate for the task.
</p>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhn_utPfIN3LdHqTraZVy33_eIQXiOgk_7PX_-iiUBIFCqp_tPCWBfYggehICWFlqLTawniPLJ0o1v5tlLgdmqDUmfs2o4lOiKHYwtrvtEuZfpWvguuAv6T9DlDpF7esoZqgSh4hu2oTWTs4ZefmhXFU6U4nfgy0EzjpuVNyAK-PTeZfDQbQArDNU9RKBYy/s1600/Screenshot%202025-12-08%20at%2011.07.42%E2%80%AFAM.png"><img alt="" border="0" data-original-height="629" data-original-width="1211" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhn_utPfIN3LdHqTraZVy33_eIQXiOgk_7PX_-iiUBIFCqp_tPCWBfYggehICWFlqLTawniPLJ0o1v5tlLgdmqDUmfs2o4lOiKHYwtrvtEuZfpWvguuAv6T9DlDpF7esoZqgSh4hu2oTWTs4ZefmhXFU6U4nfgy0EzjpuVNyAK-PTeZfDQbQArDNU9RKBYy/s1600/Screenshot%202025-12-08%20at%2011.07.42%E2%80%AFAM.png"></a></div>
<p>
<em>Iframes from origins that aren’t related to the user’s task are not shown to the model.</em>
</p>
<p>
Page navigations can happen in several ways: If the planner decides to navigate to a new origin that isn’t yet in the readable set, that origin is checked for relevancy by a variant of the User Alignment critic before Chrome adds it and starts the navigation. And since model-generated URLs could exfiltrate private information, we have a deterministic check to restrict them to known, public URLs. If a page in Chrome navigates on its own to a new origin, it’ll get vetted by the same critic.
</p>
<p>
Getting the balance right on the first iteration is hard without seeing how users’ tasks interact with these guardrails. We’ve initially implemented a simpler version of origin gating that just tracks the read-writeable set. We will tune the gating functions and other aspects of this system to reduce unnecessary friction while improving security. We think this architecture will provide a powerful security primitive that can be audited and reasoned about within the client, as it provides guardrails against cross-origin sensitive data exfiltration and unwanted actions.
</p>
<h3>Transparency and control for sensitive actions</h3>


<p>
We designed the agentic capabilities in Chrome to give the user both transparency and control when they need it most. As the agent works in a tab, it details each step in a work log, allowing the user to observe the agent's actions as they happen. The user can pause to take over or stop a task at any time. 
</p>
<p>
This transparency is paired with several layers of deterministic and model-based checks to trigger user confirmations before the agent takes an impactful action. These serve as guardrails against both model mistakes and adversarial input by putting the user in the loop at key moments.
</p>
<p>
First, the agent will require a user confirmation before it navigates to certain sensitive sites, such as those dealing with banking transactions or personal medical information. This is based on a deterministic check against a list of sensitive sites. Second, it’ll confirm before allowing Chrome to sign-in to a site via Google Password Manager – the model does not have direct access to stored passwords. Lastly, before any sensitive web actions like completing a purchase or payment, sending messages, or other consequential actions, the agent will try to pause and either get permission from the user before proceeding or ask the user to complete the next step. Like our other safety classifiers, we’re constantly working to improve the accuracy to catch edge cases and grey areas.  
</p>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBPZ9Zayd4HDUlAi_LQBhb2q5oHbDq_YuugNiGlqKL-tPYqg5wiepBk3AbhOzW51h_MY1beXC0cPaD3C9BAqUrCZAgtzh_qva_hFgl3DBF8MHivjuw3o1nJ92nbUoGDu8ExKijfFNhXaKPHnAWSg_RgO4mxwGZhYmqEQl99LtBWapWgxx1C7YyGGpJ8tGd/s1600/Screenshot%202025-12-08%20at%2011.08.40%E2%80%AFAM.png"><img alt="" border="0" data-original-height="1029" data-original-width="1029" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBPZ9Zayd4HDUlAi_LQBhb2q5oHbDq_YuugNiGlqKL-tPYqg5wiepBk3AbhOzW51h_MY1beXC0cPaD3C9BAqUrCZAgtzh_qva_hFgl3DBF8MHivjuw3o1nJ92nbUoGDu8ExKijfFNhXaKPHnAWSg_RgO4mxwGZhYmqEQl99LtBWapWgxx1C7YyGGpJ8tGd/s1600/Screenshot%202025-12-08%20at%2011.08.40%E2%80%AFAM.png"></a></div>
<p>
<em>Illustrative example of when the agent gets to a payment page, it stops and asks the user to complete the final step.  </em>
</p>
<h3>Detecting “social engineering” of agents </h3>


<p>
In addition to the structural defenses of alignment checks, origin gating, and confirmations, we have several processes to detect and respond to threats. While the agent is active, it checks every page it sees for indirect prompt injection. This is in addition to Chrome’s <a href="https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/">real-time scanning with Safe Browsing</a> and <a href="https://security.googleblog.com/2025/05/using-ai-to-stop-tech-support-scams-in.html">on-device AI</a> that detect more traditional scams. This prompt-injection classifier runs in parallel to the planning model’s inference, and will prevent actions from being taken based on content that the classifier determined has intentionally targeted the model to do something unaligned with the user’s goal. While it cannot flag everything that might influence the model with malicious intent, it is a valuable layer in our defense-in-depth.
</p>
<h3>Continuous auditing, monitoring, response </h3>


<p>
To validate the security of this set of layered defenses, we’ve built automated red-teaming systems to generate malicious sandboxed sites that try to derail the agent in Chrome. We start with a set of diverse attacks crafted by security researchers, and expand on them using LLMs following a <a href="https://storage.googleapis.com/deepmind-media/Security%20and%20Privacy/Gemini_Security_Paper.pdf">technique</a> we adapted for browser agents. Our continuous testing prioritizes defenses against broad-reach vectors such as user-generated content on social media sites and content delivered via ads. We also prioritize attacks that could lead to lasting harm, such as financial transactions or the leaking of sensitive credentials. The attack success rate across these give immediate feedback to any engineering changes we make, so we can prevent regressions and target improvements. Chrome’s auto-update capabilities allow us to get fixes out to users very quickly, so we can stay ahead of attackers.
</p>
<h3>Collaborating across the community</h3>


<p>
We have a long-standing commitment to working with the broader security research community to advance security together, and this includes agentic safety. We’ve updated our Vulnerability Rewards Program (VRP) guidelines to clarify how external researchers can focus on agentic capabilities in Chrome. We want to hear about any serious vulnerabilities in this system, and will pay up to $20,000 for those that demonstrate breaches in the <a href="https://chromium.googlesource.com/chromium/src/+/HEAD/docs/security/faq.md#ai-features">security boundaries</a>. The full details are available in <a href="https://bughunters.google.com/about/rules/chrome-friends/5745167867576320/chrome-vulnerability-reward-program-rules">VRP rules</a>.
</p>
<h3>Looking forward</h3>


<p>
The upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same rigor that has defined Chrome's security model from its inception. By extending some core principles like origin-isolation and layered defenses, and introducing a trusted-model architecture, we're building a secure foundation for Gemini’s agentic experiences in Chrome. This is an evolving space, and while we're proud of the initial protections we've implemented, we recognize that security for web agents is still an emerging domain. We remain committed to continuous innovation and collaboration with the security community to ensure Chrome users can explore this new era of the web safely.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What does Arm need to do to gain enterprise acceptance?]]></title>
<description><![CDATA[The Arm micro-architecture has enjoyed fabulous gains over the past few decades as its range expanded from embedded systems and mobile devices to cloud service providers deploying instances powered by their own brands of Arm-based chips. But enterprise use and acceptance haven’t materialized.



...]]></description>
<link>https://tsecurity.de/de/3146337/it-security-nachrichten/what-does-arm-need-to-do-to-gain-enterprise-acceptance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3146337/it-security-nachrichten/what-does-arm-need-to-do-to-gain-enterprise-acceptance/</guid>
<pubDate>Mon, 08 Dec 2025 19:36:38 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The Arm micro-architecture has enjoyed fabulous gains over the past few decades as its range expanded from embedded systems and mobile devices to cloud service providers deploying instances powered by their own brands of Arm-based chips. But enterprise use and acceptance haven’t materialized.</p>



<p>The Arm architecture was developed in 1985 by a team at Acorn Computers, a developer of microcomputers in the UK that released the first Arm chip, which was originally called the Acorn RISC Machine. Over time, Acorn’s computer business faded away, and rather than sell the processor, Arm — which was <a href="https://newsroom.arm.com/blog/arm-35-years-technology-innovation">officially founded as a company in November 1990</a> as Advanced RISC Machines — sold processor designs that licensees could modify to create a unique design.</p>



<p>For the longest time, Arm was an also-ran that barely registered in any computing capacity except for mobile and embedded. Then came the fateful decision in 2007 by Intel to decline to design a custom chip for Apple for its planned smartphone. Apple instead went with Arm for the iPhone, and the rest is history.</p>



<p>Since then, Arm has become standard issue in every smartphone and tablet on the market. It has also found some success in low-end notebooks, particularly Chromebooks. But <a href="https://www.networkworld.com/article/3959748/arm-backs-big-data-center-ambitions-with-migration-tools.html">outside of SmartNICs</a>, the enterprise remains elusive. It’s not from a lack of trying. There have been multiple efforts to sell Arm-based server chips, all of which have failed. These include:</p>



<ul class="wp-block-list">
<li><strong>Calxeda EnergyCore</strong>: Launched in 2011, Calxeda was an early pioneer in Arm servers but failed because it was a 32-bit design, not 64-bit.</li>



<li><strong>Nvidia Project Denver</strong>: A rare flop for Nvidia, it gained no traction.</li>



<li><strong>Unnamed Samsung Arm server chips</strong>: Canceled before any public release.</li>



<li><strong>AMD Seattle (Opteron A1100) and K12</strong>: Both were ultimately abandoned as AMD shifted its strategy back to x86.</li>



<li><strong>Qualcomm Centriq</strong>: Qualcomm released the Centriq 2400, a 48-core Arm server processor, but ended production shortly after launch.</li>



<li><strong>Broadcom Vulcan</strong>: Broadcom developed a competitive chip but dropped it as part of a restructuring. The IP was later picked up by Cavium and later acquired by Marvell.</li>



<li><strong>HPE Project Moonshot</strong>: These servers made it to market, but HPE has since discontinued sales of them.</li>
</ul>



<p>For its part, Arm has made significant effort to develop its <a href="https://www.networkworld.com/article/957434/arm-announces-neoverse-design-partnership.html">Neoverse architecture</a>. The Neoverse is a 64-bit design specifically for the server market. The N-series, <a href="https://www.arm.com/products/silicon-ip-cpu/neoverse/">now in its third generation</a>, is targeted at enterprise servers doing general compute workloads, and the V-series, also in its third generation, is optimized and tuned for high-performance computing and advanced analytics.</p>



<h2 class="wp-block-heading">The AMD effect</h2>



<p>A key reason so many vendors tried to succeed with Arm is because at the time, in the mid-2010s, AMD was not a viable alternative to Intel. It was struggling and had serious performance lag. OEMs and customers generally don’t like to be locked into one vendor, and there was a desire for an alternative to Intel. That led many to turn their gaze to Arm.</p>



<p>But in 2017, AMD released the Zen architecture, which was equal if not superior to the Intel architecture. Zen made AMD competitive, and it fueled an explosive rebirth for a company that was near death a few years prior.</p>



<p>AMD now has about 30% market share, while Intel suffers from a loss of technology as well as corporate leadership. Now, customers have a choice of Intel or AMD, and they don’t have to worry about porting their applications to a new platform like they would have to do if they switched to Arm.</p>



<h2 class="wp-block-heading">Analysts weigh in on Arm</h2>



<p><a href="https://www.linkedin.com/in/timcrawford/">Tim Crawford</a> sees no demand for Arm in the data center. Crawford is president of AVOA, a CIO consultancy. In his role, he talks to IT professionals all the time, but he’s not hearing much interest in Arm.</p>



<p>“I don’t see Arm really making a dent, ever, into the general-purpose processor space,” Crawford said. “I think the opportunity for Arm is special applications and special silicon. If you look at the major cloud providers, their custom silicon is specifically built to do training or optimized to do inference. Arm is kind of in the same situation in the sense that it has to be optimized.”</p>



<p>“The problem [for Arm] is that there’s not necessarily a need to fulfill at this point in time,” said <a href="https://www.linkedin.com/in/rob-enderle-03729/">Rob Enderle</a>, principal analyst with The Enderle Group. “Obviously, there’s always room for other solutions, but Arm is still going to face the challenge of software compatibility.”</p>



<p>And therein lies what may be Arm’s greatest challenge: software compatibility. Software doesn’t care (usually) if it’s on Intel or AMD, because both use the x86 architecture, with some differences in extensions. But Arm is a whole new platform, and that requires porting and testing. Enterprises generally don’t like disruption — which an architecture change would necessitate.</p>



<h2 class="wp-block-heading">Arm’s cloud success</h2>



<p>Where Arm has been successful is among hyperscale cloud service providers. Every significant player has made its own Arm-based custom CPU as a cheaper alternative to x86 CPUs. For example:</p>



<ul class="wp-block-list">
<li><strong>Graviton series from AWS</strong> is used in a broad range of AWS EC2 instances and is based on Neoverse V2 cores, offering up to 96 cores, enhanced networking, and improved price-performance for enterprise workloads.</li>



<li><a href="https://www.networkworld.com/article/4093709/cobalt-200-microsofts-next-gen-arm-cpu-targets-lower-tco-for-cloud-workloads.html"><strong>Microsoft Azure</strong> <strong>Cobalt</strong></a>is based on Ampere Altra and Neoverse designs. It’s optimized for Microsoft cloud VMs, enterprise integration, Microsoft ecosystem workloads, and hybrid scenarios.</li>



<li><strong>Google Cloud Tau T2A </strong>instances are powered by Ampere Altra (Arm Neoverse) processors, optimized for cloud-native performance.</li>



<li><strong>Alibaba Cloud ECS g8y</strong> offers Arm instances based on Neoverse, targeted at web hosting, database workloads, and more.</li>
</ul>



<p>That’s not to say that Arm has not had a victory or two. For the first time this past November, there were 18 Arm-based supercomputers on the <a href="https://www.networkworld.com/article/4099530/winners-and-losers-in-the-latest-top500-supercomputer-list.html">top 500 list of supercomputers</a> in the world. All 18 rely on the Grace CPU designed by Nvidia, which is built for high performance computing.</p>



<p>For standalone chipmakers, there are two options: Ampere Computing, which makes the Altra and Altra Max Processor specifically designed for cloud service providers; and Nvidia with the Grace processor, designed for use in tandem with its GPUs, which include the Hopper and Blackwell generations. Qualcomm is rumored to be trying yet again at a server chip, but nothing has been announced.</p>



<p>Arm’s strategy isn’t to try to take business away from the x86 market. Rather, it seeks to capture share in the cloud and eventually leverage that to get into the enterprise. It’s not trying to displace x86 where it lives; it’s trying to capture new computing areas that are mostly in the cloud where x86 has no dominance. From there, Arm hopes to work its way back into the enterprise, says <a href="https://www.linkedin.com/in/moawad/">Mohamed Awad</a>, senior vice president and general manager of the infrastructure line of business at Arm.</p>



<p>“We think that our adoption, both in the cloud and on prem, continues to accelerate as their workloads advance and become more and more modernized,” Awad says. “Our focus has been about enabling [enterprises] for hybrid-type environments, and it’s really about as they move more and more of their software stack over to a cloud-based software stack- it becomes much more attractive to them on-prem.”</p>



<p>Arm’s efforts to capture share in the cloud through cloud service providers like Amazon and Microsoft has some runway. Awad says 80% of the Fortune 500 are on AWS infrastructure, and there are more than 70,000 customers using AWS Graviton. And at AWS:reInvent last December, AWS said <a href="https://www.networkworld.com/article/3631134/graviton-progress-50-of-new-aws-instances-run-on-amazon-custom-silicon.html">50% of all EC2 instances</a> in the last few years were on Graviton.</p>



<p>But Enderle doesn’t think it will translate into Arm in the enterprise, mostly because Amazon has no incentive to sell hardware with its Graviton chip in it. “The whole point of hybrid is people who want to move workloads seamlessly between the environments, and you can’t do that with the separate processors,” he said. “Typically, you require the same platform on premise as you do in the cloud, so the migrations don’t result in breakage.”</p>



<p>Crawford said he has heard no interest from server vendors like HP, Dell, and Lenovo for a multitude of reasons. For starters, the customers aren’t asking for it. So, if the big server vendors aren’t building Arm-based servers, where do customers get them?</p>



<p>“I don’t think Arm has a place directly in the enterprise, or a product to sell specifically to the enterprise, because the enterprise is not going to create a custom platform themselves. They’re not going to build their own servers and then the operating system that sits on top of it,” Crawford said.</p>



<p>Awad said Arm is building the ecosystem around the processor similar to the way Nvidia has built a significant software ecosystem around its GPUs.</p>



<p>“If you look at what we’re doing is, our focus is on aspects of the software stack which allow developers to very quickly access whatever the underlying computer acceleration technology is that stuff like cloud AI,” he said.</p>



<p>And Arm may have been tossed a lifeline by Broadcom’s VMware, of all companies, which just announced <a href="https://www.theregister.com/2025/08/26/vmware_cloud_foundation_arm_port/">plans to port its hypervisor to the Arm platform</a>. However, this is targeted more at edge networking than data centers. Still, it’s a start.</p>



<p>In the end, Arm’s greatest challenge may be the reticence of enterprises to disrupt their servers and systems. Once you have a system operating smoothly, you don’t want to change things around without a very good reason, and while the price/performance argument that Arm has over x86 is considerable, enterprises may still be reluctant to completely turn over their data centers to a new architecture.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security highlights from AWS re:Invent 2025]]></title>
<description><![CDATA[Las Vegas this week welcomed more than 60,000 attendees for AWS re:Invent, and the message was clear: AWS wants to be the platform of choice for the agentic era. In fact, CEO Matt Garman opened the keynote describing AWS…
Read more →
The post Security highlights from AWS re:Invent 2025 appeared f...]]></description>
<link>https://tsecurity.de/de/3141749/it-security-nachrichten/security-highlights-from-aws-reinvent-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3141749/it-security-nachrichten/security-highlights-from-aws-reinvent-2025/</guid>
<pubDate>Fri, 05 Dec 2025 22:20:10 +0100</pubDate>
<content:encoded><![CDATA[<p>&lt;p&gt;Las Vegas this week welcomed more than 60,000 attendees for &lt;a href=”https://www.techtarget.com/searchcloudcomputing/conference/A-conference-guide-to-AWS-reInvent”&gt;AWS re:Invent&lt;/a&gt;, and the message was clear: AWS wants to be the platform of choice for the agentic era. In fact, CEO Matt Garman opened the keynote describing AWS…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/security-highlights-from-aws-reinvent-2025/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/security-highlights-from-aws-reinvent-2025/">Security highlights from AWS re:Invent 2025</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS re:Invent 2025: Frontier AI agents replace chatbots]]></title>
<description><![CDATA[According to AWS at this week’s re:Invent 2025, the chatbot hype cycle is effectively dead, with frontier AI agents taking their place. That is the blunt message radiating from Las Vegas this week. The industry’s obsession with chat interfaces has been replaced by a far more demanding mandate: “f...]]></description>
<link>https://tsecurity.de/de/3139297/ai-nachrichten/aws-reinvent-2025-frontier-ai-agents-replace-chatbots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3139297/ai-nachrichten/aws-reinvent-2025-frontier-ai-agents-replace-chatbots/</guid>
<pubDate>Thu, 04 Dec 2025 19:32:31 +0100</pubDate>
<content:encoded><![CDATA[<p>According to AWS at this week’s re:Invent 2025, the chatbot hype cycle is effectively dead, with frontier AI agents taking their place. That is the blunt message radiating from Las Vegas this week. The industry’s obsession with chat interfaces has been replaced by a far more demanding mandate: “frontier agents” that don’t just talk, but […]</p>
<p>The post <a href="https://www.artificialintelligence-news.com/news/aws-reinvent-2025-frontier-ai-agents-replace-chatbots/">AWS re:Invent 2025: Frontier AI agents replace chatbots</a> appeared first on <a href="https://www.artificialintelligence-news.com/">AI News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The year ahead: What will become the 3 pillars of trust in an AI-first world?]]></title>
<description><![CDATA[Today, the conversation in every boardroom is most likely centered on a single, transformative force: artificial intelligence (AI). Many see it as the engine for unprecedented growth, efficiency, and innovation. And, while this belief is justifiable, the entire revolution is being built on a frag...]]></description>
<link>https://tsecurity.de/de/3139100/it-security-nachrichten/the-year-ahead-what-will-become-the-3-pillars-of-trust-in-an-ai-first-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3139100/it-security-nachrichten/the-year-ahead-what-will-become-the-3-pillars-of-trust-in-an-ai-first-world/</guid>
<pubDate>Thu, 04 Dec 2025 17:50:59 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Today, the conversation in every boardroom is most likely centered on a single, transformative force: artificial intelligence (AI). Many see it as the engine for unprecedented growth, efficiency, and innovation. And, while this belief is justifiable, the entire revolution is being built on a fragile foundation of trust — an already fragile ground that is about to shift even further.</p>



<p>As AI systems begin to manage supply chains, deploy code, and execute financial transactions, the nature of risk changes entirely. The primary threat becomes the catastrophic cost of disruption to the intelligent systems that form the central nervous system of modern business.</p>



<p>To harness AI’s promise while mitigating its existential risks, we already know that leaders must move beyond a defensive security posture. To be effective, leaders must also fundamentally shift how they view security as a whole. They must view it as the foundation that innovation is built on, not as a barrier to progress. To do this, we, as a collective, must build a proactive strategy based on three core pillars of trust.</p>



<p><strong>1. Engineering for trust</strong></p>



<p>Trust cannot be an afterthought; it must be an <a href="https://www.paloaltonetworks.com/perspectives/is-your-ai-well-engineered-enough-to-be-trusted/">engineering outcome</a>. In the past, security was often a gate that slowed progress. Today, that model is inverted. A modern, unified security platform with trust built in by design now serves as a powerful strategic accelerator.</p>



<p>Automated security, when treated as a native component of the AI development lifecycle, eliminates the traditional brakes on progress. This enables our teams to innovate and deploy new models with the speed and confidence that delivers a direct, quantifiable competitive advantage. This transition from a reactive posture to one that ensures innovation velocity is key.</p>



<p>The “engineering for trust” approach also allows us to address a silent liability plaguing many organizations: decades of accumulated <a href="https://www.paloaltonetworks.com/perspectives/beyond-the-backlog-escaping-application-security-debt-with-aspm/" rel="sponsored">security debt</a>. A patchwork of disconnected point products creates a complex and vulnerable attack surface, a problem now amplified by the cloud. Our exclusive <a href="https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report#:~:text=In%202025%2C%20organizations%20face%20a,consistent%20%E2%80%94%20and%20higher%20%E2%80%94%20payments." rel="sponsored">internal research</a> found that a majority of cloud databases related to AI development are not properly secured, lacking basic encryption or access controls.</p>



<p>Moving to a unified, trustworthy platform is akin to refinancing this debt — a solution that any board member would be amenable to. This type of platform simplifies operations, reduces long-term risk, and frees up our most valuable resources to focus on growth instead of just defense.</p>



<p><strong>2. Cultivating cultures of trust</strong></p>



<p>A single human error can undermine even the most perfectly engineered system. While technology provides the foundation, a vigilant and <a href="https://www.paloaltonetworks.com/perspectives/why-culture-is-the-first-line-of-defense-in-the-age-of-agentic-ai/">security-conscious culture</a> forms the crucial human layer of the trust stack.</p>



<p>In an era of AI-powered phishing and sophisticated social engineering, every employee must become a steward of their organization’s security. This challenge is magnified by the rise of <a href="https://www.paloaltonetworks.com/blog/2025/06/genais-impact-surging-adoption-rising-risks/" rel="sponsored">shadow AI</a>. Our <a href="https://start.paloaltonetworks.com/Omdia-state-of-workforce-security" rel="sponsored">latest research</a> on SaaS risks reveals that the use of unsanctioned third-party AI tools in the enterprise has skyrocketed, creating a massive blind spot where sensitive corporate data is regularly fed into untrusted models. That is why this pillar demands more than annual training videos. It requires a deep-seated culture of awareness where people are empowered to question anomalies and act as the first line of defense.</p>



<p>The value of this culture extends far beyond risk mitigation. A strong culture provides the ethical guardrails that ensure AI is used responsibly, protecting the brand and maintaining customer confidence that is so difficult to earn and so easy to lose. Its essential, human-driven process protects the organization from the inside out.</p>



<p><strong>3. Governing for trust</strong></p>



<p>The speed and scale of modern AI demand a <a href="https://www.paloaltonetworks.com/perspectives/the-ai-imperative-security-designed-for-trust-control-and-cooperation/">new governance model</a> built on two key principles: unwavering human control and radical industry-wide cooperation.</p>



<p>First, we must design systems that guarantee human oversight. Robust, human-in-the-loop governance is the ultimate safeguard against the catastrophic business disruption that autonomous systems could otherwise trigger. It is the board-level guarantee that our most valuable tools remain under our command, operating as intended.</p>



<p>Second, we must recognize that we cannot face this new threat landscape alone. AI-powered attacks are an ecosystem-wide problem that demands an ecosystem-wide defense. Sharing threat intelligence and best practices across companies and industries is a core business necessity for our collective survival and stability.<br><br></p>



<p><strong>Trust as the ultimate ROI</strong></p>



<p>To lead in the age of AI, our strategy must be clear. We need well-engineered systems that accelerate the business, a vigilant culture that protects it, and a robust governance that ensures its resilience. The goal of a modern security strategy has fundamentally changed, shifting from merely preventing incidents to actively creating and protecting value.</p>



<p>In the AI-first world, thriving organizations will understand that trust is the most valuable asset on their balance sheet and the ultimate driver of their success.</p>



<p>Curious what else Ben has to say? Check out his other articles on <a href="https://www.paloaltonetworks.com/perspectives/author/ben-hasskamp/">Perspectives</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Here’s Everything AWS Announced at re:Invent 2025]]></title>
<description><![CDATA[Amazon unveiled 50+ AI updates at re:Invent, including new Nova models, autonomous agents, Bedrock upgrades, and cutting-edge Trainium hardware.
The post Here’s Everything AWS Announced at re:Invent 2025 appeared first on eWEEK.]]></description>
<link>https://tsecurity.de/de/3137541/it-nachrichten/heres-everything-aws-announced-at-reinvent-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3137541/it-nachrichten/heres-everything-aws-announced-at-reinvent-2025/</guid>
<pubDate>Thu, 04 Dec 2025 06:47:00 +0100</pubDate>
<content:encoded><![CDATA[<p>Amazon unveiled 50+ AI updates at re:Invent, including new Nova models, autonomous agents, Bedrock upgrades, and cutting-edge Trainium hardware.</p>
<p>The post <a href="https://www.eweek.com/news/aws-reinvent-2025-roundup-neuron/">Here’s Everything AWS Announced at re:Invent 2025</a> appeared first on <a href="https://www.eweek.com/">eWEEK</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to get AI agent budgets right in 2026]]></title>
<description><![CDATA[With the end of the year around the corner, I’ve been hearing a common refrain from enterprise IT and transformation leaders: “What budget should I allocate for AI agents in 2026?” The question comes as no surprise. While the rest of their organization might be winding down for the holidays, CIOs...]]></description>
<link>https://tsecurity.de/de/3136715/it-security-nachrichten/how-to-get-ai-agent-budgets-right-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3136715/it-security-nachrichten/how-to-get-ai-agent-budgets-right-in-2026/</guid>
<pubDate>Wed, 03 Dec 2025 18:20:54 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With the end of the year around the corner, I’ve been hearing a common refrain from enterprise IT and transformation leaders: “What budget should I allocate for AI agents in 2026?” The question comes as no surprise. While the rest of their organization might be winding down for the holidays, CIOs are gearing up for one of the most high-stakes planning cycles of the last decade.</p>



<p>AI agents are line items in almost every boardroom agenda. CIOs and CTOs are fielding a barrage of requests from their leadership cohort around “Where are our agents? What outcomes are we expecting? What’s the plan for next year?” According to Forrester, CIOs are set to receive <a href="https://www.forrester.com/blogs/predictions-2026-tech-leadership/" target="_blank" rel="nofollow">more budget for AI in 2026</a>, but it’s a case of more money, more problems. Next year, IT and tech leaders can expect continued business volatility and intensified pressure to justify every AI dollar is well spent.</p>



<p>As CIOs set their AI budgets, it’s worth taking a reality check: <a href="https://fortune.com/2025/08/21/an-mit-report-that-95-of-ai-pilots-fail-spooked-investors-but-the-reason-why-those-pilots-failed-is-what-should-make-the-c-suite-anxious/" target="_blank" rel="nofollow">many AI projects are still struggling to make it from pilot to production</a>, or if they do make it to production, they quickly find their use case cannot deliver the ROI they had hoped. That’s why I believe 2026 is a defining budget cycle. The organizations that select the right projects, invest in talent and capabilities and carefully consider the architecture needed to support agents at scale will build sustainable competitive advantages. As for the others? They’ll burn time and money on doomed pilots and incremental tools that offer no real business impact. To make smart bets for a critical year ahead, CIOs must start with understanding how AI agents can deliver real business outcomes instead of just excitement.</p>



<h2 class="wp-block-heading">What do customers and employees actually want from AI agents? </h2>



<p>The reason AI agents are getting board-level attention is the promise to bridge the gap between human intent and business effect through automation. Over the course of the year, I’ve consulted with hundreds of enterprise leaders seeking to transform their business with AI agents. The ones able to turn those aspirations into transformations all possessed a similar ingredient – they identified the right use cases to start with. Any CIO and any organization can get this part right.</p>



<p>So what do customers and employees <em>actually</em> want from AI agents? Almost every high-impact AI agent project I’ve seen this year boils down to the same simple concept: a user expresses an intention, and an agent takes action on their behalf to deliver an outcome. This is the paradigm that separates agentic AI from chatbots. Agents promise to go beyond just information retrieval or recommendations. That capability is valuable, no doubt, but it’s table stakes in today’s AI world. Customers and employees don’t just want responses or insights; they want assistants that can take tangible actions. They don’t just want AI to help them navigate their supply chain orders across SAP modules; they want to say “order 10 tons of product” and have their agent deliver that outcome end to end.</p>



<p>The majority of successful AI agent projects I’ve seen look just like this. Agents for internal teams focus on meaningful ways to improve productivity by empowering workers to turn complex processes into simple requests. No one, especially anyone under 30, wants to spend time learning how to point-and-click their way through a needlessly complex user interface on a SaaS platform. Forward-thinkers are building their agents to ride a layer above core products to turn intention into outcomes. The ROI in these cases is driven by cost and time savings for the business, at scale.</p>



<p>As agentic capabilities evolve, I’m increasingly seeing this same concept also being applied to AI agents that reinvent the customer experience. Look at the mortgage industry for an example. These lenders report a high drop-off rate in online mortgage applications. The reality is that mortgage applications can be quite complicated. The average applicant is often overwhelmed by financial jargon or documents they may not have readily available. If the user gets confused and steps away, odds are they won’t come back. Now, imagine replacing that with an AI agent that interacts with the core service. It can answer questions, translate complex financial terms into plain terms in real-time, save the session if needed and securely reach out for bank documents. Just a 1-2% increase in completed applications from this represents a material impact on the bottom line. That’s high-impact for the business.</p>



<h2 class="wp-block-heading">Don’t swing for the fences, just get on base </h2>



<p>As you’re allocating your budget for AI in 2026, here’s my advice: stop chasing moonshots. These vaguely scoped, overgeneralized agent dreams are often expensive, they rarely ship and they burn resources faster than they can create value. Instead, look for opportunities to hit singles and doubles. Keep your eye out for specific, high-value and outcome-driven projects that can deliver wins in months, not years. I’ll walk you through the coaching that I use with enterprise leaders planning AI projects.</p>



<p>Start with this question: What are 10 processes that are repetitive, well-documented and still being manually performed by humans? Score each one on a 1-10 scale across these three dimensions: the impact if you automated it, the risk if the project fails (where 10 is catastrophic) and the complexity to build and deploy it. The winning formula is high impact, low risk and low complexity. That’s your AI sweet spot. Aim your swings there.</p>



<p>One pharmaceutical company used this exact framework and landed on a sleeper hit: agent-based adverse event report processing. That’s not glamorous, but it freed up 40% of the team’s time that went back into actual drug discovery. In sales, I’m seeing teams use agents to create content production pipelines for outbounds, proposals and follow-ups, which helps speed up cycle times and frees reps to focus on closing deals. In financial services, agents are automating tedious back-office processes that are expensive and labor-intensive, cutting costs and reducing turnaround times by days.</p>



<h2 class="wp-block-heading">Nailing the ROI formula for AI Agents </h2>



<p>So you’ve honed in on the right projects for 2026 AI agents, now comes the hard part: the investment. This is not free; you’ve got to make tough decisions about how to appropriate the budget and how to beef up the teams that will actually go build them. But first, you need to understand something critical about the ROI formula. Return and investment mean widely different things from company to company. </p>



<p>At the enterprise scale, the value proposition for AI rests much more on increasing the bottom line. Enterprises have many more customers, opportunities for efficiency and additional sources of revenue. So even a one to two percent upside on a critical workflow, such as customer acquisition or cost reduction, can yield a material improvement to the bottom line. The scale at which enterprises operate changes the calculus for what automation flows should look like, due to the impact on their core business.</p>



<p>CIOs across the board must assemble the right team and ensure it is properly budgeted and staffed (I wrote on <a href="https://www.cio.com/article/4058647/the-talent-blueprint-for-getting-ai-agents-to-production.html">this topic</a> earlier this year). On top of that, organizations must ensure they’re building AI agents the right way. Your ROI is fundamentally dependent on your ability to scale AI agents across all different teams in your business. Without <a href="https://www.techradar.com/pro/security/ai-agents-are-fuelling-an-identity-and-security-crisis-for-organizations" target="_blank" rel="nofollow">security</a>, compliance and governance built in from the start, you can’t scale at all. You need to solve for thousands of users, each with their own permissions, and be able to trace every action the agent takes on their behalf. Build these guardrails in from day one, and your agents can become force multipliers. Otherwise, they will drown under token costs to LLMs while the projects never go beyond a prototype.</p>



<p>If 2025 was the introduction to AI agents, then 2026 will be when the winners start to emerge. The companies that break away from the pack won’t be those that talked the loudest about agents or ran the most proof-of-cycle concepts. It will be the ones who shipped them to production and saved time, made money or created new customer experiences that resonate.  The difference won’t be luck; it will come down to those who approach agents with smart design, the right use case selection and informed bets on the teams and technology to bring automation to life. The right plan could change your company’s entire trajectory.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is the new cloud: What the platform revolution teaches us about innovation]]></title>
<description><![CDATA[Artificial intelligence is the most transformative technology shift since the birth of cloud computing.



Two decades ago, cloud platforms changed how enterprises thought about infrastructure. Right now, as you’re reading this, AI platforms are changing how enterprises think about intelligence.
...]]></description>
<link>https://tsecurity.de/de/3136427/it-security-nachrichten/ai-is-the-new-cloud-what-the-platform-revolution-teaches-us-about-innovation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3136427/it-security-nachrichten/ai-is-the-new-cloud-what-the-platform-revolution-teaches-us-about-innovation/</guid>
<pubDate>Wed, 03 Dec 2025 16:50:54 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Artificial intelligence is the most transformative technology shift since the birth of cloud computing.</p>



<p>Two decades ago, cloud platforms changed how enterprises thought about infrastructure. Right now, as you’re reading this, AI platforms are changing how enterprises think about intelligence.</p>



<p>The parallels between the two are well worth highlighting. In the early 2000s, CIOs debated whether to build their own data centers or trust a shared platform like AWS. Now, 20 years on, they’re asking a similar question: should we build our own large language models, or build <em>on</em> them?</p>



<p>I believe that the lesson from the cloud era still applies. Competitive advantage comes from leveraging the platforms that already exist and innovating on top of them rather than owning the infrastructure. Let’s get into why that’s the case.</p>



<h2 class="wp-block-heading">The cloud’s first lesson: Leverage, don’t reinvent</h2>



<p>When the first generation of cloud services appeared, their broadest appeal was speed. Developers could launch applications in minutes instead of months.</p>



<p>However, while speed was the most obvious appeal here, the cloud’s real breakthrough was strategic. By handing off infrastructure management, companies could redirect their energy toward experience and innovation.</p>



<p>The enterprises that tried to replicate the “hyperscalers” by building their own clouds from scratch discovered how hard it was to keep up with the pace of platform evolution. Costs ballooned at the same time that velocity disappeared. Those who embraced the leverage model (using shared platforms as a foundation) moved faster and spent less.</p>



<p>AI is now at the same crossroads. The instinct to build proprietary models from the ground up feels familiar, but it’s no more the right move than it was with cloud. Large language models have become a new layer of digital infrastructure that is analogous to compute and storage in the cloud era. They are utilities that are powerful, scalable and continuously improving through collective use.</p>



<p>I believe that owning the plumbing no longer differentiates you, and that it never did. The question for leaders isn’t “Can we build our own model?” It’s “What unique value can we deliver by building upon one?”</p>



<h2 class="wp-block-heading">The power of open ecosystems</h2>



<p>The rise of cloud was never about one product. It was about an ecosystem that invited participation. I worked at AWS, and I can tell you that its greatest innovation was an architecture that encouraged others to build on top of it. Every API call became a building block for something new.</p>



<p>AI platforms are following the same pattern. Tools like OpenAI, Anthropic and others are offering open interfaces and SDKs that turn intelligence into an accessible service. This openness fuels compounding innovation in the form of an ecosystem that every developer, data scientist and business analyst can contribute to.</p>



<p>Enterprises that align with open ecosystems benefit from shared progress. They can experiment without owning the entire stack and move faster as the underlying technology improves. Closed systems, though, tend to stagnate. When innovation depends solely on internal capacity, growth slows, costs rise and talent disperses.</p>



<p>From what I’ve seen across my career, the future belongs to platforms that treat users as co-creators. Products and ecosystems scale exponentially because every user is also a contributor!</p>



<h2 class="wp-block-heading">The feedback flywheel</h2>



<p>Feedback is one of technology’s most underappreciated engines of progress. I remember AWS famously saying that <a href="https://www.techtarget.com/searchdatamanagement/feature/AWS-Data-Exchange-and-the-third-party-cloud-data-marketplace" target="_blank" rel="nofollow">90% of its roadmap came directly from customer requests</a>. When I was there, I saw firsthand how each improvement drove more usage, which generated more feedback, which drove more innovation.</p>



<p>AI systems are built on the same dynamic. Reinforcement learning, fine-tuning and user telemetry all feed the model’s evolution. Every query, correction or prompt becomes a signal that refines the next response.</p>



<p>This feedback flywheel is now extending into enterprise AI adoption. Each workflow, chat interaction and model output is an opportunity to learn. The organizations that intentionally design feedback loops to flow between users, data and developers evolve their systems faster than those treating AI as a static tool. The former will become industry leaders while the latter lags behind.</p>



<p>What does this look like it practice? Teams must instrument AI use cases with metrics, monitor accuracy and context, and close the loop quickly when things go wrong. Feedback is a strategy for continuous learning, not some trivial support function.</p>



<p>The most advanced AI organizations are the ones with the tightest feedback loops, not the biggest models.</p>



<h2 class="wp-block-heading">Platform thinking inside the enterprise</h2>



<p>What does all of this mean for CIOs and technology leaders? It means applying the principles of platform thinking within your own walls.</p>



<p>I tell my clients to start by viewing their enterprise <em>not </em>as a collection of systems, but as a platform others can build upon. Create reusable AI capabilities like data pipelines, governance frameworks and integration patterns that different business units can safely leverage. Encourage decentralized innovation by giving teams the guardrails and APIs to experiment.</p>



<p>In the cloud era, self-service infrastructure changed how developers worked. In the AI era, self-service intelligence is doing the same. Marketing teams generate insights from unstructured data, HR automates knowledge discovery for onboarding, finance uses AI-powered forecasting to model business outcomes, and so on and so forth. Each function builds on a shared foundation while adding its own flavor of domain expertise.</p>



<p>CIOs play the critical role of orchestrator. Their job is to ensure interoperability, security and ethical use while enabling freedom at the edge. That balance between control and creativity will define the next generation of enterprise leaders.</p>



<h2 class="wp-block-heading">Avoiding the reinvention trap</h2>



<p>There’s a natural temptation to build everything in-house, especially in technology-driven organizations. It feels safer and more controllable, but history shows how easily that instinct can slow progress.</p>



<p>I’ve seen enterprises that tried to build their own private clouds <a href="https://www.infra360.io/blog/managed-cloud-solutions-vs-inhouse-it/" target="_blank" rel="nofollow">fail to match the scale or speed</a> of public ones. The same is true of AI. Training proprietary models consumes extraordinary compute and talent, while the underlying platforms advance faster than any single company can replicate.</p>



<p>The smarter move is to differentiate at the application layer through data strategy, user experience and domain-specific integration. Build the intelligence that understands your business while also relying on established platforms for the generic cognition that everyone needs.</p>



<p>The organizations that thrive will be those that orchestrate AI across their ecosystems, not those that try to reinvent it in isolation.</p>



<h2 class="wp-block-heading">The leadership imperative</h2>



<p>AI represents a once-in-a-generation shift. However, like every major shift before it, the winners will be those who learn the right lessons from history.</p>



<p>The cloud taught us that leverage beats ownership, ecosystems beat silos and feedback beats static roadmaps. AI simply brings those lessons into a new domain.</p>



<p>For CIOs and senior technology leaders, the mandate is clear: build architectures that learn and that use open ecosystems to accelerate progress. Make feedback a cultural habit instead of an afterthought. Focus your talent on solving unique business problems instead of replicating what the platforms already provide.</p>



<p>The question isn’t whether AI will transform your enterprise; it already is. The question is whether you’ll build on the right platform to make that transformation sustainable, ethical and fast.</p>



<p>I believe that the future belongs to leaders who understand that innovation is about what you enable, not ‘just’ about what you own.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities]]></title>
<description><![CDATA[AWS and cybersecurity vendors have made several announcements at the cloud giant’s re:Invent 2025 event.  The post re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities  appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3135797/it-security-nachrichten/reinvent-2025-aws-and-security-vendors-unveil-new-products-and-capabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135797/it-security-nachrichten/reinvent-2025-aws-and-security-vendors-unveil-new-products-and-capabilities/</guid>
<pubDate>Wed, 03 Dec 2025 12:20:57 +0100</pubDate>
<content:encoded><![CDATA[<p>AWS and cybersecurity vendors have made several announcements at the cloud giant’s re:Invent 2025 event.  The post re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities  appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/reinvent-2025-aws-and-security-vendors-unveil-new-products-and-capabilities/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/reinvent-2025-aws-and-security-vendors-unveil-new-products-and-capabilities/">re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities ]]></title>
<description><![CDATA[AWS and cybersecurity vendors have made several announcements at the cloud giant’s re:Invent 2025 event. 
The post re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities  appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3135760/it-security-nachrichten/reinvent-2025-aws-and-security-vendors-unveil-new-products-and-capabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135760/it-security-nachrichten/reinvent-2025-aws-and-security-vendors-unveil-new-products-and-capabilities/</guid>
<pubDate>Wed, 03 Dec 2025 12:05:43 +0100</pubDate>
<content:encoded><![CDATA[<p>AWS and cybersecurity vendors have made several announcements at the cloud giant’s re:Invent 2025 event. </p>
<p>The post <a href="https://www.securityweek.com/reinvent-2025-aws-and-security-vendors-unveil-new-products-and-capabilities/">re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities </a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s lack of ROI is down to leadership, not tech]]></title>
<description><![CDATA[The increasing hype around AI has exceeded any other technology shift, perhaps ever. This has been met with a corresponding amount of investment. Gartner estimates worldwide spending on AI through 2025 will be nearly $1.5 trillion. Despite the staggering amount, most organizations continue to gra...]]></description>
<link>https://tsecurity.de/de/3135651/it-security-nachrichten/ais-lack-of-roi-is-down-to-leadership-not-tech/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135651/it-security-nachrichten/ais-lack-of-roi-is-down-to-leadership-not-tech/</guid>
<pubDate>Wed, 03 Dec 2025 11:20:19 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The increasing hype around AI has exceeded any other technology shift, perhaps ever. This has been met with a corresponding amount of investment. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-09-17-gartner-says-worldwide-ai-spending-will-total-1-point-5-trillion-in-2025" rel="nofollow">Gartner estimates</a> worldwide spending on AI through 2025 will be nearly $1.5 trillion. Despite the staggering amount, most organizations continue to grapple with a chronic gap between promise and realized value.</p>



<p>The most widely recognized data point to support this comes from an <a href="https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf" rel="nofollow">MIT report</a> from earlier this year that reveals 95% of gen AI pilots fail. A <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/seizing-the-agentic-ai-advantage" rel="nofollow">McKinsey study</a> also found that nearly 80% of companies use gen AI, yet almost as many report no significant impact to the bottom line.</p>



<p>But there’s proof AI is working, if modestly. The <a href="https://www.cisco.com/c/dam/m/en_us/solutions/ai/readiness-index/2025-m10/documents/cisco-ai-readiness-index-2025-realizing-the-value-of-ai.pdf" rel="nofollow">2025 Cisco AI Readiness Index</a> shows 13% of all companies get consistently measurable returns from AI. So while this is a minority, leading organizations are starting to see value. But the origins of that value increasingly stem from leadership clarity, strategic alignment, and execution, not the technology itself. The Cisco AI Readiness Index measured this and found 99% of companies that have realized value from AI have a well-defined strategy that embraces change, and includes formal programs to help employees get comfortable with the new technology.</p>



<p>Today’s CEOs and CIOs face a generational inflection point. They must redefine success for AI not as a means of cost-cutting, but as a driver for capacity creation, innovation, and human-centric outcomes. The path forward requires breaking down work, reassessing where automation helps, and empowering talent to focus on growth and transformation.</p>



<h2 class="wp-block-heading">Setting the stage: AI promise vs. reality</h2>



<p>Among many CIOs, the biggest challenge is the C-Suite and board know they need AI but aren’t sure what for. This creates unrealistic expectations that AI will be a panacea to all problems and send productivity skyrocketing. When the outcomes are unrealistic, a successful project may be deemed unsuccessful because the initial goals were incorrect. A contributing factor to this problem is that many business units don’t have the KPIs to create the business metrics to measure.</p>



<p>An example of this is with contact centers where AI agents could be used for agent coaching, <a href="https://www.cio.com/article/4033097/is-ai-the-end-of-it-as-we-know-it.html?utm=hybrid_search">virtual agents</a>, scheduling, scoring calls, note taking and more. Measuring the value of these can be difficult, so many businesses have defaulted to cutting costs by reducing agents. This can backfire if not done in a measured way. Klarna, for instance, eliminated about 700 agents, saw customer service scores tank, and then hired people back. This wasn’t a technology problem but rather leadership didn’t put the right plan in place to understand the impact.</p>



<h2 class="wp-block-heading">Diagnosing the problem: Tech limitations or leadership gaps?</h2>



<p>Issues with achieving ROI on AI and <a href="https://www.cio.com/article/3848260/how-automation-forges-a-sense-of-community-and-purpose-at-6sense.html?utm=hybrid_search">automation technology efforts</a> are often confused with the diagnosis of the issue at hand. A lack of tech readiness concerning integrating complex data and scaling automation remains a challenge. More often than not, however, the issue that gets acted upon may be less with the technology itself and more with the way technology efforts are governed and led. This would indicate the obstacles that exist to technology’s successful implementation lie more with the board than the code and cloud setup. Failures happen because business leaders prioritize expediency driven by market hype instead of thinking about genuine business transformation.</p>



<p>It’s also important that prior to AI projects being kicked off, there’s clear business alignment and an understanding of the metrics being measured to calculate ROI. Projects launched as isolated technology experiments without a well-defined business case tied to a strategic priority are hard to measure and often vague in value, leading to projects that are easy to cut.</p>



<h2 class="wp-block-heading">The leadership inflection point: Beyond cost cutting</h2>



<p>The business world sits at a leadership inflection point where for the first time, workforce transformation will be more than just human. With the rapid adoption of AI and autonomous agents, leaders now face complex decisions about how value is derived and maintained within their organizations. This shift requires cutting costs but also reimagining the relationship between human skills and the technical capabilities of AI, which ensures organizational cultures and processes can adapt to this new era of hybrid workforces.</p>



<p>“Everyone’s been racing to build more AI models, compute, and agents, but the real bottleneck to enterprise AI adoption isn’t supply, it’s that enterprises don’t know where or how to use AI to do real work,” says Greg Shewmaker, CEO of enterprise intelligence company <a href="https://rpotential.ai/" rel="nofollow">r.Potential</a>. “We believe the missing piece is the coordination layer between human and digital work, where you can capture actual workforce demand, generate realistic and deployable configurations of human and AI capabilities, and tie them to real business outcomes. If we don’t get this right, the next wave of automation won’t just reshape companies, it’ll destabilize work itself.” </p>



<p>His point underscores what many executives miss: AI’s promise isn’t just a technological or operational challenge, it’s an existential leadership one. As the boundaries blur between tasks suited for humans and those automated by machines, IT and business leaders will need to focus on maximizing value creation through deep integration of people, technology, and culture.​</p>



<p>So it becomes critical for the C-suite to reconsider timelines related to investments and expand capacity in accordance with tech and market needs. This shift in human capital management involves being able to forecast the future workforce and deploy human resources in sync with machine-based intelligence. Innovation should take precedence that’s less about adding to current performance and more about ensuring organizations can remain agile and ready to facilitate innovation in terms of related infrastructure and preparedness to reinvent themselves.</p>



<h2 class="wp-block-heading">Breaking down work and value creation</h2>



<p>Understanding the key components of work is essential to developing understandable ROI from AI. Any returns must consider the adoption of technology and the transformation of processes. The goal should be to leverage AI to amplify human effort in areas that require human judgment, empathy, and creativity rather than in areas where there’s only repetition of tasks, thereby assigning human resources to higher-value supervisory and human roles where they can be most productive and valuable.</p>



<p>The key to success is to refocus on enabling talent to drive revenue growth and innovation through AI. So the goal is to apply AI strategically to liberate <a href="https://www.cio.com/article/4034321/skills-and-the-ai-ready-organization-four-things-to-consider.html?utm=hybrid_search">highly-skilled people</a> from working on the 80% of any job that can, should, and must be automated so they can focus on the last 20%, which drives new revenue growth, customer loyalty, and innovation breakthroughs.</p>



<p>The AI era will reshape every industry, and if CIOs and CEOs aren’t evolving, the AI investment will be wasted. The key to realizing real value in AI is to ensure leadership is future-ready and embraces new skills and change. It’s not about being the best coder in the room but instilling the right leadership structure. This involves a leadership mentality that uses AI to further human-centric goals and not simply fill an operational spreadsheet with AI data. This requires strict ethics and governance modeled in every aspect of decision-making, and firm alignment on the business side where every AI project has a defined purpose for the organization.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fortinet at AWS re:Invent 2025: Expanding What’s Possible in Cloud Security]]></title>
<description><![CDATA[At AWS re:Invent, Fortinet is proud to support several key AWS launches that make securing the cloud simpler, smarter, and more integrated than ever.        This article has been indexed from Industry Trends & Insights Read the original article: Fortinet…
Read more →
The post Fortinet at AWS re:I...]]></description>
<link>https://tsecurity.de/de/3133838/it-security-nachrichten/fortinet-at-aws-reinvent-2025-expanding-whats-possible-in-cloud-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3133838/it-security-nachrichten/fortinet-at-aws-reinvent-2025-expanding-whats-possible-in-cloud-security/</guid>
<pubDate>Tue, 02 Dec 2025 17:36:06 +0100</pubDate>
<content:encoded><![CDATA[<p>At AWS re:Invent, Fortinet is proud to support several key AWS launches that make securing the cloud simpler, smarter, and more integrated than ever.        This article has been indexed from Industry Trends &amp; Insights Read the original article: Fortinet…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fortinet-at-aws-reinvent-2025-expanding-whats-possible-in-cloud-security/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fortinet-at-aws-reinvent-2025-expanding-whats-possible-in-cloud-security/">Fortinet at AWS re:Invent 2025: Expanding What’s Possible in Cloud Security</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Computer maker HP to cut up to 6,000 jobs by 2028 as it turns more to AI]]></title>
<description><![CDATA[US firm says plan to speed up product development and improve customer satisfaction would save $1bn a yearUp to 6,000 jobs are to go at HP worldwide in the next three years as the US computer and printer maker increasingly adopts AI to speed up product development.Announcing a lower-than-expected...]]></description>
<link>https://tsecurity.de/de/3121461/it-nachrichten/computer-maker-hp-to-cut-up-to-6000-jobs-by-2028-as-it-turns-more-to-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3121461/it-nachrichten/computer-maker-hp-to-cut-up-to-6000-jobs-by-2028-as-it-turns-more-to-ai/</guid>
<pubDate>Wed, 26 Nov 2025 12:31:26 +0100</pubDate>
<content:encoded><![CDATA[<p>US firm says plan to speed up product development and improve customer satisfaction would save $1bn a year</p><p>Up to 6,000 jobs are to go at HP worldwide in the next three years as the US computer and printer maker increasingly adopts AI to speed up product development.</p><p>Announcing a lower-than-expected profit outlook for the coming year, <a href="https://www.hp.com/us-en/newsroom/press-releases/2025/hp-inc-reports-fiscal-2025-full-year-and-fourth-quarter-results.html#:~:text=Reports%20Fiscal%202025%20Full%20Year%20and%20Fourth%20Quarter%20Results,-November%2025%2C%202025&amp;text=HP%20Inc.%20and%20its%20subsidiaries,from%20the%20prior-year%20period.">HP said it would cut</a> between 4,000 and 6,000 jobs by the end of October 2028. It has about 56,000 employees. The news drove its shares lower by 6%.</p> <a href="https://www.theguardian.com/business/2025/nov/26/computer-maker-hp-to-cut-up-to-6000-jobs-by-2028-as-it-turns-more-to-ai">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apstra founder launches Aria to tackle AI networking performance]]></title>
<description><![CDATA[There are a growing number of networking startups working to tackle the challenges of AI networking. Aria Networks is hoping that its differentiated approach based on rich network telemetry will actually solve real-world problems for network operators.



Mansour Karam, founder and CEO of Aria Ne...]]></description>
<link>https://tsecurity.de/de/3117376/it-security-nachrichten/apstra-founder-launches-aria-to-tackle-ai-networking-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3117376/it-security-nachrichten/apstra-founder-launches-aria-to-tackle-ai-networking-performance/</guid>
<pubDate>Mon, 24 Nov 2025 15:51:28 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There are a growing number of networking startups working to tackle the challenges of AI networking. <a href="https://arianetworks.com/">Aria Networks</a> is hoping that its differentiated approach based on rich network telemetry will actually solve real-world problems for network operators.</p>



<p><a href="https://www.linkedin.com/in/mansourkaram/">Mansour Karam</a>, founder and CEO of Aria Networks, is no stranger to the world of creating networking startups that disrupt the existing market. Karam spent nearly two decades building his networking credentials. He joined Arista in 2006 during the company’s early days and later spent several years at<a href="https://www.networkworld.com/article/968372/arista-snatches-up-sdn-pioneer-big-switch-networks.html"> Big Switch Networks</a> during the initial SDN wave. Karam also founded intent-driven networking vendor Apstra to reinvent the management and operational layer for networks; Apstra was<a href="https://www.networkworld.com/article/969406/juniper-reinforces-its-intent-based-networking-with-apstra-buy.html"> acquired by Juniper Networks</a> in 2020.</p>



<p>While SDN and intent-driven networking represented disruptive innovations in their time, AI is reshaping how networking architectures are designed and deployed today. <a href="https://www.networkworld.com/article/4087534/buyers-guide-to-ai-networking-technology.html">AI networking</a> represents more than an incremental shift. The backend Ethernet networks connecting GPU clusters have different requirements than traditional cloud infrastructure. </p>



<p>“If the network isn’t performing optimally, then you can’t utilize your GPUs optimally,” Karam told <em>Network World</em>. “The GPUs are extremely expensive, and they’re the ones that are generating your revenue.”</p>



<h2 class="wp-block-heading">From switch-centric to path-centric architecture</h2>



<p>Market opportunity and AI requirements are the key reasons why Karam decided to start Aria Networks. </p>



<p>He noted that overall data center networking has been growing at single-digit percentages for the past decade or two. AI networking is <a href="https://www.networkworld.com/article/3809711/high-speed-ethernet-switches-a-bright-spot-in-network-forecasts.html">changing that trajectory</a> dramatically. “When you have explosive growth like that, gaps for customers feel underserved, and really opportunities like this provide an opportunity for new entrants,” Karam said.</p>



<p>Aria’s technical approach differs from incumbent vendors in its focus on end-to-end path optimization rather than individual switch performance. Karam argues that traditional networking vendors think of themselves primarily as switch companies, with software efforts concentrated on switch operating systems rather than cluster-wide operational models.</p>



<p>“It’s no longer just about the switch itself. It’s really about the end-to-end path,” Karam explained. “When you look at these jobs being scheduled, it’s about the paths the traffic are going to take through the network, end-to-end that really matter.”</p>



<h2 class="wp-block-heading">Telemetry at microsecond resolution</h2>



<p>The company is targeting the backend Ethernet network that connects GPUs in AI clusters. It’s building with merchant silicon from Broadcom and using the open-source S<a href="https://www.networkworld.com/article/969241/meet-sonic-the-new-nos-definitely-not-the-same-as-the-old-nos.html">ONiC network operating system</a>.</p>



<p>Aria’s core differentiation centers on extracting and acting on network telemetry that already exists in modern switching silicon but remains largely untapped outside of hyperscale environments. “In order to deliver on this performance, you need the data, you need telemetry, and this telemetry today exists,” Karam explained. “If you look at these ASICs from chips like Broadcom, they have tons of telemetry at the microsecond resolution.”</p>



<p>The challenge, according to Karam, is figuring out how to effectively extract, store, process and act on the telemetry data at scale, which is something that Aria is working on delivering as part of its platform.</p>



<h2 class="wp-block-heading">Deterministic versus probabilistic network optimization</h2>



<p>Aria is not only building networking gear for AI networks but also using AI to help improve networking.</p>



<p>Karam draws a clear distinction between rule-based deterministic approaches that have been used in the past and AI-driven probabilistic methods for network optimization. “When we built my previous company with Apstra, we didn’t have AI, and so we did everything very deterministically. Everything was rule based,” Karam said. </p>



<p>That deterministic approach worked well in controlled environments but had limitations. Probabilistic AI-driven methods offer advantages for intuitive performance detection and dynamic reaction in complex scenarios. “When you’re trying to be more intuitive about detecting performance issues or reacting on the fly, then probabilistic approaches, AI, bring a unique advantage,” Karam explained.</p>



<p>But Karam emphasized that simply adding AI capabilities to existing architectures won’t deliver meaningful results. He’s critical of vendors that layer AI chatbots on top of legacy systems.</p>



<p>“A lot of what you see from a lot of vendors, when they say ‘we bring AI,’ what they’re going to do is kind of slap an AI chatbot on top of existing architecture,” Karam said. “But with AI, what we’ve seen again and again across every domain, is that in order for AI to become effective, you really need to specialize it for this domain, meaning building an architecture from the ground up that is optimized for AI.”</p>



<h2 class="wp-block-heading">More to come as the company peels back the onion</h2>



<p>Aria is taking a staged approach to revealing technical details about its platform as it continues to develop technology. The company has disclosed some of the foundational technologies it’s building on, including SONiC and microsecond telemetry, but is only incrementally revealing more details as it continues to build out.</p>



<p>“The power of AI is tremendous,” Karam said. “And having AI as a tool to bring to bear, combined with the data to really go and solve these problems and deliver on this performance optimization, the opportunity there is immense.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[My decade+ year old gaming PC's second lease on life]]></title>
<description><![CDATA[https://preview.redd.it/adal1k06iw2g1.png?width=1920&format=png&auto=webp&s=e7245b9e0a625ef9f5ae92ac82b2d1edcfc51f50 According to anaconda-ks.cfg I set my system up Mid July 2025. It's done the majority of what I need.  Every time I need something new I spend a little time looking for the best wa...]]></description>
<link>https://tsecurity.de/de/3114700/linux-tipps/my-decade-year-old-gaming-pcs-second-lease-on-life/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3114700/linux-tipps/my-decade-year-old-gaming-pcs-second-lease-on-life/</guid>
<pubDate>Sun, 23 Nov 2025 02:49:18 +0100</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://preview.redd.it/adal1k06iw2g1.png?width=1920&amp;format=png&amp;auto=webp&amp;s=e7245b9e0a625ef9f5ae92ac82b2d1edcfc51f50">https://preview.redd.it/adal1k06iw2g1.png?width=1920&amp;format=png&amp;auto=webp&amp;s=e7245b9e0a625ef9f5ae92ac82b2d1edcfc51f50</a></p> <p>According to anaconda-ks.cfg I set my system up Mid July 2025. It's done the majority of what I need. </p> <p>Every time I need something new I spend a little time looking for the best way to go about things.</p> <p>I expect this to be a long process as new needs pop up. I keep some google docs on useful commands and the setups, configs, installs I've done so I don't need to reinvent the wheel if I ever crash or start fresh.</p> <p>Free yourselves. Use old hardware. Avoid being tracked.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/NSASpyVan"> /u/NSASpyVan </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1p48sur/my_decade_year_old_gaming_pcs_second_lease_on_life/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1p48sur/my_decade_year_old_gaming_pcs_second_lease_on_life/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.18 Beta available with a few nuisance bugs being squashed]]></title>
<description><![CDATA[SteamOS 3.7.18 Beta "Old Enough to Vote" was released by Valve today, bringing in a few more fixes for some annoying sounding issues..Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3110666/linux-tipps/steamos-3718-beta-available-with-a-few-nuisance-bugs-being-squashed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3110666/linux-tipps/steamos-3718-beta-available-with-a-few-nuisance-bugs-being-squashed/</guid>
<pubDate>Thu, 20 Nov 2025 21:07:20 +0100</pubDate>
<content:encoded><![CDATA[SteamOS 3.7.18 Beta "Old Enough to Vote" was released by Valve today, bringing in a few more fixes for some annoying sounding issues.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt>.</p><p>Read the full article on <a href="https://www.gamingonlinux.com/2025/11/steamos-3-7-18-beta-available-with-a-few-nuisance-bugs-being-squashed/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Admin-Leitfaden: Disaster Recovery 2025]]></title>
<description><![CDATA[Der Admin-Leitfaden: Disaster Recovery 2025

      
      
        
          
            
                



            
          
        
              
    
  Oliver Altvater
Mo., 17.11.2025 - 11:28


            Malware, Ransomware, Fehlkonfigurationen, Cloudausfälle und mehr: Lesen Sie ...]]></description>
<link>https://tsecurity.de/de/3102176/server/der-admin-leitfaden-disaster-recovery-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3102176/server/der-admin-leitfaden-disaster-recovery-2025/</guid>
<pubDate>Mon, 17 Nov 2025 11:36:02 +0100</pubDate>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Der Admin-Leitfaden: Disaster Recovery 2025</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/admin-leitfaden-disaster-recovery"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Titelbild_Der%20Admin-Leitfaden_Disaster%20Recovery%202025.jpg?itok=Uc2U9Kqt" width="480" height="319" alt="Feuerwehrman im Einsatz, Scherenschnittprofil." title="Der Admin-Leitfaden: Disaster Recovery 2025" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/146" lang about="https://www.it-administrator.de/user/146" typeof="schema:Person" property="schema:name" datatype class="username">Oliver Altvater</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2025-11-17T11:28:00+01:00" title="Montag, November 17, 2025 - 11:28" class="datetime">Mo., 17.11.2025 - 11:28</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Malware, Ransomware, Fehlkonfigurationen, Cloudausfälle und mehr: Lesen Sie in diesem Admin-Leitfaden, wie Sie Ihre IT-Systeme nach einem Ausfall schnell, sicher und nachweisbar wiederherstellen – unabhängig der Umgebung, der Plattform und der Branche.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/grundlagen" hreflang="en">Grundlagen</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/admin-leitfaden-disaster-recovery" rel="tag" title="Der Admin-Leitfaden: Disaster Recovery 2025" hreflang="en">Weiterlesen<span class="visually-hidden"> über Der Admin-Leitfaden: Disaster Recovery 2025</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI, without fear: An open note to IT]]></title>
<description><![CDATA[If your inbox looks anything like mine, AI has gone from “my group wants to explore this interesting pilot” to “red alert, board-level priority.” Nearly 70% of Fortune 500 companies use Microsoft Copilot. Of those that partner with Integreon, many are still primarily using the browser-based versi...]]></description>
<link>https://tsecurity.de/de/3098410/it-security-nachrichten/ai-without-fear-an-open-note-to-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3098410/it-security-nachrichten/ai-without-fear-an-open-note-to-it/</guid>
<pubDate>Fri, 14 Nov 2025 13:19:12 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>If your inbox looks anything like mine, AI has gone from “my group wants to explore this interesting pilot” to “red alert, board-level priority.” <a href="https://news.microsoft.com/en-hk/2024/11/20/ignite-2024-why-nearly-70-of-the-fortune-500-now-use-microsoft-365-copilot/" target="_blank" rel="nofollow">Nearly 70% of Fortune 500 companies use Microsoft Copilot</a>. Of those that partner with Integreon, many are still primarily using the browser-based version. What that tells me is the interest is real, but the comfort level isn’t there yet.</p>



<p>Here’s the reality, my IT friends — generative AI is a strategic imperative and one we as guardians of the data and infrastructure need to be front and center. The impediment is certainly not a lack of vision; rather, it is risk-based. How IT and our partners in InfoSec choose to support, or conversely restrict, AI now will have a direct impact on the company’s ability to compete at a variety of levels and within various corporate disciplines.</p>



<p>Let’s take a collective deep breath and explore ways in which IT can be that strategic enabler, while still maintaining integrity and security. You with me?</p>



<h2 class="wp-block-heading">See AI’s value in the larger strategic context</h2>



<p>Corporate data (including legal, HR and marketing documents) <a href="https://www.komprise.com/wp-content/uploads/Komprise_IDG_GettingSmart-aboutData-Growth_07Feb2019.pdf" rel="nofollow">has been </a><a href="https://www.komprise.com/wp-content/uploads/Komprise_IDG_GettingSmart-aboutData-Growth_07Feb2019.pdf" target="_blank" rel="nofollow">growing at an exponential rate</a>. Historically, these documents required heavy manual work — drafting, reviewing, summarizing, classifying and archiving. Human capacity scales linearly, while unstructured data grows exponentially. The result? Vast amounts of untapped corporate knowledge and an increased reliance on outsourcing, which only widens the cyber and third-party risk surface.</p>



<p>AI changes this dynamic. It offers automation at scale for drafting, summarizing and classifying unstructured data — creating a generational opportunity to rearchitect enterprise data governance. We now have the potential to evolve from fragmented, federated data silos into next-generation semi-centralized architectures (data lakes, data rivers) that serve both structured and unstructured needs.</p>



<p>For IT, this is an invitation to extend capabilities into areas traditionally underserved — legal, procurement, HR, marketing — while also reducing attack surfaces and improving data quality.</p>



<h2 class="wp-block-heading">See risk in the business context</h2>



<p>Risk management should never be reduced to simply saying <em>“no”</em> to AI. Instead, IT has an opportunity — and a responsibility — to partner with business leaders in evaluating risk in proportion to the value AI delivers.</p>



<p>Generative AI and AI agents, in many ways, mirror human performance characteristics. And just as businesses have long relied on human-driven processes for critical workflows, they have also developed robust detective, corrective and compensating controls to manage risks inherent in human operations. The difference now is scale and automation — but the principles of governance remain familiar.</p>



<p>This means organizations don’t need to reinvent the wheel. Many established procedures, policies and guidelines can be modernized and extended to cover AI-driven workflows. By adapting existing governance frameworks, businesses can integrate AI more confidently without stalling innovation.</p>



<p>Equally important, when IT takes the time to understand the <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/derisking-ai-by-design-how-to-build-risk-management-into-ai-development" target="_blank" rel="nofollow">risk appetite</a> of the business, it often helps streamline end-to-end processes rather than complicate them. And when IT brings in its toolkit — such as privileged access management, single sign-on, identity governance, endpoint protection and other enterprise-grade controls — the result is not just safe adoption, but a stronger overall security posture for the organization.</p>



<p>In short: AI risk isn’t a reason to say no. It’s an invitation for IT and business to align more closely — modernizing existing controls, adapting governance and ensuring innovation happens securely and responsibly.</p>



<h2 class="wp-block-heading">Build and unify AI security and risk management infrastructure</h2>



<p>Just as we would not build security architecture one employee at a time, we should not approach AI piecemeal. IT needs to establish a holistic AI security and risk infrastructure, ready for a world where AI agents become a core part of enterprise workflows.</p>



<p>A baseline architecture should include at least these seven layers:</p>



<ol start="1" class="wp-block-list">
<li><strong>Security operations center (SOC):</strong> 24/7 threat monitoring, detection and response, including penetration testing and dark web monitoring, to provide real-time visibility and actionable insights.</li>



<li><strong>Security policy &amp; awareness:</strong> Regular, engaging training and simulations to reduce human risk and build a culture of vigilance.</li>



<li><strong>Endpoint managed detection and response (MDR):</strong> Next-gen antivirus, continuous monitoring and active remediation of endpoint threats.</li>



<li><strong>Identity protection &amp; privileged access management (PAM):</strong> Continuous monitoring of user behavior, MFA enforcement and protection against credential misuse. Enforcing least privilege, securing privileged accounts and providing auditable, monitored remote sessions.</li>



<li><strong>Vulnerability management:</strong> Ongoing asset discovery, scanning, penetration testing and prioritized remediation.</li>



<li><strong>Advanced email threat protection:</strong> AI-powered detection of phishing, ransomware and targeted attacks across inbound, outbound and internal traffic.</li>



<li><strong>Audit &amp; compliance:</strong> Alignment with globally recognized standards (ISO 27001, ISO 27701, SOC 2 Type II) to maintain transparency, governance and client trust.</li>
</ol>



<p>By combining these layers, IT can build resilience into the enterprise by design — ensuring AI adoption strengthens rather than weakens security posture.</p>



<h2 class="wp-block-heading">A strategic imperative</h2>



<p>AI isn’t just another wave of technology — it’s a shift in how we work, secure and create value. As IT leaders, we get to choose whether we slow things down or step up to help our businesses move forward with confidence.</p>



<p>If we embrace the enabler role, we don’t just keep the lights on — we shape the future. By balancing risk with strategy, modernizing our controls and building a strong foundation, we can make AI both safe and transformative.</p>



<p>At the end of the day, the future of AI in the enterprise will be written by the technologists. We have the opportunity at hand to be the ones holding the pen.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Venmo Introduces 'Venmo Stash' to Reinvent Rewards]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3089807/it-security-nachrichten/venmo-introduces-venmo-stash-to-reinvent-rewards/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3089807/it-security-nachrichten/venmo-introduces-venmo-stash-to-reinvent-rewards/</guid>
<pubDate>Mon, 10 Nov 2025 15:04:49 +0100</pubDate>
</item>
<item>
<title><![CDATA[Anzeige: Anker Solix Balkonkraftwerk zum neuen Amazon-Tiefstpreis]]></title>
<description><![CDATA[Das Anker Solix Balkonkraftwerk mit Speicher und zwei Solarpanels ist nun zum Amazon-Bestpreis erhältlich - perfekt für sonnige Ersparnisse. (Balkonkraftwerk, Technik/Hardware)]]></description>
<link>https://tsecurity.de/de/3089667/it-nachrichten/anzeige-anker-solix-balkonkraftwerk-zum-neuen-amazon-tiefstpreis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3089667/it-nachrichten/anzeige-anker-solix-balkonkraftwerk-zum-neuen-amazon-tiefstpreis/</guid>
<pubDate>Mon, 10 Nov 2025 13:45:32 +0100</pubDate>
<content:encoded><![CDATA[Das Anker Solix Balkonkraftwerk mit Speicher und zwei Solarpanels ist nun zum Amazon-Bestpreis erhältlich - perfekt für sonnige Ersparnisse. (<a href="https://www.golem.de/specials/balkonkraftwerk/">Balkonkraftwerk</a>, <a href="https://www.golem.de/specials/technik-und-hardware/">Technik/Hardware</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=202025&amp;page=1&amp;ts=1762778342" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.17 released with fixes for Baldur's Gate 3, OS Updates and Discover]]></title>
<description><![CDATA[Valve released the latest stable system update with SteamOS 3.7.17 now available bringing bug fixes, but also disables wake-on-bluetooth for Steam Deck LCD..Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3084380/linux-tipps/steamos-3717-released-with-fixes-for-baldurs-gate-3-os-updates-and-discover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3084380/linux-tipps/steamos-3717-released-with-fixes-for-baldurs-gate-3-os-updates-and-discover/</guid>
<pubDate>Thu, 06 Nov 2025 23:20:53 +0100</pubDate>
<content:encoded><![CDATA[Valve released the latest stable system update with SteamOS 3.7.17 now available bringing bug fixes, but also disables wake-on-bluetooth for Steam Deck LCD.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt>.</p><p>Read the full article on <a href="https://www.gamingonlinux.com/2025/11/steamos-3-7-17-released-with-fixes-for-baldurs-gate-3-os-updates-and-discover/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accelerate Your Cloud Journey: Meet SUSE at AWS re:Invent 2025]]></title>
<description><![CDATA[The world’s premier cloud computing event, AWS re:Invent 2025, is a critical hub for customers and partners looking to solve their most challenging IT problems in Cloud, AI, and Security. SUSE is a proud Bronze sponsor at AWS re:Invent 2025 and will be at Booth #487 from December 1–5, showcasing ...]]></description>
<link>https://tsecurity.de/de/3081576/unix-server/accelerate-your-cloud-journey-meet-suse-at-aws-reinvent-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3081576/unix-server/accelerate-your-cloud-journey-meet-suse-at-aws-reinvent-2025/</guid>
<pubDate>Wed, 05 Nov 2025 16:21:11 +0100</pubDate>
<content:encoded><![CDATA[<p>The world’s premier cloud computing event, AWS re:Invent 2025, is a critical hub for customers and partners looking to solve their most challenging IT problems in Cloud, AI, and Security. SUSE is a proud Bronze sponsor at AWS re:Invent 2025 and will be at Booth #487 from December 1–5, showcasing our latest AI-ready, resilient-by-design, and […]</p>
<p>The post <a href="https://www.suse.com/c/accelerate-your-cloud-journey-meet-suse-at-aws-reinvent-2025/">Accelerate Your Cloud Journey: Meet SUSE at AWS re:Invent 2025</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS re:Invent]]></title>
<description><![CDATA[Meet the Teramind Team at AWS re:Invent When: December 1 – 5,  2025 Where: Las Vegas, Nevada Join Teramind at AWS re:Invent to see how our behavioral analytics platform transforms security blind spots into organizational clarity. Discover cutting-edge solutions that optimize workforce productivit...]]></description>
<link>https://tsecurity.de/de/3080145/it-security-nachrichten/aws-reinvent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3080145/it-security-nachrichten/aws-reinvent/</guid>
<pubDate>Tue, 04 Nov 2025 23:04:29 +0100</pubDate>
<content:encoded><![CDATA[<p>Meet the Teramind Team at AWS re:Invent When: December 1 – 5,  2025 Where: Las Vegas, Nevada Join Teramind at AWS re:Invent to see how our behavioral analytics platform transforms security blind spots into organizational clarity. Discover cutting-edge solutions that optimize workforce productivity while proactively preventing insider threats. Book a Meeting Book a Demo What to […]</p>
<p>The post <a href="https://www.teramind.co/aws-reinvent/">AWS re:Invent</a> first appeared on <a href="https://www.teramind.co/">Teramind</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic workflows: Embracing the next wave of AI]]></title>
<description><![CDATA[Software is learning to act. Not merely to respond or execute commands, but to perceive context, reason through complexity and pursue outcomes on its own behalf. Agentic AI is the buzzword of the moment, but beneath the hype lies a meaningful shift in how organizations will work, support their te...]]></description>
<link>https://tsecurity.de/de/3078942/it-security-nachrichten/agentic-workflows-embracing-the-next-wave-of-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3078942/it-security-nachrichten/agentic-workflows-embracing-the-next-wave-of-ai/</guid>
<pubDate>Tue, 04 Nov 2025 11:48:28 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Software is learning to act. Not merely to respond or execute commands, but to perceive context, reason through complexity and pursue outcomes on its own behalf. Agentic AI is the buzzword of the moment, but beneath the hype lies a meaningful shift in how organizations will work, support their teams and make decisions in the years ahead.</p>



<p>More than a passing phase, agentic AI represents the next stage in automation’s evolution — one that moves from efficiency toward adaptability, and from static workflows toward systems that can interpret intention, collaborate with human teams and actually think and act on their own behalf. With the promise of significant increases in productivity and efficiency, it’s easy to see why.</p>



<p><a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027" target="_blank" rel="nofollow">Gartner</a> predicts that at least 15% of day-to-day work decisions will be made autonomously through agentic AI by 2028, up from 0% in 2024. Additionally, 33% of enterprise software applications are expected to include agentic AI by 2028, up from less than 1% in 2024. While this is exciting, it’s also not a one-size-fits-all solution. And before jumping in head-first, it’s a good time to weigh the benefits and challenges adopting agentic workflows will have on your own business.</p>



<h2 class="wp-block-heading">The journey from automation to agency</h2>



<p>The early days of automation were about repetition and consistency. Robotic process automation tools replaced manual data entry, basic scheduling and other repetitive tasks with rule-based scripts. This was revolutionary for its time, but it was rigid in its approach. When an input didn’t match the script, human intervention was required.</p>



<p>Over time, businesses layered intelligence onto these workflows. Machine learning allowed software to make predictions or classifications, nudging automation toward greater sophistication. Yet even then, systems remained reactive. They could respond, but they couldn’t initiate. For example, AI could flag an anomaly, but couldn’t decide whether it was significant or what to do about it.</p>



<p>Then came the generative AI era, where models could create language, images and code. Generative AI expanded what machines could produce, but not what they could decide. It generated possibilities, not priorities. The intelligence was expressive, but not yet agentic.</p>



<p>With agentic AI, we’re moving toward a phase where systems are not just reactive, but proactive. These AI agents are capable of perceiving changing conditions, reasoning through alternatives and taking action autonomously. They don’t just follow instructions, but move the needle in pursuing real business objectives. In other words, software now acts with purpose, albeit within the boundaries of human oversight.</p>



<h2 class="wp-block-heading"><a></a>What agentic AI is…and isn’t</h2>



<p>Agentic AI blends intelligence and automation into a single operational layer that can manage outcomes rather than just execute steps. Instead of relying on humans to define every possible rule, agentic systems understand goals and context. They can reason through multiple inputs, choose the best path forward and adapt as conditions change.</p>



<p>For any kind of AI, data is critical, and this level of reasoning requires memory or a data source. For agentic AI workflows to be effective for a business, the AI solution must be anchored to a deep, unified system of record that is the one source of truth reflecting what’s happening across the organization in real time. Without that data substrate, an agent is just guessing. The system of record is what gives both the AI and business operations continuity. And understanding not only what to do next, but why that action aligns with the larger mission, and keeping every teammate up to speed on what’s going on, is imperative.</p>



<p>While traditional automation in customer support might categorize a service ticket and route it to the right queue. An agentic system can triage the issue, draft a response, update records and even resolve the problem if it falls within defined guardrails. In a sales environment, it can evaluate lead quality, tailor outreach based on behavioral data and move prospects through the funnel without waiting for manual triggers.</p>



<p>The distinction is subtle but powerful. Traditional automation executes rules<em>, </em>whereas by contrast, agentic AI executes judgment<em>.</em> It doesn’t just know what to do, but actually decides how to do it, based on context and evolving information. That capacity for self-direction is what makes the technology so transformative.</p>



<p>Make no mistake, though, this is not an argument in favor of cutting staff or quitting our 9-5s in favor of agentic replacements. Human oversight is still necessary — arguably more than ever before. While tech is advancing, so are end-users’ and consumers’ awareness and scrutiny of it.</p>



<p>As such, the most responsible use of agentic AI isn’t replacement, it’s reinforcement. It’s about freeing people from procedural work so they can focus on the complex, empathetic problems that require a human touch. This is especially important in industries like real estate or healthcare, where decisions are deeply personal.</p>



<h2 class="wp-block-heading">Preparing for the age of agentic AI</h2>



<p>Optimizing for agentic AI isn’t just about adding smarter tools; it begins re-architecting the environment those tools inhabit. Organizations that thrive will have integrated, high-quality data foundations and unified workflows. Fragmented systems or poor data hygiene can cripple an AI agent’s ability to reason effectively. For many enterprises, this means modernizing their systems of record — CRMs, ERPs and HR platforms — that make up digital operations.</p>



<p>Equally important is the need for well-defined guardrails. Businesses must define what good decisions look like, the limits of an agent’s autonomy and the ethical or compliance constraints that must be followed. This balance between freedom and control is critical. Too many restrictions, and the AI can’t act usefully, but too few and it risks acting outside the organization’s intentions.  </p>



<p>Recent <a href="https://www.deloitte.com/us/en/services/consulting/blogs/ai-adoption-challenges-ai-trends.html" target="_blank" rel="noreferrer noopener">Deloitte survey findings</a> reflect this. Nearly 60% of AI leaders report their organization’s primary challenges in adopting agentic AI are integrating with legacy systems and addressing risk and compliance concerns. On the flip side, unclear use cases/business value was the top answer for other respondents. While both groups cited risk and compliance concerns as a top challenge, it’s clear there’s a divide on where employees fit into the agentic AI puzzle.</p>



<p>But if history has taught us anything, it’s that the best results are realized when people, processes and tech operate together, as one collaborative network. Organizations that excel in this next era of AI will be the ones that take this into account when deploying their AI agents.</p>



<h2 class="wp-block-heading">Why humans are a value add</h2>



<p>While much of the conversation around agentic AI centers on automation, the deeper story is about augmentation. As intelligence shifts deeper into systems, the human role moves higher in purpose. Instead of being the operators inside every workflow, people become the designers of intent. This includes defining objectives, setting ethical and operational boundaries and interpreting outcomes through the lens of business strategy.</p>



<p>This evolution will inevitably reshape roles and organizational design. Teams will shift from micromanaging workflows to supervising AI agents, curating data and optimizing performance across systems. This will require new skill sets in technical fluency and delegating meaningful work to intelligent systems. In fact, <a href="https://www.pwc.com/us/en/tech-effect/ai-analytics/ai-agent-survey.html#:~:text=sustain%20that%20success.-,Of%20the%20300%20senior%20executives%20in%20our%20May%202025%20survey,May%202025%2C%20base%20of%20308" target="_blank" rel="noreferrer noopener">recent research from PwC</a> found that 67% of executives agree that AI agents will drastically transform existing roles within the next 12 months. In fact, 48% reported they will likely increase headcount due to change brought on by AI agents.</p>



<p>The leaders who embrace this shift early will gain more than efficiency. As agentic AI learns and improves, organizations can scale decision-making without scaling headcount. They can respond to customer needs in real time, anticipate and insulate their business from market shifts, and allocate human creativity and innovation where it matters most.</p>



<h2 class="wp-block-heading">Building agentic workflows</h2>



<p>Before organizations can fully realize the value of agentic AI, they need to lay the groundwork, much like systems and data had to be centralized before reaping the benefits of automation. Deploying agentic systems without the right operational and technological foundations will only amplify inefficiencies, not eliminate them. Companies must first align people, processes and technology by ensuring that their data infrastructure is unified, their processes are standardized and their governance frameworks are mature enough to support decision-making at scale.</p>



<p>To make that transition effectively, organizations should focus on a few key steps:</p>



<ul class="wp-block-list">
<li><strong>Establish a deep system of record.</strong> Agentic AI depends on consistent, real-time access to information. Consolidating fragmented data across departments, systems and platforms ensures agents have the visibility and context to act intelligently.</li>



<li><strong>Create and enforce clear governance and ethical guardrails.</strong> Define the boundaries of agent autonomy, specifying where human oversight is required and how decisions should be audited. This builds trust and prevents rogue automation.</li>



<li><strong>Adopt orchestration layers for multi-agent collaboration.</strong> As AI systems grow, businesses will need orchestration tools that coordinate how AI agents communicate, hand off tasks to human teams and align on objectives.</li>



<li><strong>Reskill teams for AI collaboration.</strong> In agentic workflows, humans and AI don’t work in isolation, but as a team. Employees must learn how to supervise, interpret and refine agentic behavior, shifting from process execution to performance management and continuous improvement. Just as importantly, teams need to work alongside AI and pick up where it leaves off, handling the human moments that require empathy or judgment.</li>



<li><strong>Centralization first for the biggest impact. </strong>Agentic AI delivers its greatest value in organizations that have already centralized their operations — leaving behind same-store models in favor of specialized teams and shared systems. Centralization aligns people, processes and data around consistent, scalable workflows, giving AI the clarity and context it needs to act intelligently.</li>
</ul>



<p>The alignment between data clarity, centralization, governance, orchestration and human oversight is the differentiator between experimentation and transformation. And for those willing to reimagine their workflows and take the right steps, the reward can be significant — an organization that doesn’t just run efficiently, but learns and evolves continuously.</p>



<p>Agentic AI isn’t a far-off concept; it’s here. The companies optimizing for it today will be the ones with a competitive advantage in the future.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HTTPS by default]]></title>
<description><![CDATA[One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the first access to any public site without HTTPS.




The “Always Use Secure Con...]]></description>
<link>https://tsecurity.de/de/3067414/it-security-nachrichten/https-by-default/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3067414/it-security-nachrichten/https-by-default/</guid>
<pubDate>Tue, 28 Oct 2025 20:49:01 +0100</pubDate>
<content:encoded><![CDATA[<p>
One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the first access to any public site without HTTPS.
</p>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXrS0w0j-B4TjCUWdtAUto_P-3BYetTEfuqTGuGkVli-e7O92UPFEjrIQuoGKGCyDZLkkfmr9PU1MAKbU9rEp8ZPoTTuG1jkoPSzSXx2QDPxNKkXUesNJfmY9HpN1AV5bUtTd27RiSafiDEGybf0M7cDIpi4XtlhXwiZizipeR2T2t77_r34JX8y-_s2ji/s1600/Screenshot%202025-10-28%20at%2011.11.00%E2%80%AFAM.png"><img alt="" border="0" data-original-height="451" data-original-width="883" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXrS0w0j-B4TjCUWdtAUto_P-3BYetTEfuqTGuGkVli-e7O92UPFEjrIQuoGKGCyDZLkkfmr9PU1MAKbU9rEp8ZPoTTuG1jkoPSzSXx2QDPxNKkXUesNJfmY9HpN1AV5bUtTd27RiSafiDEGybf0M7cDIpi4XtlhXwiZizipeR2T2t77_r34JX8y-_s2ji/s1600/Screenshot%202025-10-28%20at%2011.11.00%E2%80%AFAM.png"></a></div>
<p>
The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS
</p>
<p>
<a href="https://chrome.security/">Chrome Security's mission</a> is to make it safe to click on links. Part of being safe means ensuring that when a user types a URL or clicks on a link, the browser ends up where the user intended. When links don't use HTTPS, an attacker can hijack the navigation and force Chrome users to load arbitrary, attacker-controlled resources, and expose the user to malware, targeted exploitation, or social engineering attacks. Attacks like this are not hypothetical—software to hijack navigations is readily available and attackers have previously used insecure HTTP to <a href="https://blog.google/threat-analysis-group/0-days-exploited-by-commercial-surveillance-vendor-in-egypt/#:~:text=exploit%20delivery%20via%20man-in-the-middle%20(mitm)">compromise user devices</a> in a targeted attack.
</p>
<p>
Since attackers only need a single insecure navigation, they don't need to worry that many sites have adopted HTTPS—any single HTTP navigation may offer a foothold. What's worse, many plaintext HTTP connections today are entirely invisible to users, as HTTP sites may immediately redirect to HTTPS sites. That gives users no opportunity to see Chrome's "Not Secure" URL bar warnings after the risk has occurred, and no opportunity to keep themselves safe in the first place.
</p>
<p>
To address this risk, we <a href="https://blog.chromium.org/2021/07/increasing-https-adoption.html">launched the “Always Use Secure Connections” setting</a> in 2022 as an opt-in option. In this mode, Chrome attempts every connection over HTTPS, and shows a bypassable warning to the user if HTTPS is unavailable. We also previously discussed our intent to move <a href="https://blog.chromium.org/2023/08/towards-https-by-default.html">towards HTTPS by default</a>. We now think the time has come to enable “Always Use Secure Connections” for all users by default.
</p>
<h2>Now is the time.</h2>


<p>
For more than a decade, Google has published the <a href="https://transparencyreport.google.com/https/overview?hl=en">HTTPS transparency report</a>, which tracks the percentage of navigations in Chrome that use HTTPS. For the first several years of the report, numbers saw an impressive climb, starting at around 30-45% in 2015, and ending up around the 95-99% range around 2020. Since then, progress has largely plateaued. 
</p>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXSN7f2wT1P2RGgK3pEEPW0Gelsge0JJ66bujFzrteRxegGfckgBc9glnCOcY6Ex5w64CKkcdjD2T3W2pDxNxMuPqMLDcnLt3qTGonkucdHnQuN8-ifXnDcbuXI7RpcdvZGv3agBBF8YrtxGLUhIIFm1jXKQFc2eC9jQHbTgT4DSovx8DJAKMhgxdi8161/s1600/Screenshot%202025-10-28%20at%2011.12.15%E2%80%AFAM.png"><img alt="" border="0" data-original-height="675" data-original-width="1329" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXSN7f2wT1P2RGgK3pEEPW0Gelsge0JJ66bujFzrteRxegGfckgBc9glnCOcY6Ex5w64CKkcdjD2T3W2pDxNxMuPqMLDcnLt3qTGonkucdHnQuN8-ifXnDcbuXI7RpcdvZGv3agBBF8YrtxGLUhIIFm1jXKQFc2eC9jQHbTgT4DSovx8DJAKMhgxdi8161/s1600/Screenshot%202025-10-28%20at%2011.12.15%E2%80%AFAM.png"></a></div>
<p>
HTTPS adoption expressed as a percentage of main frame page loads
</p>
<p>
This rise represents a tremendous improvement to the security of the web, and demonstrates that HTTPS is now mature and widespread. This level of adoption is what makes it possible to consider stronger mitigations against the remaining insecure HTTP.
</p>
<h2>Balancing user safety with friction</h2>


<p>
While it may at first seem that 95% HTTPS means that the problem is mostly solved, the truth is that a few percentage points of HTTP navigations is still <em>a lot</em> of navigations. Since HTTP navigations remain a regular occurrence for most Chrome users, a naive approach to warning on all HTTP navigations would be quite disruptive. At the same time, as the plateau demonstrates, doing nothing would allow this risk to persist indefinitely. To balance these risks, we have taken steps to ensure that we can help the web move towards safer defaults, while limiting the potential annoyance warnings will cause to users. 
</p>
<p>
One way we're balancing risks to users is by making sure Chrome does not warn about the same sites excessively. In all variants of the "Always Use Secure Connections" settings, so long as the user regularly visits an insecure site, Chrome will not warn the user about that site repeatedly. This means that rather than warn users about 1 out of 50 navigations, Chrome will only warn users when they visit a new (or not recently visited) site without using HTTPS.
</p>
<p>
To further address the issue, it's important to understand what sort of traffic is still using HTTP. The largest contributor to insecure HTTP by far, and the largest contributor to variation across platforms, is insecure navigations to <em>private</em> sites. The graph above includes both those to public sites, such as <code>example.com</code>, and navigations to private sites, such as local IP addresses like <code>192.168.0.1</code>,  single-label hostnames, and shortlinks like <code>intranet/</code>. While it is free and easy to get an HTTPS certificate that is trusted by Chrome for a public site, acquiring an HTTPS certificate for a private site unfortunately remains complicated. This is because private names are "non-unique"—private names can refer to different hosts on different networks. There is no single owner of <code>192.168.0.1</code> for a certification authority to validate and issue a certificate to.
</p>
<p>
HTTP navigations to private sites can still be risky, but are typically less dangerous than their public site counterparts because there are fewer ways for an attacker to take advantage of these HTTP navigations. HTTP on private sites can only be abused by an attacker also on your local network, like on your home wifi or in a corporate network.
</p>
<p>
If you exclude navigations to private sites, then the distribution becomes much tighter across platforms. In particular, Linux jumps from 84% HTTPS to nearly 97% HTTPS when limiting the analysis to public sites only. Windows increases from 95% to 98% HTTPS, and both Android and Mac increase to over 99% HTTPS.
</p>
<p>
In recognition of the reduced risk HTTP to private sites represents, last year we introduced a variant of “Always Use Secure Connections” for <em>public sites only</em>. For users who frequently access private sites (such as those in enterprise settings, or web developers), excluding warnings on private sites significantly reduces the volume of warnings those users will see. Simultaneously, for users who do not access private sites frequently, this mode introduces only a small reduction in protection. This is the variant we intend to enable for all users next year.
</p>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjihQPKh0xhxDHIaAhXaqpXq0chmBB9F5pdNcdRxxOlRjwzcjwaS4gZr0N9jGqXRBg8WawbCr947UV6NaOXLBYG7beCnUDW4MDeMXXP_vcJsTXIVn00VrNdtkAl8piBlwG8ScZMcoHnJRnb8JLlQp856VK5_hrpcAdh8agYa6qPZG9JNbkxhjP6Qt0UleJE/s1600/Screenshot%202025-10-28%20at%2011.14.05%E2%80%AFAM.png"><img alt="" border="0" data-original-height="446" data-original-width="1189" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjihQPKh0xhxDHIaAhXaqpXq0chmBB9F5pdNcdRxxOlRjwzcjwaS4gZr0N9jGqXRBg8WawbCr947UV6NaOXLBYG7beCnUDW4MDeMXXP_vcJsTXIVn00VrNdtkAl8piBlwG8ScZMcoHnJRnb8JLlQp856VK5_hrpcAdh8agYa6qPZG9JNbkxhjP6Qt0UleJE/s1600/Screenshot%202025-10-28%20at%2011.14.05%E2%80%AFAM.png"></a></div>
<p>
<em>“Always Use Secure Connections,” available at chrome://settings/security</em>
</p>
<p>
In Chrome 141, we experimented with enabling “Always Use Secure Connections” for public sites by default for a small percentage of users. We wanted to validate our expectations that this setting keeps users safer without burdening them with excessive warnings. 
</p>
<p>
Analyzing the data from the experiment, we confirmed that the number of warnings seen by any users is considerably lower than 3% of navigations—in fact, the median user sees fewer than one warning per week, and the ninety-fifth percentile user sees fewer than three warnings per week..
</p>
<h2>Understanding HTTP usage</h2>


<p>
Once “Always Use Secure Connections” is the default and additional sites migrate away from HTTP, we expect the actual warning volume to be even lower than it is now. In parallel to our experiments, we have reached out to a number of companies responsible for the most HTTP navigations, and expect that they will be able to migrate away from HTTP before the change in Chrome 154. For many of these organizations, transitioning to HTTPS isn't disproportionately hard, but simply has not received attention. For example, many of these sites use HTTP only for navigations that immediately redirect to HTTPS sites—an insecure interaction which was previously completely invisible to users.
</p>
<p>
Another current use case for HTTP is to avoid mixed content blocking when accessing devices on the local network. Private addresses, as discussed above, often do not have trusted HTTPS certificates, due to the difficulties of validating ownership of a non-unique name. This means most local network traffic is over HTTP, and cannot be initiated from an HTTPS page—the HTTP traffic counts as <a href="https://developer.mozilla.org/en-US/docs/Web/Security/Mixed_content">insecure mixed content</a>, and is blocked. One common use case for needing to access the local network is to configure a local network device, e.g. the manufacturer might host a configuration portal at <code>config.example.com</code>, which then sends requests to a local device to configure it.
</p>
<p>
Previously, these types of pages needed to be hosted without HTTPS to avoid mixed content blocking. However, we recently introduced a <a href="https://developer.chrome.com/blog/local-network-access">local network access permission</a>, which both prevents sites from accessing the user’s local network without consent, but also allows an HTTPS site to bypass mixed content checks for the local network once the permission has been granted. This can unblock migrating these domains to HTTPS.
</p>
<h2>Changes in Chrome </h2>


<p>
We will enable the "Always Use Secure Connections" setting in its public-sites variant <em>by default</em> in October 2026, with the release of Chrome 154. Prior to enabling it by default for all users, in Chrome 147, releasing in April 2026, we will enable Always Use Secure Connections in its public-sites variant for the <a href="https://blog.google/products/chrome/google-chrome-safe-browsing-one-billion-users/">over 1 billion users</a> who have opted-in to Enhanced Safe Browsing protections in Chrome.
</p>
<p>
While it is our hope and expectation that this transition will be relatively painless for most users, users will still be able to disable the warnings by disabling the "Always Use Secure Connections" setting.
</p>
<p>
If you are a website developer or IT professional, and you have users who may be impacted by this feature, we very strongly recommend enabling the "Always Use Secure Connections" setting today to help identify sites that you may need to work to migrate. IT professionals may find it useful to read our <a href="https://chromium.googlesource.com/chromium/src/+/main/docs/security/ask-before-http/ask-before-http-adoption-guide.md">additional resources</a> to better understand the circumstances where warnings will be shown, how to mitigate them, and how organizations that manage Chrome clients (like enterprises or educational institutions) can ensure that Chrome shows the right warnings to meet those organizations' needs.
</p>
<h2>Looking Forward</h2>


<p>
While we believe that warning on insecure public sites represents a significant step forward for the security of the web, there is still more work to be done. In the future, we hope to work to further reduce barriers to adoption of HTTPS, especially for local network sites. This work will hopefully enable even more robust HTTP protections down the road.
</p>

<span class="byline-author">Posted by Chris Thompson, Mustafa Emre Acer, Serena Chen,Joe DeBlasio, Emily Stark and David Adrian, Chrome Security Team</span>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.17 Beta disables wake-on-bluetooth for Steam Deck LCD again]]></title>
<description><![CDATA[Seems that wake-on-bluetooth for the Steam Deck LCD model is quite problematic, as Valve have again disabled it in the latest SteamOS update..Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3066069/linux-tipps/steamos-3717-beta-disables-wake-on-bluetooth-for-steam-deck-lcd-again/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3066069/linux-tipps/steamos-3717-beta-disables-wake-on-bluetooth-for-steam-deck-lcd-again/</guid>
<pubDate>Tue, 28 Oct 2025 10:37:24 +0100</pubDate>
<content:encoded><![CDATA[Seems that wake-on-bluetooth for the Steam Deck LCD model is quite problematic, as Valve have again disabled it in the latest SteamOS update.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt>.</p><p>Read the full article on <a href="https://www.gamingonlinux.com/2025/10/steamos-3-7-17-beta-disables-wake-on-bluetooth-for-steam-deck-lcd-again/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[랜섬웨어 복구의 함정···몸값 지불 기업 40% “데이터 결국 잃었다”]]></title>
<description><![CDATA[보험사 히스콕스(Hiscox)가 중소기업 1,000여 곳을 대상으로 실시한 ‘사이버 준비 보고서(Cyber Readiness Report)’에 따르면, 랜섬웨어 복구를 위해 사이버범죄자에게 몸값을 지불한 기업 중 5곳 중 2곳(약 40%)은 결국 데이터를 복구하지 못한 것으로 나타났다.



조사 결과, 랜섬웨어는 여전히 기업에 심각한 위협으로 남아있었다. 전체 응답 기업 중 27%가 지난 1년 동안 랜섬웨어 공격을 경험했으며, 이 중 보험 가입 여부와 관계없이 80%가 핵심 데이터를 복구하거나 보호하기 위해 몸값을 지불했다고...]]></description>
<link>https://tsecurity.de/de/3063663/it-security-nachrichten/40/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3063663/it-security-nachrichten/40/</guid>
<pubDate>Mon, 27 Oct 2025 08:34:38 +0100</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>보험사 히스콕스(Hiscox)가 중소기업 1,000여 곳을 대상으로 실시한 ‘<a href="https://www.hiscox.ie/sites/ireland-new/files/2025-09/Hiscox%20Cyber%20Readiness%20Report%202025.pdf" target="_blank" rel="nofollow">사이버 준비 보고서(Cyber Readiness Report)</a>’에 따르면, 랜섬웨어 복구를 위해 사이버범죄자에게 몸값을 지불한 기업 중 5곳 중 2곳(약 40%)은 결국 데이터를 복구하지 못한 것으로 나타났다.</p>



<p>조사 결과, 랜섬웨어는 여전히 기업에 심각한 위협으로 남아있었다. 전체 응답 기업 중 27%가 지난 1년 동안 랜섬웨어 공격을 경험했으며, 이 중 보험 가입 여부와 관계없이 80%가 핵심 데이터를 복구하거나 보호하기 위해 몸값을 지불했다고 응답했다. 몸값을 지불한 기업 가운데 데이터를 전부 혹은 일부 복구하는 데 성공한 곳은 60%에 불과했다.</p>



<p>한편 보험사 <a href="https://qbeeurope.com/news-and-events/press-releases/ransomware-attacks-to-rise-by-40-by-2026-qbe-warns/" target="_blank" rel="nofollow">QBE</a>가 최근 발표한 ‘사이버 범죄 및 클라우드 기반 위협 보고서’에서는 랜섬웨어 사고가 2025년 1분기에 전년 동기 대비 약 3배 증가했다고 밝혔다. 2024년 1분기 572건였던 공격 건수가 올해 같은 기간 1,537건으로 급증했다. 또한 크라우드스트라이크(CrowdStrike)가 이달 발표한 ‘2025 랜섬웨어 현황 보고서’에서도 <a href="https://www.csoonline.com/article/4075912/ai-enabled-ransomware-attacks-cisos-top-security-concern-with-good-reason.html" target="_blank">몸값을 지불한 피해자의 93%가 결국 데이터를 도난</a>당한 것으로 나타났다.</p>



<h2 class="wp-block-heading">결함 있는 랜섬웨어 암호화 구조, 복구 과정의 최대 걸림돌</h2>



<p>전문가들은 히스콕스의 랜섬웨어 피해 통계가 기업이 복구를 시도할 때 직면하는 수많은 문제를 단적으로 드러낸다고 설명했다.</p>



<p>사이버보안 기업 브라이드웰(Bridewell)의 사고 대응 매니저 <a href="https://www.linkedin.com/in/james-m-john/?originalSubdomain=uk" target="_blank" rel="nofollow">제임스 존</a>은 “60%의 복구율은 실제 사고 대응 현장에서 반복적으로 나타나는 기술적·운영적 문제를 보여준다”라고 말했다. 그는 “<a href="https://www.csoonline.com/article/3838121/the-dirty-dozen-12-worst-ransomware-groups-active-today.html" target="_blank">랜섬웨어 운영자</a> 간의 기술 수준에는 큰 차이가 있다. 락빗(LockBit), ALPHV 같이 정착된 그룹은 ‘평판’을 유지하기 위해 정상 작동하는 복호화 도구를 제공하는 반면, 규모가 작은 공격 그룹은 암호화 구현이 불완전하거나, 몸값을 받은 뒤 연락을 끊는 경우도 많다”라고 분석했다. 또한 그는 복구 도구 자체가 느리고 신뢰성이 떨어지는 경우가 많다고 덧붙였다.</p>



<p>존은 이어 “기업 전반의 데이터를 복구하는 과정은 수주가 걸릴 수 있으며, 손상된 파일이나 복잡한 데이터베이스 시스템은 복구에 실패하는 경우도 많다. 복호화 과정 자체가 추가적인 데이터 손상을 일으킨 사례도 있다”라고 말했다.</p>



<p>복구 도구가 제공되더라도 오류가 포함돼 있거나, 복호화 후에 파일이 손상되거나 접근이 불가능한 경우가 적지 않다. 게다가 많은 기업이 평소 검증되지 않은 백업에 의존하고 있으며, 일부 피해 기업은 공격 이후 백업 데이터마저 함께 암호화됐다는 사실을 뒤늦게 발견하고 있다.</p>



<p>영국 보안관리 서비스 기업 아벨라시큐리티(Avella Security)의 파트너이자 영국 정부 사이버보안 자문 위원인 <a href="https://www.linkedin.com/in/darylflack/?originalSubdomain=uk" target="_blank" rel="nofollow">대릴 플랙</a>은 “범죄자들은 종종 불완전하거나 호환되지 않는 암호화 도구를 사용하며, 많은 기업이 데이터 복구를 안정적으로 수행할 인프라를 갖추지 못한 상황이다. 백업이 불완전하거나 시스템이 여전히 침해된 상태라면 복구는 더욱 어렵다”라고 설명했다.</p>



<h2 class="wp-block-heading">복구를 위협하는 또 다른 요소</h2>



<p>최근 랜섬웨어 공격은 단순히 데이터를 암호화하는 수준을 넘어섰다. 공격자는 몸값을 지불한 이후에도 탈취한 데이터를 공개하겠다고 <a href="https://www.csoonline.com/article/4032874/ransomware-attacks-the-evolving-extortion-threat-to-us-financial-institutions.html" target="_blank">협박</a>하거나, 추가로 분산서비스거부(DDoS) 공격을 가하겠다고 위협하는 이중, 삼중 갈취 방식을 점점 더 자주 사용하고 있다.</p>



<p>이 같은 변화는 피해 기업이 몸값을 지불할 경우 무엇을 기대할 수 있는지에 대한 판단 자체를 근본적으로 바꾸고 있다. 결국 비용을 지불한다고 해서 랜섬웨어로 인해 발생한 문제가 해결되지 않을 수 있다는 의미다.</p>



<p>존은 “몸값을 지불하면 암호화 문제는 해결될 수 있지만, 시스템 전체의 침해 문제는 그대로 남을 수 있다”라고 지적했다.</p>



<p>더욱이 랜섬웨어 공격은 법적, 운영 문제뿐만 아니라 기업 평판까지도 위협할 수 있다. 이런 문제가 <a href="https://www.csoonline.com/article/3825444/ransomware-gangs-extort-victims-17-hours-after-intrusion-on-average.html" target="_blank">몇 시간 내에 연달아 발생</a>하기 때문에 기업은 극심한 압박을 받을 수 있다.</p>



<p>또한 범죄자와 거래해야 하는 불확실성까지 겹치면서, 몸값을 지불하더라도 완전한 데이터 복구로 이어지지 않는 경우가 많아진다.</p>



<p>영국 법무법인 하퍼제임스(Harper James)의 데이터 보호·프라이버시 팀 선임 변호사 <a href="https://harperjames.co.uk/our-people/lillian-tsang/" rel="nofollow">릴리언 창</a>은 복구 키를 받더라도 일부 데이터는 이미 손상 및 변경됐거나 유출됐을 수 있다고 경고했다.</p>



<p>그는 “이런 상황은 운영상 큰 혼란을 초래할 뿐 아니라, 특히 개인정보가 포함된 경우에는 심각한 데이터 보호 문제로 이어질 수 있다. 기록이 손실되거나 유출되면 영국 일반개인정보보호법(GDPR)상 개인정보 침해로 간주돼, 보고 의무와 규제 조사를 받을 가능성이 생긴다”라고 진단했다.</p>



<p>창은 또 “몸값을 지불해도 해커가 약속을 지키지 않을 경우 법적 대응 수단이 없으며, 더 나쁜 경우에는 자금이 제재 대상 단체로 흘러들어가 추가적인 법적 위험을 초래할 수도 있다”라고 말했다.</p>



<h2 class="wp-block-heading">재정적 및 법적 대응 과제</h2>



<p>일본 물류기업 칸츠(Kantsu)의 사례는 랜섬웨어 공격이 실제로 어떤 방식으로 전개되는지를 잘 보여준다. 칸츠의 타츠조 히사히로 대표는 <a href="https://www.cio.com/article/4036296/%E3%82%B5%E3%82%A4%E3%83%90%E3%83%BC%E6%94%BB%E6%92%83%E3%81%AB%E3%81%95%E3%82%89%E3%81%95%E3%82%8C%E3%81%9F%E4%BC%81%E6%A5%AD%E7%B5%8C%E5%96%B6%E8%80%85%E3%81%8C%E8%AA%9E%E3%82%8B%E5%AF%BE%E5%BF%9C.html" target="_blank">인터뷰</a>에서 공격을 겪은 이후 운영을 복구한 과정에 대해 설명했다.</p>



<p>당시 랜섬웨어에 몸값을 지불하지 않은 칸츠는 운영 복구 비용을 충당하기 위해 금융 기관에 자금 지원을 요청해야 했다. 보험에 가입돼 있었지만, 보험금이 지급되려면 청구 절차를 거쳐야 했기 때문이다. 이 사례는 기업이 랜섬웨어 공격으로부터 완전히 회복하려면 기술적 대응뿐 아니라 재정적 대비책까지 마련해야 한다는 점을 보여준다.</p>



<p>또한 랜섬웨어 공격으로 시스템이 중단되고 개인정보가 침해됐다면 기업은 즉시 규제 당국과 피해자에게 이를 통보해야 하는 법적 의무를 지게 된다.</p>



<p>하퍼제임스의 창은 “불완전한 정보만으로 신속하고 중대한 결정을 내려야 한다는 점이 핵심 과제다. 몸값을 지불할 때의 법적 위험, 비즈니스 연속성에 미치는 영향, 그리고 개인에게 발생할 수 있는 피해를 기술적 상황이 완전히 파악되지 않은 상태에서 경영진은 판단을 내려야 한다”라고 설명했다.</p>



<h2 class="wp-block-heading">대비가 곧 최선의 방어</h2>



<p>일부 전문가는 랜섬웨어 공격이 언제든 현실화될 수 있다는 점을 고려해, 재난 복구 계획의 일환으로 <a href="https://www.csoonline.com/article/515730/business-continuity-and-disaster-recovery-planning-the-basics.html" target="_blank">사고 대응 전문업체</a>와 사전 계약을 유지할 것을 권장하고 있다.</p>



<p>직접 위협 인텔리전스에 특화된 사이버보안 기업 블랙와이어드(Blackwired)의 최고경영자 <a href="https://www.linkedin.com/in/jeremysamide/" target="_blank" rel="nofollow">제레미 새마이드</a>는 “암호화폐 거래를 안전하게 처리할 역량을 갖춘 신뢰할 만한 사고 대응 또는 협상 전문업체와 사전 계약을 맺는 것이 매우 중요하다”라고 말했다. 그는 “전문업체는 <a href="https://www.csoonline.com/article/3568817/the-ransomware-negotiation-playbook-adds-new-chapters.html" target="_blank">협상 과정</a>을 관리하고 비트코인·모네로·제트캐시 등 다양한 암호화폐를 다룰 수 있으며, 복구를 위한 최후의 수단으로 몸값을 지불해야 하는 상황에서도 안전하게 거래를 수행할 수 있다”라고 설명했다.</p>



<p>새마이드는 “준비는 항복이 아니다. 어떤 상황에서도 대응할 수 있도록 대비하는 것”이라고 강조했다.</p>



<p>다만 창은 랜섬웨어 공격에 대비해 범죄자에게 지불할 자금을 미리 마련해 두는 행동을 지양해야 한다고 조언했다.</p>



<p>그는 “몸값 지급을 위한 자금을 따로 확보해 두는 것은 점점 더 문제적인 방식으로 인식되고 있다. 지불 행위 자체가 불법은 아니지만, 제재 위반으로 이어질 수 있고 범죄 행위를 조장할 위험이 있으며, 무엇보다 긍정적인 결과를 보장하지 않는다”라고 말했다.</p>



<p>창은 강력한 보안 조치, 충분히 검증된 복구 계획, 명확한 보고 절차, 사이버 보험을 통한 회복력 강화에 투자해야 보다 안전한 법적, 전략적 입지를 확보할 수 있다고 진단했다.</p>



<p>그는 “사이버 보험은 단순히 재정적 보호를 제공하는 것을 넘어, 전문적인 대응 지원을 통해 피해 규모와 시스템 중단 시간을 크게 줄일 수 있다는 점에서 랜섬웨어 대응에 매우 중요하다”라고 설명했다.</p>



<p><a href="https://www.csoonline.com/article/571703/cyber-insurance-explained.html" target="_blank">사이버 보험</a>은 일반적으로 능동적인 위기 대응 관리를 지원하며, 다음과 같은 사항을 보장한다.</p>



<ul class="wp-block-list">
<li>사고 발생 직후 즉각적인 대응 및 포렌식 조사</li>



<li>감염된 시스템의 격리 및 복구 조치</li>



<li>해커와의 협상 및 법률적 조율 지원</li>



<li>데이터 복원 및 비즈니스 연속성 확보 지원</li>
</ul>



<p>새마이드는 “보험이 공격 자체를 막을 수는 없지만, 피해를 완화하고 혼란스러운 상황에 질서를 부여하며 기업이 랜섬웨어 위기를 홀로 감당하지 않도록 돕는다”라고 말했다.</p>



<p>그러나 일부 전문가는 사이버 보험에도 주의할 점이 있다고 지적했다.</p>



<p>플랙은 “보험료가 계속 오르고 있으며, 보험사는 다단계 인증(MFA), 패치 관리, 정기적인 백업 검증 등 기본적인 보안 요건을 충족해야만 보장을 제공하거나 갱신을 허용하고 있다”라고 설명했다. 다만 그는 “이런 변화는 기업이 보안 수준을 높이고, 리스크 관리의 일환으로 더 성숙한 보안 관행을 도입하도록 유도하고 있다”라고 분석했다.</p>



<h2 class="wp-block-heading">사이버 복구 전략의 필요성</h2>



<p>전문가들은 랜섬웨어 공격 이후의 사이버 복구를 단순한 기술 조치가 아닌 ‘재난 복구’ 수준으로 다뤄야 한다고 조언했다. 이를 위해서는 명확하게 정의된 내부 복구 계획을 마련하고 전 과정을 문서화해, 손상되지 않은 데이터를 신뢰성 있게 복원할 수 있는 체계를 갖춰야 한다.</p>



<p>인덱스엔진스(Index Engines)의 최고마케팅책임자 <a href="https://www.linkedin.com/in/mcgann/" target="_blank" rel="nofollow">짐 맥갠</a>은 “기업이 랜섬웨어 공격을 받으면 가장 시급하게 해야 할 일은 공격의 전체 범위를 파악하는 것”이라고 언급했다. 그는 “어떤 데이터가 침해됐는지, 어떤 시스템이 영향을 받았는지, 그리고 기존 백업이 신뢰할 수 있는 상태인지 확인하는 것이 핵심”이라고 말했다.</p>



<p>맥갠은 이어 “백업이 존재하더라도 무결성 검증이라는 중요한 과제가 남는다. 백업 데이터에 손상되거나 변조된 파일이 포함돼 있다면 복구 과정에서 다시 위협이 유입될 위험이 있다”라고 경고했다.</p>



<p>그는 “이제 기업은 단순한 데이터 복원 수준을 넘어 철저한 데이터 무결성 검증 절차를 포함한 내부 복구 계획을 마련해야 한다”라고 조언했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What powers reinvention at NRG]]></title>
<description><![CDATA[For decades, power companies were the definition of dull. Powering your home was necessary but uninspiring, a commodity no different than running water. NRG Energy is proving that view outdated with acquisitions, partnerships, and a willingness to reimagine what a power generator can be, turning ...]]></description>
<link>https://tsecurity.de/de/3057118/it-security-nachrichten/what-powers-reinvention-at-nrg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3057118/it-security-nachrichten/what-powers-reinvention-at-nrg/</guid>
<pubDate>Thu, 23 Oct 2025 12:05:00 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For decades, power companies were the definition of dull. Powering your home was necessary but uninspiring, a commodity no different than running water. NRG Energy is proving that view outdated with acquisitions, partnerships, and a willingness to reimagine what a power generator can be, turning electricity into an engaging experience.</p>



<p>“Energy providers have always been thought of as the background players in people’s lives,” says <a href="https://www.linkedin.com/in/dak-liyanearachchi-0664381/" rel="nofollow">Dak Liyanearachchi</a>, the company’s EVP and CTO. “Our job now is to move to the foreground and show that energy can be personal and intelligent.”</p>



<h2 class="wp-block-heading">From residential power to connected experiences</h2>



<p>NRG began as a power generator before broadening its reach to serve residential customers. In recent years, it’s redefined its consumer strategy by bringing together electricity, smart home solutions, and digital platforms. The acquisition of Vivint Smart Home and partnerships with Renew Home gave NRG the foundation to link thermostats, energy services, and residential devices into one ecosystem, unlocking the potential of virtual power plant (VPP) technology.</p>



<p>A VPP aggregates distributed resources like thermostats, batteries, and rooftop solar across thousands of homes. Coordinated effectively, it becomes a flexible network that shifts demand, balances supply, and supports the grid during times of crisis.</p>



<p>The result is energy management that feels seamless and intentional. The Vivint and Nest thermostats don’t just heat and cool, they dynamically reduce demand on the grid during peak hours, improving reliability while realizing new capabilities for the company. Consumers see lower bills and greater comfort, but behind the scenes, the technology powers something larger.</p>



<p><a></a>In Texas, where extreme weather and surging demand from <a href="https://www.cio.com/article/222623/7-things-to-know-about-ai-in-the-data-center.html?utm=hybrid_search">AI data centers</a> can strain the grid, NRG’s VPP approach provides resilience. The company is targeting a gigawatt of capacity, enough to power hundreds of thousands of homes without building a single new plant.</p>



<p>“This isn’t just about keeping the lights on,” Liyanearachchi explains. “It’s about turning millions of small resources into a collective force that ensures reliability, reduces costs, and <a href="https://www.cio.com/article/3992816/9-projects-top-of-mind-for-it-leaders-today.html?utm=hybrid_search">creates value</a> for everyone.”</p>



<h2 class="wp-block-heading">Rewiring technology to match strategy</h2>



<p>NRG’s consumer story wouldn’t be possible without reimagining how technology operates inside the company. Under Liyanearachchi’s leadership, NRG has moved to a product operating model, aligning business and technology teams around shared outcomes rather than siloed projects.</p>



<p>“Historically, electricity providers approached technology as a request and deliver model,” he says. “The business would hand over requirements, and six to 12 months later, technology would deliver, often out of sync with the need. We knew that wasn’t sustainable if we wanted to bring smart home and energy into one seamless experience.”</p>



<p>The shift has introduced budget transparency, empowered business leaders to set technology priorities, and created a single cadence for planning and execution. Quarterly sessions also bring residential power, smart home, and energy teams together to align on customer priorities and deliver integrated products.</p>



<p>When developing new home energy offerings, NRGs’ teams now also span smart home, energy, engineering, and business leaders. The result is concepts moving quickly into products delivered to millions of households.</p>



<p>Additionally, AI enablement throughout the software development lifecycle is poised to continue pushing the operating model toward leaner, faster deployment, while promoting democratized AI usage by non-technology team members.</p>



<p>“The product operating model has given us a shared language,” Liyanearachchi says. “It’s no longer about technology supporting the business from the sidelines. We’re building solutions together, side by side.”</p>



<h2 class="wp-block-heading"><a></a>The AI catalyst</h2>



<p>AI runs through NRG’s industry and internal strategies, and traditional machine learning powers personalization, fraud detection, and forecasting. Plus, generative AI has opened new horizons, particularly in customer care and sales, where it reduces friction and improves both customer and employee experience.</p>



<p>“We see AI through two lenses,” Liyanearachchi says. “One is industry wide with the surge of data centers, EV adoption, and smart devices creating unprecedented demand for power. AI will be part of managing that. The second is internal, using AI to transform how we work, from forecasting weather driven demand to reimagining customer interactions.”</p>



<p>NRG’s <a href="https://www.cio.com/article/4021841/lighting-the-first-flame-how-to-spark-a-transformation-that-sticks.html?utm=hybrid_search">transformation</a> office plays a central role, too, looking beyond immediate use cases to envision the business of 2030. Forecasting demand with more precision, integrating renewables, and managing a grid strained by AI workloads are all on the agenda as well.</p>



<h2 class="wp-block-heading">Building for unprecedented demand</h2>



<p>States like Texas, Georgia, and Virginia face surging energy consumption from population growth, electrification, and AI driven data centers. Left unchecked, that demand could result in brownouts or blackouts.</p>



<p>NRG is addressing this challenge on two fronts: through its VPP strategy, which reduces strain on the grid by orchestrating demand at scale, and through continued investment in traditional generation to ensure reliability by acquiring assets such as the Rockland portfolio, which closed earlier this year, and pursuing additional opportunities like LS Power (subject to close).</p>



<p>“It isn’t either or,” Liyanearachchi adds. “The future of energy will be both virtual and physical. We’re investing in power plants and power pixels, the distributed intelligence that turns homes into part of the solution.”</p>



<h2 class="wp-block-heading"><a></a>Lessons for leaders</h2>



<p>For Fortune 500 CIOs, NRG’s transformation is more than a power provider story. It’s a playbook for reinvention. Energy may be the context, but the underlying themes resonate across industries.</p>



<p>NRG shows what it looks like to turn a commodity into an experience, shifting electricity from a background service into something customers actively value. It demonstrates how aligning business and technology through a product <a href="https://www.cio.com/article/3834755/the-product-operating-model-thats-driving-transformation-at-modivcare.html?utm=hybrid_search">operating model</a> can move IT from service provider to co-creator. It also highlights how AI can serve not only as an efficiency driver, but as a catalyst to reimagine how the business operates and engages customers.</p>



<p>The reminder is clear that even the most commoditized industries can reinvent themselves. The real question is whether leaders are ready to challenge assumptions and rewire their organizations to make it happen.</p>



<p>For NRG, the days of being seen as just another power provider are over. The company is showing that transformation isn’t reserved for digital natives. It’s available to any industry bold enough to put experience at the center.</p>



<p>“Power may never be sexy in the traditional sense, but when you deliver comfort, reliability, and innovation into people’s homes, and reshape how the grid works in the process, that’s pretty exciting,” says Liyanearachchi.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hugging Face and VirusTotal: Building Trust in AI Models]]></title>
<description><![CDATA[We’re happy to announce a collaboration with Hugging Face, an open platform that fosters collaboration and transparency in AI, to make security insights more accessible to the community. VirusTotal’s analysis results are now integrated directly into the Hugging Face platform, helping users unders...]]></description>
<link>https://tsecurity.de/de/3056862/malware-trojaner-viren/hugging-face-and-virustotal-building-trust-in-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3056862/malware-trojaner-viren/hugging-face-and-virustotal-building-trust-in-ai-models/</guid>
<pubDate>Thu, 23 Oct 2025 09:46:15 +0200</pubDate>
<content:encoded><![CDATA[<p>We’re happy to announce a collaboration with <a href="https://huggingface.co/">Hugging Face</a>, an open platform that fosters collaboration and transparency in AI, to make security insights more accessible to the community. VirusTotal’s analysis results are now integrated directly into the Hugging Face platform, helping users understand potential risks in model files, datasets, and related artifacts before they download them.</p><p>
</p><p><b>Security context where you need it</b></p>
<p>When you browse a file on Hugging Face, you’ll now see security information coming from different scanners, including VirusTotal results. In the example below, VirusTotal detects the file as unsafe and links directly to its public report for full details.</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEga3DkPqRRwryQ5NEuG9zmI8q2c9cKr-IObSEGILLCrQontAvDskG09vuWMA_EU7dAiL8ChpMPv_rKE4YvnP-WwIlwB-NJbiKWfyi0-qY50IUYS0lk4AAyVvJfi9AAmahk2UpW5o_laxVBoOh1h1pAQuAxFsf2yQl38YyZ2Gb4I_y5k4aZPyoFm1mtewOQ/s1600/Screenshot%202025-10-22%2015.48.23.png"><img alt="" border="0" data-original-height="696" data-original-width="780" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEga3DkPqRRwryQ5NEuG9zmI8q2c9cKr-IObSEGILLCrQontAvDskG09vuWMA_EU7dAiL8ChpMPv_rKE4YvnP-WwIlwB-NJbiKWfyi0-qY50IUYS0lk4AAyVvJfi9AAmahk2UpW5o_laxVBoOh1h1pAQuAxFsf2yQl38YyZ2Gb4I_y5k4aZPyoFm1mtewOQ/s1600/Screenshot%202025-10-22%2015.48.23.png"></a></div>
</center>
<p><b>Addressing new challenges</b></p>
<p>As AI adoption grows, we see familiar threats taking new forms, from tampered model files and unsafe dependencies to data poisoning and hidden backdoors. These risks are part of the broader AI supply chain challenge, where compromised models, scripts, or datasets can silently affect downstream applications.</p>
<p>At VirusTotal, we’re also evolving to meet the challenges of this new landscape. We’re developing AI-driven analysis tools such as Code Insight, which uses LLMs to understand and explain code behavior, and we’re adding support for specialized tools for model/serialization formats, including picklescan, safepickle, and ModelScan, to help surface risky patterns and unsafe deserialization flows.</p>
<p>Our collaboration with Hugging Face strengthens this effort. By connecting VirusTotal’s analysis with Hugging Face’s AI Hub, we can expand our research into threats targeting AI models and share that visibility across the industry, helping everyone build better defenses, tools, and approaches to improve global security.</p>
<p><b>Stronger together</b></p>
<p>This collaboration is part of our ongoing mission to make security intelligence simpler and more accessible. It follows our recent effort to streamline <a href="https://blog.virustotal.com/2025/10/simpler-access-for-stronger-virustotal.html">VirusTotal access and API usage for the community</a>, and now extends that same spirit into the AI space.</p>
<p>We believe that openness, collaboration, and shared knowledge are the best defenses against evolving threats. Hugging Face and VirusTotal share that vision: empowering researchers, developers, and defenders worldwide to build safely and openly.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's Planned Foldable iPad With 18-inch Screen Hits Development Snags]]></title>
<description><![CDATA[Apple's effort to reinvent the iPad by adding a giant foldable screen has hit development hurdles, potentially delaying the planned launch. Bloomberg: The company has been working on the device -- projected to cost around $3,000 -- for several years and had most recently aimed for a 2028 release....]]></description>
<link>https://tsecurity.de/de/3054078/it-security-nachrichten/apples-planned-foldable-ipad-with-18-inch-screen-hits-development-snags/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3054078/it-security-nachrichten/apples-planned-foldable-ipad-with-18-inch-screen-hits-development-snags/</guid>
<pubDate>Tue, 21 Oct 2025 23:19:27 +0200</pubDate>
<content:encoded><![CDATA[Apple's effort to reinvent the iPad by adding a giant foldable screen has hit development hurdles, potentially delaying the planned launch. Bloomberg: The company has been working on the device -- projected to cost around $3,000 -- for several years and had most recently aimed for a 2028 release. But engineering challenges tied to weight, features and display technology have pushed its potential debut to 2029 or later, according to people familiar with the matter. 

Apple is working with Samsung Display Co. to develop the roughly 18-inch panel for the device, said the people, who asked not to be identified because the work isn't public. The screen minimizes the crease seen on foldable displays, matching an approach that Apple is also using with its upcoming foldable iPhone. The iPad project is part of a broader push to bring more innovative devices to market. Apple just introduced its first new iPhone design in years -- the ultrathin $999 Air model -- and is working on everything from smart glasses to a tabletop robot device.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Apple's+Planned+Foldable+iPad+With+18-inch+Screen+Hits+Development+Snags%3A+https%3A%2F%2Fapple.slashdot.org%2Fstory%2F25%2F10%2F21%2F2047227%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fapple.slashdot.org%2Fstory%2F25%2F10%2F21%2F2047227%2Fapples-planned-foldable-ipad-with-18-inch-screen-hits-development-snags%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://apple.slashdot.org/story/25/10/21/2047227/apples-planned-foldable-ipad-with-18-inch-screen-hits-development-snags?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Architecting a high-performance delivery engine]]></title>
<description><![CDATA[You’ve focused on making credible, board-level promises that connect technology to business value by going Beyond the business case: A playbook for securing board-level buy-in. After you secure your mandate and walk out with the buy-in you need to drive real change, your accountability shifts fro...]]></description>
<link>https://tsecurity.de/de/3053034/it-security-nachrichten/architecting-a-high-performance-delivery-engine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3053034/it-security-nachrichten/architecting-a-high-performance-delivery-engine/</guid>
<pubDate>Tue, 21 Oct 2025 14:05:05 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You’ve focused on making credible, board-level promises that connect technology to business value by going <a href="https://www.cio.com/article/4049950/beyond-the-business-case-a-playbook-for-securing-board-level-buy-in.html">Beyond the business case: A playbook for securing board-level buy-in</a>. After you secure your mandate and walk out with the buy-in you need to drive real change, your accountability shifts from the vision you sold to the delivery engine you must build.</p>



<p>Think of yourself as the team principal of a Formula 1 racing team. You’ve just convinced the sponsors to back your vision of podium finishes and championships; the promises still echo in the boardroom. But a vision doesn’t win races. A finely tuned car, an elite pit crew and a world-class driver do.</p>



<p>In the enterprise, it’s the same. Boardroom commitments mean nothing without an organization designed to deliver them. The single greatest predictor of your success isn’t your technology stack: it’s your organizational architecture. But before you can lay out a new blueprint, you must first understand the flawed models holding you back.</p>



<h2 class="wp-block-heading">The organizational models that hold you back</h2>



<p>Most technology organizations are not designed; they’re inherited. They’re a collection of vertical silos (applications, infrastructure, data, security, etc.) optimized for a bygone era of stability and control.</p>



<p>It’s like an F1 team where the engine designers aren’t allowed to speak to the chassis engineers and the driver only sees the car on race day.</p>



<p>This isn’t just inefficient; it’s disempowering. Talented professionals become ticket-takers in a feature factory, stripped of ownership and lacking context. They burn out under the weight of handoffs and politics, while the business loses faith in IT’s ability to execute and turns to shadow IT or unsanctioned third-party solutions that only exacerbate the problem.</p>



<p>And every missed deadline or clumsy release is more than an operational hiccup; it’s a withdrawal from the political capital you worked so hard to build. CIOs rarely get fired over a single outage. They get fired because the organization they inherited was incapable of delivering on the promises they made.</p>



<h2 class="wp-block-heading"><a></a>The engines of a modern technology organization</h2>



<p>To deliver on your commitments, you must re-architect around the flow of value, just as an F1 car is architected not for raw speed, but for sustainable performance: the ability to be fast, reliable and precise, lap after lap. That means moving beyond technology layers and designing a system with three core engines, each with a distinct but interlocking purpose.</p>



<h3 class="wp-block-heading">Engine 1: Product teams as the driver and the car</h3>



<p>Product teams are your race crews: durable, cross-functional units that own business outcomes end to end. Unlike project teams that disband after launch, product teams stay with their domain, whether that’s digital onboarding, checkout and payments, or inventory and fulfillment.</p>



<p>Their mission isn’t to deliver a set of features; it’s to achieve measurable outcomes. Instead of reporting “20 new features shipped,” they point to “+15% customer retention” or “three weeks shaved off onboarding.” That’s how promises to the board become the day-to-day mission of empowered teams.</p>



<p>The payoff is enormous. McKinsey’s analysis shows <a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/the-bottom-line-benefit-of-the-product-operating-model" target="_blank" rel="noreferrer noopener">companies with mature product models deliver 60% higher shareholder returns</a> and 16% higher operating margins.</p>



<p>In my own experience at Sagent, we saw the transformation firsthand: velocity increased, but so did solution quality, because teams had the context and autonomy to solve real industry problems, not just build to a spec.</p>



<p>When you design your organization this way, you don’t just build software. You build a culture of ownership that becomes a magnet for top talent.</p>



<h3 class="wp-block-heading">Engine 2: Platform teams as the high-tech garage</h3>



<p>In Formula 1, a world-class car is built and perfected in a world-class garage. It’s the high-tech hub where perfectly engineered parts are organized, specialized tools are ready and expert mechanics can work with speed and precision. Your platform teams are this well-stocked garage.</p>



<p>Their mission is to treat infrastructure, cloud services, developer tools and data pipelines as first-class citizens. Their customers are the engineers inside your company and success is measured by how frictionless they make delivery.</p>



<p>This approach tackles the reality of cognitive load, which is the mental energy engineers spend on things other than creating customer value. As the book “<a href="https://teamtopologies.com/book" target="_blank" rel="noreferrer noopener">Team Topologies</a>” explains, no team can master every domain.</p>



<p>Without platform teams, you get duplication of effort, with multiple teams solving authentication, CI/CD or observability in inconsistent ways. The result is waste, inconsistency and maintenance nightmares.</p>



<p>Platform teams prevent this by providing a custom-molded tool chest where every tool is in its place. This includes specialized diagnostic software (well-documented APIs), automated assembly workflows (golden paths to deployment) and a unified telemetry dashboard (shared observability). That level of organization frees product teams to focus on high-performance engineering, not on searching for the right wrench.</p>



<p>And don’t underestimate the talent advantage. World-class engineers want to build; they don’t want to fight brittle pipelines or reinvent tools. A thoughtful platform strategy doesn’t just speed delivery. It helps you attract and retain the very people you need to win.</p>



<h3 class="wp-block-heading">Engine 3: The office of the CIO as the car concept and design team</h3>



<p>While the other engines are winning races today, this is the team that designs the championship-winning car concept for next season. This strategic function governs cross-cutting architecture, mitigates long-term technology risk, manages the technical debt portfolio and scans the horizon for innovation.</p>



<p>Crucially, it doesn’t need to be a heavy bureaucracy. In some organizations, it’s a formal architecture team; in others, a rotating council of senior engineers or lightweight guilds. The form matters less than the function: which is to ensure today’s speed doesn’t become tomorrow’s technical bankruptcy.</p>



<p>This team makes conscious decisions: which technical debt is acceptable for now, which must be retired to enable scale and which emerging technologies, like AI governance, agentic automation and quantum security, demand early exploration.</p>



<p>Far from being an ivory tower, this function is about credibility. It ensures your technology investments stand up to scrutiny from investors, regulators and customers. It’s the safeguard that keeps the enterprise competitive not just this quarter, but for years to come.</p>



<h2 class="wp-block-heading"><a></a>Beyond the org chart: Dismantling cultural silos</h2>



<p>A perfect blueprint isn’t enough. A high-performance engine will seize without lubrication; and the friction that grinds a technology organization to a halt comes from its silos. Not the technical ones, but the cultural ones.</p>



<p>I once saw a development team and a security team each assume the other owned API encryption standards. The result? Over a dozen services were deployed without consistent safeguards.</p>



<p>That wasn’t a tech failure … it was a leadership failure to establish a cultural default of shared accountability. And it carried real stakes: promises made to the board were compromised well before they reached production.</p>



<p>This is why leading firms pursue what <a href="https://www.deloitte.com/us/en/insights/topics/talent/human-capital-trends/2023/human-capital-leadership-outlook.html" rel="nofollow">Deloitte’s </a><a href="https://www.deloitte.com/us/en/insights/topics/talent/human-capital-trends/2023/human-capital-leadership-outlook.html" target="_blank" rel="nofollow">Human Capital Trends</a> calls a “boundaryless organization.” To get there, you need rituals that create a culture of transparency and shared ownership. I focus on what I call JAB: three non-negotiables that jab away at the cultural silos that hold organizations back.</p>



<ul class="wp-block-list">
<li><strong>J for joint planning:</strong> A shared rhythm where teams align on goals, dependencies and trade-offs. It replaces siloed roadmaps with a single, unified mission.</li>



<li><strong>A for architecture showcases:</strong> Regular forums where teams present work in progress. This serves as a powerful antidote to the “not invented here” syndrome and creates a culture of shared learning.</li>



<li><strong>B for blameless post-mortems:</strong> A process focused on systemic causes, not individual blame. This is the bedrock of psychological safety: replacing a culture of fear with one of continuous improvement.</li>
</ul>



<p>These practices force the conversations that legacy silos were designed to avoid.</p>



<p>At the same time, balance matters. Over-collaboration slows everything down. The goal isn’t endless consensus; it’s precision alignment with enough shared context to keep the chassis stable while the engine runs at full speed.</p>



<h2 class="wp-block-heading">The leadership transformation</h2>



<p>Architecting this model requires a fundamental shift in leadership. As team principal, your primary job is no longer to direct every turn from the pit wall. It’s to lead with CARE, a people-oriented framework that elevates structure into sustained performance:</p>



<ul class="wp-block-list">
<li><strong>Clarify:</strong> Translate board-level promises into a cohesive mission that aligns strategy, structure and outcomes. Teams must know not just what hill to take, but whyit matters.</li>



<li><strong>Amplify:</strong> Relentlessly amplify the why through storytelling at scale. It’s your job to keep the vision alive when day-to-day pressures threaten to bury it.</li>



<li><strong>Remove:</strong> Dismantle the friction (processes, silos or politics) that slow execution. Clearing obstacles is one of the most high-leverage acts of leadership you can perform.</li>



<li><strong>Empower:</strong> Grant teams true ownership of outcomes, shifting the conversation from assigned activities to measurable impact. When leaders let go, teams step up.</li>
</ul>



<p>Your legacy isn’t the systems you ship: it’s the organization you leave behind … resilient, empowered and capable of delivering value year after year.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 IT wins to deliver before the year ends]]></title>
<description><![CDATA[There may be just over two months left in 2025, but that’s enough time to deliver a few more IT wins and set the stage for bigger victories in the year to come.



Given the long list of priorities CIOs had at the start of this year, IT leaders still have plenty of opportunities to pursue — from ...]]></description>
<link>https://tsecurity.de/de/3050722/it-security-nachrichten/7-it-wins-to-deliver-before-the-year-ends/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3050722/it-security-nachrichten/7-it-wins-to-deliver-before-the-year-ends/</guid>
<pubDate>Mon, 20 Oct 2025 12:20:46 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There may be just over two months left in 2025, but that’s enough time to deliver a few more IT wins and set the stage for bigger victories in the year to come.</p>



<p>Given <a href="https://www.cio.com/article/4074789/10%20top%20priorities%20for%20CIOs%20in%202025%20%7C%20CIO">the long list of priorities CIOs had at the start of this year</a>, IT leaders still have plenty of opportunities to pursue — from AI initiatives to strategy adjustments.</p>



<p>What work are IT leaders looking to push across the finish line before the year runs out? Here’s a look at the end-of-year projects making CIOs’ must-do-now lists.</p>



<h2 class="wp-block-heading">1. Shoring up the AI governance policy</h2>



<p>The race to harness artificial intelligence in the enterprise has been under way for years, yet many organizations don’t yet have a <a href="https://www.cio.com/article/3984527/how-to-establish-an-effective-ai-grc-framework.html">fully formed AI governance policy</a>.</p>



<p>The 2025 Public Company Board Practices and Oversight Survey from the National Association of Corporate Directors found that only 36% of boards have adopted an AI governance framework, only 23% have reevaluated corporate strategies to incorporate AI’s impact, and a mere 27% have incorporated AI oversight responsibilities into board committee charters.</p>



<p>“AI governance is all over the place,” says <a href="https://www.cio.com/article/4074789/About%20Us%20-%20Key%20Staff%20-%20ITML%20Institute">Eric Bloom</a>, executive director of the IT Management and Leadership Institute. “For CIOs [whose organizations] don’t have AI governance and usage guidelines, they should create them now. And if they developed them more than a year ago, then they should be readdressing them because the technology has changed so much and so quickly.”</p>



<p>RGP CIO <a href="https://rgp.com/leadership/keith-golden/" rel="nofollow">Keith Golden</a> is tackling this task, knowing that having up-to-date guidelines is key for successful AI deployments. The global consulting and project execution company has an AI task force working to develop “a fully-fledged governance model” that will include ways to evaluate and prioritize proposed AI projects, he says, adding that this work will include establishing processes to monitor and measure AI initiatives to ensure they deliver business value.</p>



<p>“We’re taking steps to really manage our own AI shop effectively,” Golden says, noting that he’s aiming to finish work on this by year’s end.</p>



<h2 class="wp-block-heading">2. Strengthening the foundation needed for AI deployments</h2>



<p>Successful AI deployments require more than good governance; they also need the <a href="https://www.cio.com/article/4006394/how-cios-are-getting-data-right-for-ai.html">right data and technology environment</a>.</p>



<p>Many CIOs are making sure those elements are in place ASAP, says <a href="https://www.kearney.com/about/people/bio/eric-stettler" rel="nofollow">Eric Stettler</a>, partner in the technology transformation practice at Kearney, a global strategy and management consulting firm.</p>



<p>“The CIO needs to make sure the foundational capabilities — data, application architecture, the enterprise architecture, the needed skill sets — are all set up to take full advantage of AI technologies and deliver meaningful outcomes for the organization,” Stettler says, noting that the lack of these contributes to the high percentage of <a href="https://www.cio.com/article/4055896/from-pilot-to-profitability-how-to-approach-enterprise-ai-adoption.html">organizations struggling to move AI pilots to enterprise-scale production</a>.</p>



<p><a href="https://www.cio.com/article/4074789/(35)%20Brian%20Fruh%20-%20MBA,%20CISSP%20%7C%20LinkedIn">Brian Fruh</a>, former CIO and head of technology at Impax Asset Management and now offering fractional CIO services, says he and other CIOs are making big plays to that end, particularly around data.</p>



<p>“There is still more work to be done with data governance and making sure [organizations] have a single source of truth. There is a sense of urgency now as AI is maturing, because you can’t fully capitalize on AI until data governance, the single source of truth, data security, and those other foundational pieces are in place,” Fruh says.</p>



<h2 class="wp-block-heading">3. Delivering AI that has demonstrable value</h2>



<p>A September 2025 report from Boston Consulting Group titled <a href="https://media-publications.bcg.com/The-Widening-AI-Value-Gap-Sept-2025.pdf" rel="nofollow">The Widening AI Value Gap</a> included sobering findings: “Only 5% of companies in our 2025 study of more than 1,250 firms worldwide are achieving AI value at scale — a measure of how tough the full AI transformation is. Fully 60% of companies are not achieving material value at all, reporting minimal revenue and cost gains despite substantial investment.”</p>



<p>Given such figures, CIOs are feeling the pressure to deliver, says <a href="https://www.progress.com/company/leadership/ian-pitt" rel="nofollow">Ian Pitt</a>, executive vice president and CIO at Progress Software.</p>



<p>“It feels as if we’re almost in the <a href="https://www.cio.com/article/4046443/gen-ai-descends-into-disillusionment.html">second trough of disillusionment with AI</a>, the first being after ChatGPT came out when we found it didn’t solve all our problems. Now, with this new round of AI, CEOs and CFOs are now saying, ‘Show me the value,’” he says. “If CIOs aren’t working on that, they should, because the life of the IT leader is all about returns on investment. We can talk about keeping the bad guys out, keeping the lights on, enabling a great workplace, but it all has to come with a was-it-all-worth-it mindset.”</p>



<p>Pitt and his IT team are working to deploy more AI within the company that will measurably boost productivity or generate efficiencies, he says.</p>



<p>A big focus heading into the last quarter for Pitt is making sure “everyone in the company is a frequent return visitor” to the Microsoft Copilot capabilities that IT had deployed earlier this year. He is measuring the rate of the technology’s use by user and identifying those who need more training to ensure the company gets to full adoption fast. Working to get high adoption rates means the company can maximize the value of its investment, he says.</p>



<p>“It’s all around making sure we can end the year on a high point,” he adds.</p>



<p>Other CIOs, including <a href="https://www.linkedin.com/in/dvidoni/" rel="nofollow">Pegasystems CIO David Vidoni</a>, are making a similar push to close out 2025.</p>



<p>Vidoni is looking to deploy agentic AI in ways that support the company’s goals of rapid growth without additional costs. He and his IT team are creating agents to help employees move through their work more quickly and easily. For example, one agent in progress will identify sales leads, pull relevant information on the customer and products, and draft custom proposals — enabling Pegasystems account executives to finalize the messaging without having to manually perform as much of that work.</p>



<h2 class="wp-block-heading">4. Readying employees for AI-enabled attacks</h2>



<p>Deepfake incidents are increasingly impacting organizations, according to <a href="https://www.gartner.com/en/newsroom/press-releases/2025-09-02-why-cios-cannot-ignore-the-rising-tide-of-deepfake-attacks" rel="nofollow">research firm Gartner, pointing to a 2025 survey</a> showing that 43% of responding tech leaders saw at least one audio call incident and 37% experienced deepfakes in video calls.</p>



<p>RGP’s Golden is now working to step up his organization’s readiness to <a href="https://www.csoonline.com/article/3982379/deepfake-attacks-are-inevitable-cisos-cant-prepare-soon-enough.html">fend off those and other AI-enabled attacks</a>.</p>



<p>“The threat actors are using AI tools and AI automation, so it’s a good idea for CIOs to look at their own tooling and coverage to see where there are weaknesses and also talk to vendors about how they’re preparing,” he says.</p>



<p>Golden and others list several steps they’re taking now to help their organizations better defend against <a href="https://www.csoonline.com/article/564321/6-ways-hackers-will-use-machine-learning-to-launch-attacks.html">AI-enabled attacks</a>, a list that includes educating leadership on the risks, implementing training programs that specifically address the threat, and <a href="https://www.csoonline.com/article/4042494/how-ai-is-reshaping-cybersecurity-operations.html">implementing more AI in their security programs</a>.</p>



<h2 class="wp-block-heading">5. Improving customer and employee experiences</h2>



<p>Both lines of business leaders and IT leaders listed improving customer experience as a top priority for 2025, according to the <a href="https://www.cio.com/article/3976500/state-of-the-cio-survey-2025.html">State of the CIO Survey</a> published in May by CIO.com.</p>



<p>Gartner in its <a href="https://www.evanta.com/resources/cio/survey-report/top-3-priorities-for-cios-in-2025" rel="nofollow">2025 CIO Agenda survey</a> similarly found that <a href="https://www.cio.com/article/3966301/customer-centric-it-strategies-for-delivering-winning-customer-experiences.html">improving customer experience</a> was a top goal for the year, coming in at No. 5 on the list of CIO priorities.</p>



<p>Pegasystems’ Vidoni wants to close out the year with a few more wins in this category.</p>



<p>“On the client experience side, we’re having a big push to make it easier for them to find what they’re looking for from us, make it more intuitive for customers to interact with us, make it easier to find what they need,” he says, stressing that customers now expect both great products and great experiences from companies.</p>



<p>Vidoni says improving customer experience supports company objectives beyond customer satisfaction and retention, explaining that improved customer experience reduces the workload on staff by reducing the need for customers to connect with employees for information.</p>



<p>He and his IT team are working to add AI agents to customer-facing features to help make company-customer interactions fast, seamless, productive, and personalized.</p>



<h2 class="wp-block-heading">6. Speeding up</h2>



<p><a href="https://www.linkedin.com/in/jamilfarshchi/" rel="nofollow">Jamil Farshchi</a>, CTO at Equifax, one of the three major credit reporting agencies in the US, says he wants IT to focus on bringing more speed to the business — something he has been working on but isn’t yet finished with.</p>



<p>“Our most significant IT win this year isn’t a single product or a platform. It’s making every part of our business run faster,” he says. “Our multiyear, approximately $3 billion Equifax cloud transformation has equipped us to increase our speed in a variety of ways, including processing data, onboarding customers, shipping new products, and detecting threats.”</p>



<p>That transformation has brought the company plenty of wins already, “and we’re on track to launch around 150 new products before the end of the year,” Farshchi says, noting “we’ve made great strides, but there’s no finish line.”</p>



<h2 class="wp-block-heading">7. Preparing a realistic 2026 budget (that can handle uncertainty)</h2>



<p>The outlook for 2026 is mixed, with executives downgrading expectations and bracing for possible economic turbulence.</p>



<p>That’s the message CIOs are getting. Gartner’s <a href="https://www.gartner.com/en/chief-information-officer/insights/cio-agenda" rel="nofollow">2026 CIO Agenda Preview</a> report declared, “Executives have hit the brakes on 2025 growth forecasts,” explaining that “74% of executive leadership teams have lowered 2025 top-line growth expectations for their organizations. Organizations are, on average, recalibrating top-line growth expectations downward by 8.3% relative to expectations at the start of the year.”</p>



<p>The Gartner report also found that only 53% of CIOs expect their budgets to increase in 2026, with the average increase being only 2.79%. Some 27% expect a level-funded budget and 19% anticipate a decrease in IT spending year of year. CIOs can expect “to face sustained pressure to reduce costs and improve productivity,” Gartner wrote in its report.</p>



<p>RGP’s Golden is developing an IT budget for 2026 that will deliver what the business needs while respecting the current macroeconomic uncertainty, listing the ability to successfully balance those issues as one win he wants to notch before the year closes.</p>



<p>“For most people this is budget season coming up, and for most of the colleagues I talk to and what I hear back from clients is that we’re still in a time of economic uncertainty. So our budget is all-weather. We need to be prepared if there is a lift, and we need to be prepared for choppy waters. Many of my colleagues have that same kind of framing,” Golden says.</p>



<p>To thread the needle here, Golden says he’s building a budget based on “what we absolutely have to have regardless of economic conditions and what we might do if the macroeconomic lift is coming. We’ll have what we’re prepared to do under any circumstance.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple SVP Eddy Cue wants to reinvent sports streaming, says it is broken for fans]]></title>
<description><![CDATA[Eddy Cue has been on a media tour talking about Apple TV, sports rights, and F1, suggesting that Apple wants to differentiate itself by doing sports differently from everyone else.Apple wants to do more than make a movie about F1. Image source: AppleOn October 14, Apple's SVP of services, Eddy Cu...]]></description>
<link>https://tsecurity.de/de/3045300/ios-mac-os/apple-svp-eddy-cue-wants-to-reinvent-sports-streaming-says-it-is-broken-for-fans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3045300/ios-mac-os/apple-svp-eddy-cue-wants-to-reinvent-sports-streaming-says-it-is-broken-for-fans/</guid>
<pubDate>Fri, 17 Oct 2025 00:34:49 +0200</pubDate>
<content:encoded><![CDATA[Eddy Cue has been on a media tour talking about <a href="https://appleinsider.com/inside/apple-tv" title="Apple TV" data-kpt="1">Apple TV</a>, sports rights, and F1, suggesting that Apple wants to differentiate itself by doing sports differently from everyone else.<br><br><div><img src="https://photos5.appleinsider.com/gallery/65439-136890-F1_The_Moive_Photo_0110-xl.jpg" alt="Crowd watches a car race on a track, phones raised, capturing the fast-moving cars with enthusiasm." height="738"><br><span>Apple wants to do more than make a movie about F1. Image source: Apple</span></div><br>On October 14, Apple's SVP of services, <a href="https://appleinsider.com/inside/eddy-cue" title="Eddy Cue" data-kpt="1">Eddy Cue</a>, detailed some of Apple's <a href="https://appleinsider.com/articles/25/10/14/svp-eddy-cue-talks-apple-tv-hints-at-subscriber-numbers-dropping-the-">media strategy</a> on a podcast, and he's been touring since. His repeated comment is that the way sports are being handled by broadcasters today is broken, and Apple wants to do things differently.<br><br>According to <a href="https://www.cnbc.com/2025/10/16/apple-wants-to-reform-sports-streaming-as-it-nears-f1-rights-deal.html">a report</a> from <em>CNBC</em>, Apple is on the verge of announcing a $140 million per year media rights deal with F1. Cue spoke about how Apple has approached sports and why things are so broken for sports fans today.<br><br><br> <a href="https://appleinsider.com/articles/25/10/16/apple-svp-eddy-cue-wants-to-reinvent-sports-streaming-says-it-is-broken-for-fans?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/242092?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025]]></title>
<description><![CDATA[Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025

      
      
        
          
            
                



            
          
        
              
    
  Oliver Altvater
Mo., 13.10.2025 - 13:34


            Machen Sie Ihre Cloud- und Virtualisierungsinfrastruktur...]]></description>
<link>https://tsecurity.de/de/3037429/server/der-admin-leitfaden-cloud-und-virtualisierungssicherheit-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3037429/server/der-admin-leitfaden-cloud-und-virtualisierungssicherheit-2025/</guid>
<pubDate>Mon, 13 Oct 2025 16:35:34 +0200</pubDate>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/admin-leitfaden-cloud-und-virtualisierungssicherheit"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Titelbild_Admin-Leitfaden_Cloud-%20und%20Virtualisierungssicherheit%202025.jpg?itok=UZWTy-FV" width="480" height="319" alt="Vektorgrafische Darstellung der Cloud- und Virtualisierungssicherheit" title="Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/146" lang about="https://www.it-administrator.de/user/146" typeof="schema:Person" property="schema:name" datatype class="username">Oliver Altvater</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2025-10-13T13:34:00+02:00" title="Montag, Oktober 13, 2025 - 13:34" class="datetime">Mo., 13.10.2025 - 13:34</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Machen Sie Ihre Cloud- und Virtualisierungsinfrastruktur mit diesem praktischen Admin-Leitfaden sofort sicherer. Entwickeln Sie mit praxisnahen Einblicken, konkreten Konfigurations-Tipps und hilfreichen Checklisten ein ganzheitliches Sicherheitskonzept und etablieren Sie Sicherheit als kontinuierlichen Prozess.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/grundlagen" hreflang="en">Grundlagen</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/admin-leitfaden-cloud-und-virtualisierungssicherheit" rel="tag" title="Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025" hreflang="en">Weiterlesen<span class="visually-hidden"> über Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI and the Future of American Politics]]></title>
<description><![CDATA[Two years ago, Americans anxious about the forthcoming 2024 presidential election were considering the malevolent force of an election influencer: artificial intelligence. Over the past several years, we have seen plenty of warning signs from elections worldwide demonstrating how AI can be used t...]]></description>
<link>https://tsecurity.de/de/3036994/it-security-nachrichten/ai-and-the-future-of-american-politics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3036994/it-security-nachrichten/ai-and-the-future-of-american-politics/</guid>
<pubDate>Mon, 13 Oct 2025 13:19:19 +0200</pubDate>
<content:encoded><![CDATA[<p>Two years ago, Americans anxious about the forthcoming 2024 presidential election were considering the malevolent force of an election influencer: artificial intelligence. Over the past several years, we have seen <a href="https://www.cigionline.org/articles/then-and-now-how-does-ai-electoral-interference-compare-in-2025/">plenty</a> <a href="https://www.frontiersin.org/journals/artificial-intelligence/articles/10.3389/frai.2025.1569115/full">of</a> <a href="https://www.nytimes.com/2025/06/26/technology/ai-elections-democracy.html">warning</a> <a href="https://cdn.prod.website-files.com/643ecb10be528d2c1da863cb/682f5ae442fffdff819ef830_TP%202025.2.pdf">signs</a> from elections worldwide demonstrating how AI can be used to propagate misinformation and alter the political landscape, whether by <a href="https://www.nytimes.com/2023/12/13/us/politics/trump-meme-trolls-2024.html">trolls</a> on social media, <a href="https://www.npr.org/2024/08/17/nx-s1-5079397/openai-chatgpt-iranian-group-us-election">foreign</a> <a href="https://www.nato.int/docu/review/articles/2025/02/07/algorithmic-invasions-how-information-warfare-threatens-nato-s-eastern-flank/index.html">influencers</a>, or even a <a href="https://www.nbcnews.com/politics/2024-election/democratic-operative-admits-commissioning-fake-biden-robocall-used-ai-rcna140402">street magician</a><a href="https://www.nbcnews.com/politics/2024-election/democratic-operative-admits-commissioning-fake-biden-robocall-used-ai-rcna140402">.</a> AI is poised to play a more volatile role than ever before in America’s next federal election in 2026. We can already see how different groups of political actors are approaching AI. Professional campaigners are using AI to accelerate the traditional tactics of electioneering; organizers are using it to reinvent how movements are built; and citizens are using it both to express themselves and amplify their side’s messaging. Because there are so few rules, and so little prospect of regulatory action, around AI’s role in politics, there is no oversight of these activities, and no safeguards against the dramatic potential impacts for our democracy...</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I thought the Bose QuietComfort headphones already hit their peak - then I tried the newest model]]></title>
<description><![CDATA[With the new QuietComfort Ultra 2, Bose doesn't try to reinvent the wheel. Instead, it's made strides in almost every essential aspect.]]></description>
<link>https://tsecurity.de/de/3035501/hacking/i-thought-the-bose-quietcomfort-headphones-already-hit-their-peak-then-i-tried-the-newest-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3035501/hacking/i-thought-the-bose-quietcomfort-headphones-already-hit-their-peak-then-i-tried-the-newest-model/</guid>
<pubDate>Sun, 12 Oct 2025 13:05:08 +0200</pubDate>
<content:encoded><![CDATA[With the new QuietComfort Ultra 2, Bose doesn't try to reinvent the wheel. Instead, it's made strides in almost every essential aspect.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI plans a small family of devices to reinvent human-computer interaction — but Sam Altman says "it'll take some time"]]></title>
<description><![CDATA[OpenAI's CEO recently revealed that the company is planning to develop a family of small AI-powered devices that will change how people interact with computers.]]></description>
<link>https://tsecurity.de/de/3016883/windows-tipps/openai-plans-a-small-family-of-devices-to-reinvent-human-computer-interaction-but-sam-altman-says-itll-take-some-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3016883/windows-tipps/openai-plans-a-small-family-of-devices-to-reinvent-human-computer-interaction-but-sam-altman-says-itll-take-some-time/</guid>
<pubDate>Thu, 02 Oct 2025 13:07:27 +0200</pubDate>
<content:encoded><![CDATA[OpenAI's CEO recently revealed that the company is planning to develop a family of small AI-powered devices that will change how people interact with computers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nadella Appoints New CEO To Run Microsoft's Biggest Businesses]]></title>
<description><![CDATA[Microsoft is promoting Judson Althoff, currently executive vice president and chief commercial officer at Microsoft, to a new role as CEO of its commercial business. From a report: It's the latest shakeup inside the company, as Microsoft navigates what CEO Satya Nadella calls a "tectonic AI platf...]]></description>
<link>https://tsecurity.de/de/3015469/it-security-nachrichten/nadella-appoints-new-ceo-to-run-microsofts-biggest-businesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3015469/it-security-nachrichten/nadella-appoints-new-ceo-to-run-microsofts-biggest-businesses/</guid>
<pubDate>Wed, 01 Oct 2025 18:18:29 +0200</pubDate>
<content:encoded><![CDATA[Microsoft is promoting Judson Althoff, currently executive vice president and chief commercial officer at Microsoft, to a new role as CEO of its commercial business. From a report: It's the latest shakeup inside the company, as Microsoft navigates what CEO Satya Nadella calls a "tectonic AI platform shift." It's also a move that will allow Nadella to focus on more technical work at Microsoft, while still remaining overall CEO. 

In an internal memo to employees today, Nadella announced Althoff's promotion and said it's linked with the need for Microsoft to reinvent itself in the AI era and "bring together sales, marketing, operations, and engineering to drive growth and strengthen our position as the partner of choice for AI transformation." Althoff has led Microsoft's global sales organization for the past nine years, helping the company build out its Microsoft Customer and Partner Solutions (MCAPS) division. He will now also be responsible for the operations and marketing teams that help sell Microsoft's software and services to businesses, but not the engineering teams that help build them.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Nadella+Appoints+New+CEO+To+Run+Microsoft's+Biggest+Businesses%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F10%2F01%2F1534253%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F10%2F01%2F1534253%2Fnadella-appoints-new-ceo-to-run-microsofts-biggest-businesses%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/25/10/01/1534253/nadella-appoints-new-ceo-to-run-microsofts-biggest-businesses?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How strategy and alignment can make or break your product launches]]></title>
<description><![CDATA[In Navigating the honeymoon phase of a new product launch, I stressed how important it is for product leaders to lay a strong foundation during the initial phase of product launch, or risk losing momentum and time due to rework, reestablishing credibility with your stakeholders and experiencing m...]]></description>
<link>https://tsecurity.de/de/3014751/it-security-nachrichten/how-strategy-and-alignment-can-make-or-break-your-product-launches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3014751/it-security-nachrichten/how-strategy-and-alignment-can-make-or-break-your-product-launches/</guid>
<pubDate>Wed, 01 Oct 2025 13:19:38 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In <a href="https://www.cio.com/article/4032054/navigating-the-honeymoon-phase-of-a-new-product-launch.html">Navigating the honeymoon phase of a new product launch</a>, I stressed how important it is for product leaders to lay a strong foundation during the initial phase of product launch, or risk losing momentum and time due to rework, reestablishing credibility with your stakeholders and experiencing misalignment on key goals and even the overall strategy.</p>



<p>Now I want to dig in deeper on strategy.</p>



<p>Launching a product is one of the most exciting (and daunting) moments in a company’s lifecycle. I’ve led teams through this process multiple times and have seen firsthand that the difference between a successful launch and a frustrating misstep often comes down to strategy. Strategy isn’t just having a vague idea of “what we want to build,” but a clear, repeatable and well-communicated strategy that aligns stakeholders, guides decision-making and withstands the inevitable challenges.</p>



<p>These are the principles I’ve developed over the years while leading product strategy at companies like Chronosphere and Splunk. My hope is to give other leaders a practical framework for approaching launches with discipline and confidence.</p>



<h2 class="wp-block-heading">Start with the why and build alignment</h2>



<p>One of the most common mistakes product leaders and the C-suite alike often make is assuming a strategy already exists. An idea exists, but an idea isn’t a strategy. Before building roadmaps or sprint plans, take a step back and think: Why are we doing this?</p>



<p>A <a href="https://longform.asmartbear.com/great-strategy/" target="_blank" rel="nofollow">strong strategy</a> rests on three foundations.</p>



<ol start="1" class="wp-block-list">
<li><strong>Market opportunity:</strong> Something has shifted or been overlooked in the market. Maybe existing vendors are overpriced, or an entire segment is underserved. Articulating the gap crisply is step one.</li>



<li><strong>Why us: </strong>Equally important is explaining why your company is best positioned to seize that opportunity. Is it brand reputation? Unique technology? Distribution reach? Stakeholders need to hear a credible reason why this isn’t just another good idea, but an idea that will succeed.</li>



<li><strong>How:</strong> How is your company realistically going to get there? Stakeholders and project teams are looking for something simple, believable, compelling and convincing.  This should be the 10-second version of the core pillars or standout capabilities of the roadmap. This is not the detailed roadmap.</li>
</ol>



<p>When I joined Chronosphere, for example, I knew getting engineering leaders invested early was critical. Their analytical perspective challenged me to refine assumptions and by the time we rolled out the strategy more broadly, it was already stress-tested. This early buy-in also turned them into my biggest champions, reinforcing the message across the organization.</p>



<p>According to research by consulting and training firm LSA Global, <a href="https://lsaglobal.com/insights/proprietary-methodology/lsa-3x-organizational-alignment-model/" target="_blank" rel="nofollow">companies that align product strategy with corporate strategy see significantly higher growth rates than their peers</a>. But alignment doesn’t happen by accident — it requires intentional conversations with stakeholders, often individually, before group settings, to avoid groupthink and uncover true expectations.</p>



<h2 class="wp-block-heading">Balance disruption with pragmatism</h2>



<p>Every product team wants to be disruptive, but disruption has to be strategic. I’ve seen teams try to reinvent every aspect of a product, from the UI to the backend to the go-to-market strategy, only to burn out. The truth is, not every part of a launch needs disruption.</p>



<p>Instead, I map out distinct phases for the first few years and identify where we will disrupt versus where we will follow. If a competitor is doing something right, I’m not afraid to take notes. In fact, in many cases, users have limits to how much disruption they can accept in a new product, and you must understand those limits. Ask yourself, are you another player in the market with some differentiation, or are you creating a market for something materially new? The former will have a higher mix of table stakes features relative to disruptive features versus the latter. Understanding and embracing the reality of which one of those you are doing will help you balance your investments in disruptive capabilities vs. table stakes.</p>



<p>Key takeaway: Disruption is only valuable when the market craves it.</p>



<p>South Park’s “Underpants Gnomes” episode captures this pitfall well:</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper youtube-video">

</div></figure>



<ul class="wp-block-list">
<li>Phase 1: Collect underpants</li>



<li>Phase 2: ?</li>



<li>Phase 3: Profit</li>
</ul>



<p>Without clear links between disruption and value creation, a strategy collapses into wishful thinking.</p>



<h2 class="wp-block-heading">Make the team co-owners of the strategy</h2>



<p>Strategies fail when they’re imposed. They succeed when teams feel ownership. At Chronosphere, before bringing stakeholders into the fold, I first iterated with engineering leaders. This not only improved the plan but also created internal advocates who could carry the message forward.</p>



<p>Giving teams skin in the game helps do two things:</p>



<ul class="wp-block-list">
<li>Strengthens the strategy itself, because people closest to the work sharpen the assumptions.</li>



<li>Ensures the strategy lives beyond the leadership team, because employees repeat it with genuine, authentic conviction.</li>
</ul>



<p>When stakeholders see excited teams, they trust the direction more. Excitement is contagious, and in my experience, it’s the best signal that a strategy will survive the ups and downs of execution.</p>



<h2 class="wp-block-heading">Repeat success criteria, make it your mantra</h2>



<p>Another hard lesson I learned at my former company, Splunk, was that success criteria can drift. Midway through a product’s lifecycle, stakeholders sometimes “remember” different goals than the ones we agreed on. The product under my purview exceeded revenue targets for several years, but because I hadn’t consistently repeated the strategy and success metrics, late-stage perceptions shifted. As a result, the product was seen as less successful than it really was.</p>



<p>That experience taught me the importance of ruthless clarity and repetition. A strategy should be explainable in five minutes without slides. I rehearse it until I can deliver it to a busy executive in an elevator ride. Then I repeat it — at all-hands, in board meetings, during one-on-ones — until people can recite it back.</p>



<p>Neuroscience<a href="https://neurosciencenews.com/rwpwtition-memory-26114/" rel="nofollow"> </a>shows <a href="https://neurosciencenews.com/rwpwtition-memory-26114/" target="_blank" rel="nofollow">repetition is how people internalize ideas</a>. In the context of product launches, repetition ensures the vision doesn’t get diluted as teams sprint toward delivery.</p>



<h2 class="wp-block-heading">Iterations and updates to strategy are expected</h2>



<p>Your strategy will be an evolving organism; very rarely can you consider it done and dusted the first time you craft it. Expect pivots, missed targets and unexpected obstacles. What matters is that you can evolve your strategy as you learn more. </p>



<p>However, while it is true that a strategy will evolve, a well-thought-out strategy will change when the underlying assumptions or real-world data change, and hopefully those will change infrequently.</p>



<h2 class="wp-block-heading">Strategy as the anchor</h2>



<p>Crafting a winning product strategy isn’t about writing a perfect document. It’s about building a living framework that aligns people, withstands pressure and guides tough decisions.</p>



<p>Every launch I’ve been part of has reinforced this: Ideas are plentiful, but disciplined strategies are rare. The leaders who can articulate a compelling “why,” repeat it until it sticks, balance disruption with pragmatism and bring their teams along for the ride are the ones who consistently turn launches into lasting successes.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Crowdsourced AI += Exodia Labs]]></title>
<description><![CDATA[We’re adding a new specialist to VirusTotal’s Crowdsourced AI lineup: Exodia Labs, with an AI engine focused on analyzing Chrome extension (.CRX) files. This complements our existing Code Insight and other AI contributors by helping users better understand this format and detect possible threats....]]></description>
<link>https://tsecurity.de/de/3014625/malware-trojaner-viren/crowdsourced-ai-exodia-labs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3014625/malware-trojaner-viren/crowdsourced-ai-exodia-labs/</guid>
<pubDate>Wed, 01 Oct 2025 12:16:49 +0200</pubDate>
<content:encoded><![CDATA[<p>We’re adding a new specialist to VirusTotal’s Crowdsourced AI lineup: <a href="https://exodialabs.xyz/">Exodia Labs</a>, with an AI engine focused on analyzing Chrome extension (.CRX) files. This complements our existing Code Insight and other AI contributors by helping users better understand this format and detect possible threats.
</p>
<p><b>What you get in VirusTotal</b></p>
<ul>
  <li><u>Second opinion for .CRX</u>: Exodia Labs adds another AI analysis stream alongside Code Insight. It gives a fresh, independent view on the same sample type. Like all Crowdsourced AI engines, it’s meant to complement (not replace) traditional detections and human analysis.
  </li><li><u>Clear verdict in the UI</u>: Each Exodia report includes a simple verdict (benign, suspicious, or malicious) to help you quickly spot risky extensions.
  </li><li><u>Searchable results in VT Intelligence</u>: You can now use new operators to search and pivot across Exodia Labs results:
  <ul>
    <li><i>exodialabs_ai_verdict:malicious | suspicious | benign</i> 
    </li><li><i>exodialabs_ai_analysis:&lt;keywords&gt;</i>
  </li></ul>
</li></ul>
<p><b>See it in action</b></p><p>
</p><p>Here are a few Exodia Labs AI report examples you can explore in VT:</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhf5DCISQRJk-fiZd41OvSHcMRzKyc6tPenUHpeVPFsjz07CUFr8BXa_H2Up4TyQdaqkbu1X4Lx7f1No3Y0786TRs7Vju6Fnf0KMZ9spZkIaudXZExhoJ87JXKw1dOivkkQXMiiYHNyi6rvLC38en6sLOpvoC7Viq041sDJlycM_tlWtSl6ef0BXfvVbe8/s1600/Screenshot%202025-10-01%2010.11.18.png"><img alt="" border="0" data-original-height="441" data-original-width="1233" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhf5DCISQRJk-fiZd41OvSHcMRzKyc6tPenUHpeVPFsjz07CUFr8BXa_H2Up4TyQdaqkbu1X4Lx7f1No3Y0786TRs7Vju6Fnf0KMZ9spZkIaudXZExhoJ87JXKw1dOivkkQXMiiYHNyi6rvLC38en6sLOpvoC7Viq041sDJlycM_tlWtSl6ef0BXfvVbe8/s1600/Screenshot%202025-10-01%2010.11.18.png"></a></div>
<a href="https://www.virustotal.com/gui/file/31da559ae4af91106e0a18740d6bb8916e2017f6a37a02ea2a8127f1da30ec77"><span><span>31da559ae4af91106e0a18740d6bb8916e2017f6a37a02ea2a8127f1da30ec77</span></span></a>
</center>
<br>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9ni_Uwcv_zx2pEW-c1aFyRULwx3CE0ED_j7T_YXJajjbYxZ-OybLqeForU0wunEt8smU3RIVhiaIKttqIhNUcfDvtOR6Maa6wWox9q8sVnUY6kuX-WZZ-ve9_OGdo26aCqZ51i31Wjy8Gku3aGePgmQ4gC_2Fze5tQ1_tJ4b_PtKf-X7c_5Oomj6E1z0/s1600/Screenshot%202025-10-01%2010.13.41.png"><img alt="" border="0" data-original-height="479" data-original-width="1255" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9ni_Uwcv_zx2pEW-c1aFyRULwx3CE0ED_j7T_YXJajjbYxZ-OybLqeForU0wunEt8smU3RIVhiaIKttqIhNUcfDvtOR6Maa6wWox9q8sVnUY6kuX-WZZ-ve9_OGdo26aCqZ51i31Wjy8Gku3aGePgmQ4gC_2Fze5tQ1_tJ4b_PtKf-X7c_5Oomj6E1z0/s1600/Screenshot%202025-10-01%2010.13.41.png"></a></div>
<a href="https://www.virustotal.com/gui/file/69c926ea84536bdaba7e4f765bde65eb0199ac30be3a96729a21ea7efa48d721"><span><span>69c926ea84536bdaba7e4f765bde65eb0199ac30be3a96729a21ea7efa48d721</span></span></a>
</center>  
<br>
<p>You can also explore Exodia Labs verdicts at scale using VirusTotal Intelligence.</p>
<p>For example, the following query lists Chrome extensions flagged as malicious and related to financial activity: <i>exodialabs_ai_verdict:malicious AND exodialabs_ai_analysis:financial</i></p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixVbwEu7G8CC4TBh_w82y96Rb-dmpOwoXnzI9pk_P6dwKt1zYvmM72MQ_by3tC8GbKp1HnDsonwpmOcmq5uK68LoamTkBe9NIwhvTppYigWRTYk2CAe0OLm8YPDQfxKzWR3-9FCnLsCXQRovwtsBQAkchd9TQP0wBSugWNVdLA362Qn0GsCu0cFzGlgiQ/s1600/Screenshot%202025-10-01%2010.24.06.png"><img alt="" border="0" data-original-height="956" data-original-width="1675" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixVbwEu7G8CC4TBh_w82y96Rb-dmpOwoXnzI9pk_P6dwKt1zYvmM72MQ_by3tC8GbKp1HnDsonwpmOcmq5uK68LoamTkBe9NIwhvTppYigWRTYk2CAe0OLm8YPDQfxKzWR3-9FCnLsCXQRovwtsBQAkchd9TQP0wBSugWNVdLA362Qn0GsCu0cFzGlgiQ/s1600/Screenshot%202025-10-01%2010.24.06.png"></a></div>
</center>
<br>
<p>This search shows several .CRX files where Exodia Labs AI detected suspicious financial behavior.</p>
<p>Let’s look at two examples:</p>
<ul>
  <li><u>Westpac Extension</u>: Exodia Labs flags it as malicious. The AI analysis shows the extension connects to a remote WebSocket server and exfiltrates cookies, one-time passwords, and payment tokens. It manipulates banking pages and forwards captured credentials to a C2, showing signs of credential theft and financial data tampering.
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2QdV_Xx3KMMdkFJJ7CSAeNLs1CwkyX_pKVGEp74CDvV4hwnyG2WbVR7q32YSBL7xW67eVR_AXytez9zgYCoEruflFGS8mD1cYkZ6oYq8UScxslr2I0Hv_JZ0ITH6ezph84B7nmApWwgIet0NnGNBbLgoklZyA2CoFteTjDVKG0N__uuhB-vTyi1HduqI/s1600/Screenshot%202025-10-01%2010.26.07.png"><img alt="" border="0" data-original-height="1096" data-original-width="1323" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2QdV_Xx3KMMdkFJJ7CSAeNLs1CwkyX_pKVGEp74CDvV4hwnyG2WbVR7q32YSBL7xW67eVR_AXytez9zgYCoEruflFGS8mD1cYkZ6oYq8UScxslr2I0Hv_JZ0ITH6ezph84B7nmApWwgIet0NnGNBbLgoklZyA2CoFteTjDVKG0N__uuhB-vTyi1HduqI/s1600/Screenshot%202025-10-01%2010.26.07.png"></a></div>
<a href="https://www.virustotal.com/gui/file/34244257f633e104d06b0c4273caca96eb916d26540eeea68495707cbc920bdb"><span><span>34244257f633e104d06b0c4273caca96eb916d26540eeea68495707cbc920bdb</span></span></a>
  </center>
  <br>
  </li><li><u>Spidy Extension</u>: Also flagged as malicious. The analysis shows it requests <all_urls> and cookies permissions, executes remote crawling jobs, and collects user profile and bank account details. The extension behaves like a data-exfiltration client handling financial credentials not mentioned in its public description.
<center>
    <div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikOVzzqBrCyr6qjnbu3D7ln8VSAcVZkhRdIln9gEAUwF00DX9fqNZHAeWQJm7xtLehlUNajGmh1kqJHk3IYPtOAYqSrA5YJ6NkY30ynzq8xPG-nq5j_2H8M6oakRw7pqDzsBQMUIwqqtOZXlmgjGH32-G0i2Doj9pV0gEVfpV0BcT300mfwee15o_HAKI/s1600/Screenshot%202025-10-01%2010.27.17.png"><img alt="" border="0" data-original-height="1062" data-original-width="1323" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikOVzzqBrCyr6qjnbu3D7ln8VSAcVZkhRdIln9gEAUwF00DX9fqNZHAeWQJm7xtLehlUNajGmh1kqJHk3IYPtOAYqSrA5YJ6NkY30ynzq8xPG-nq5j_2H8M6oakRw7pqDzsBQMUIwqqtOZXlmgjGH32-G0i2Doj9pV0gEVfpV0BcT300mfwee15o_HAKI/s1600/Screenshot%202025-10-01%2010.27.17.png"></a></div>
<a href="https://www.virustotal.com/gui/file/718eab32b5597e479d63f1d4e6402b7844eb9a4ee01c9028e44eb202d5ebcb2f"><span><span>718eab32b5597e479d63f1d4e6402b7844eb9a4ee01c9028e44eb202d5ebcb2f</span></span></a>
    </center>
  </all_urls></li></ul>
<p><b>About Exodia Labs</b></p>
<p>Exodia Labs builds AI-driven analysis for Chrome Web Store extensions, also exposing a <a href="https://chromewebstore.google.com/detail/exo-sentinel-ai-for-googl/hmhdbojifpgbfkbojpjkdmknpfgdcheg">browser add-on</a> that lets users request an AI assessment directly from an extension’s store page and view a detailed report plus a verdict. For security teams, the same analysis powers the backend results we index in VirusTotal.</p>
<p><b>Join Crowdsourced AI</b></p>
<p>Crowdsourced AI is about aggregating independent AI solutions that explain behavior and provide judgments across many file types, helping you understand unfamiliar code faster and spot novel threats sooner. If you build AI models that can help the community, we want to hear from you. 
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[M5 iPad Pro leak shows 35% GPU boost – better for gaming?]]></title>
<description><![CDATA[Apple hasn’t announced the M5 iPad Pro yet, but early leaks suggest the tablet could deliver a significant leap in graphics performance. A pre-release unit tested ahead of launch shows a roughly 35% GPU improvement over last year’s M4 model, which could make a noticeable difference for graphic-in...]]></description>
<link>https://tsecurity.de/de/3013839/ios-mac-os/m5-ipad-pro-leak-shows-35-gpu-boost-better-for-gaming/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3013839/ios-mac-os/m5-ipad-pro-leak-shows-35-gpu-boost-better-for-gaming/</guid>
<pubDate>Wed, 01 Oct 2025 02:24:53 +0200</pubDate>
<content:encoded><![CDATA[Apple hasn’t announced the M5 iPad Pro yet, but early leaks suggest the tablet could deliver a significant leap in graphics performance. A pre-release unit tested ahead of launch shows a roughly 35% GPU improvement over last year’s M4 model, which could make a noticeable difference for graphic-intensive apps and games.



Early Look at Apple’s Unreleased M5 iPad Pro



Russian tech channel Wylsacom published what appears to be the first unboxing and benchmark tests of the new iPad Pro with Apple’s M5 chip. According to the channel, the model tested was a 13-inch Wi-Fi variant with 256 GB of storage.



At first glance, Apple hasn’t changed much in terms of hardware design. The M5 iPad Pro keeps the same size, colors, and chassis as the M4 version. Even existing accessories like the Magic Keyboard and Folio case remain compatible. This continuity may disappoint users expecting a visual refresh, but the real changes are under the hood.



Benchmark Results Show Significant GPU Gains







The leaked benchmark data points to a major performance bump where it matters most for demanding tasks: graphics. Geekbench 6 scores show:




Single-core performance: 10% faster



Multi-core performance: 15% faster



GPU performance: 34–35% faster




In real terms, this means the M5 iPad Pro can render complex visuals, run 3D design tools, and process effects-heavy content more efficiently. Games that struggled to hit consistent frame rates on the M4 could now run more smoothly. Even though the iPad Pro is not marketed as a gaming tablet, this level of GPU growth is enough to push it closer to dedicated gaming devices.



Better for Creators and Power Users Too



A stronger GPU doesn’t just benefit games. Apps like Final Cut Pro, Blender, and high-end AR tools rely heavily on graphics performance. If the leaked numbers hold true, the M5 iPad Pro could handle these workflows more comfortably, especially paired with the increased 12 GB RAM (up from 8 GB on the M4).



The leak also notes full compatibility with existing accessories and iPadOS 26 optimizations, including new interface customization options. That suggests Apple is positioning the M5 iPad Pro as a drop-in upgrade for current users rather than a radical redesign.



If you use the iPad Pro for graphic design, 3D modeling, or video editing, the 35% GPU bump is more than a spec-sheet detail. It could directly translate to faster renders and smoother multitasking. And while the iPad Pro still won’t replace a gaming console, this jump makes it more capable of handling demanding titles from the App Store or streaming platforms.



The M5 iPad Pro doesn’t reinvent Apple’s tablet, but its graphics gains make it the most powerful iPad yet. If performance matters more to you than a new design, this generation might be worth the upgrade.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple refreshes Beats lineup with Powerbeats Fit]]></title>
<description><![CDATA[Apple is refreshing its fitness-focused audio lineup with the launch of the Powerbeats Fit, a direct successor to the popular Beats Fit Pro from 2021. The new earbuds replace the older model under the Powerbeats branding while keeping the same $200 price tag. The focus this time is not on reinven...]]></description>
<link>https://tsecurity.de/de/3013389/ios-mac-os/apple-refreshes-beats-lineup-with-powerbeats-fit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3013389/ios-mac-os/apple-refreshes-beats-lineup-with-powerbeats-fit/</guid>
<pubDate>Tue, 30 Sep 2025 19:36:50 +0200</pubDate>
<content:encoded><![CDATA[Apple is refreshing its fitness-focused audio lineup with the launch of the Powerbeats Fit, a direct successor to the popular Beats Fit Pro from 2021. The new earbuds replace the older model under the Powerbeats branding while keeping the same $200 price tag. The focus this time is not on reinventing the product, but on refining the experience with a more comfortable fit, a smaller case, and a few practical updates designed for everyday use.



Focus on comfort and fit



The biggest change in the Powerbeats Fit is how they feel in your ears. Beats redesigned the wingtip with 20% more flexibility, aiming for a snug, secure fit without the fatigue some users reported with the previous model. That extra flexibility makes them suitable for long listening sessions, not just workouts.



The earbuds now ship with four ear tip sizes instead of three, including a new extra-small option for better customization. This small but useful change improves noise isolation and helps you get the most out of the active noise canceling (ANC) performance.



Apple also trimmed the charging case by 17%, making it easier to slip into a pocket or gym bag. Like the earbuds, the case is now IPX4-rated for moisture resistance, which means it can handle sweat and light splashes, an essential feature if you plan to use them during workouts or outdoor runs.



Small design tweaks, familiar performance



Apart from the improved comfort, much of what users liked about the Beats Fit Pro returns here. The Powerbeats Fit runs on Apple’s H1 chip, powering features like:




Active Noise Cancellation and Transparency mode



Personalized Spatial Audio with dynamic head tracking



Adaptive EQ for sound tuning



Audio Sharing and automatic device switching



Hands-free Siri and Find My support




The earbuds also retain physical button controls instead of touch-sensitive panels, which many users still prefer for accuracy during workouts. Battery life remains unchanged too: 6 hours with ANC on and 7 hours without it, with up to 30 hours total when using the charging case. A 5-minute Fast Fuel charge provides up to an hour of playback.



Support across iOS




https://youtu.be/K2fvFZw84Xo




If you’re using an iPhone, Powerbeats Fit integrates directly into iOS settings. Android users can access similar controls through a dedicated Beats app, which offers customizable controls, battery status, Locate My Beats, and an ear tip fit test. Both platforms support one-touch pairing, so setup is straightforward regardless of which device you use.



Apple’s positioning for Powerbeats Fit



In a statement, Oliver Schusser, Apple’s vice president of Music, Sports, and Beats, said the move to rebrand the lineup was intentional:




“Reintroducing Beats Fit Pro as Powerbeats Fit — alongside Powerbeats Pro 2 — unifies our lineup under a name synonymous with athletic performance and gives customers a clearer choice between two distinct, fitness-first form factors. Powerbeats Fit combines the best of Beats Fit Pro with next-level comfort, durability, and portability — making it a worthy addition to the Powerbeats family.”




Availability and final details



Powerbeats Fit is available for preorder now for $199.99, with four color options: Jet Black, Gravel Gray, Spark Orange, and Power Pink. Retail availability begins October 2.



What this update shows is Apple’s shift in strategy for Beats: rather than chase radical redesigns every year, it’s doubling down on small, meaningful changes that make the listening experience better. The Powerbeats Fit doesn’t try to reinvent what worked, but it polishes the formula and that might be exactly what users want.]]></content:encoded>
</item>
<item>
<title><![CDATA[The broken economics of AI require a full-stack fix]]></title>
<description><![CDATA[A new era of AI is taking shape. Over the last year, the demand for deploying trained models in real-time applications has surged, along with a continuous stream of challengers and disruptors entering the scene. AI inference, the process of using a trained AI model to make predictions or decision...]]></description>
<link>https://tsecurity.de/de/3012635/it-security-nachrichten/the-broken-economics-of-ai-require-a-full-stack-fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3012635/it-security-nachrichten/the-broken-economics-of-ai-require-a-full-stack-fix/</guid>
<pubDate>Tue, 30 Sep 2025 14:19:29 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A new era of AI is taking shape. Over the last year, the demand for deploying trained models in real-time applications has surged, along with a continuous stream of challengers and disruptors entering the scene. AI inference, the process of using a trained AI model to make predictions or decisions by crunching new data inside neural-networked systems, has become a critical and complex growth area. It’s backed by deep investment and <a href="https://www.marketsandmarkets.com/PressReleases/ai-inference.asp#:~:text=The%20report%20%22AI%20Inference%20Market,19.2%25%20from%202025%20to%202030." target="_blank" rel="nofollow">projected to grow</a> at a compound annual growth rate (CAGR) of 19.2% through 2030.</p>



<p>Right now, a top concern across the industry is simple: We need to process significantly more data (tokens) through more AI models for dramatically less cost. Processing inference AI tokens is 10 to 100 times more expensive than it should be, forming a challenging barrier to entry that cuts across a wide variety of use cases with different input data modalities such as text, image, video and audio, as well as multimodal combinations of them.</p>



<p>Complexity and cost are tightly connected. Model size, data movement and computational demands all stack up and every one of them impacts ROI. To move beyond limited pilot programs and into real business impact, we must confront this challenge head-on.</p>



<p>We need to fix the broken economics to unlock adoption. Until the cost curve is repaired, we will fall short of realizing AI’s full potential for enhancing existing markets and creating new ones.</p>



<p>In the race to commoditize generative and agentic AI tokens, the winners will be those who can deliver the best, fastest and most cost-effective options. To get there, we must break with legacy assumptions.</p>



<h2 class="wp-block-heading">What led us here</h2>



<p>Looking back at the deep learning revolution, everything changed with AlexNet’s breakthrough in 2012. That neural network shattered image-recognition accuracy records and proved deep learning could deliver game-changing results.</p>



<p>What made AlexNet possible? Nvidia’s GPU. Originally built for gaming, it turned out GPUs were well-suited for the massive, repetitive calculations of neural networks. Nvidia had already invested in making GPUs programmable for general-purpose computing for HPC workloads, giving them a huge head start when AI erupted.</p>



<p>GPU performance for AI began outpacing CPUs at an exponential rate, leading to what became known as Huang’s Law: the observation that AI performance on GPUs doubles every 12 to 18 months. Unlike Moore’s Law, Huang’s Law is holding strong, fueled by a more parallelized GPU architecture and the evolving system architecture surrounding it.</p>



<p>Which brings us to today. We have powerful GPUs and custom AI accelerators, aka XPUs, but we’re connecting them to an infrastructure built with repurposed legacy CPUs and NICs. It’s like putting a Ferrari engine into a go-kart.</p>



<p>The legacy x86 architecture used by most AI servers’ CPU head nodes isn’t built to keep up with AI. It’s a general-purpose processor that can’t maintain the volume and velocity of processing required of the AI server’s head node by ever-evolving AI workloads. It ends up leaving expensive GPUs sitting idle, underutilized and underperforming.</p>



<p>One GPU is not sufficient anymore, so bigger arrays of GPUs are now used. They form a larger virtual processor to run those huge models and do it faster, which improves user experience and offers faster response time to agents in need of multiple iterations of model querying. Improved network connectivity and data transfer time between GPUs is now critical so GPUs will not be wasted waiting on data.</p>



<h2 class="wp-block-heading">Employing the full stack</h2>



<p>AI needs massive data flows in the blink of an eye (actually, much faster than that). To drive the cost-per-data-token down toward near zero, we need a full-stack approach with smarter software, purpose-built hardware and intelligent orchestration.</p>



<p>On the hardware side, GPUs and other XPUs are evolving rapidly. Their performance is improving year over year and not just because of more transistors, but because of better architecture, tighter integration and faster memory. Huang’s Law continues to deliver.</p>



<p>But these powerful AI processors are held back by the systems they’re embedded in. It’s like lining up Ferraris and asking them to race during rush-hour traffic.</p>



<p>New classes of specialized AI chips are emerging, fundamentally transforming computing, connectivity and networking for AI. This isn’t another GPU or XPU; it’s innovation at the core of the system — both from the head-node side as well as from the scale-up and scale-out network sides. These AI-optimized, purpose-built chips are masters of traffic control and processing that enable GPUs to run at full speed.</p>



<p>It is increasingly clear that we need faster, smarter, compute-enabled and AI-optimized NICs natively integrated into those evolving networking frameworks and stacks (nCCL, xCCL, etc.) while bypassing the CPU during data-transferring stages. The network becomes not just a superhighway, but part of the brain of the operation. These new NICs can adapt to new and future protocols designed for AI and HPC, like the <a href="https://ultraethernet.org/wp-content/uploads/sites/20/2025/06/UEC1.0Whitepaper.pdf" target="_blank" rel="nofollow">ultra ethernet protocol</a>.</p>



<p>On the software side, we’re seeing major advances. Techniques like pruning and knowledge distillation help make models faster, lighter and more efficient. Smaller models, like DeepSeek, outperform expectations by optimizing and balancing inference compute and data flows.</p>



<p>To truly reduce the cost-per-AI-token, everything across the stack must work in sync, from silicon and software to system design. The right combination can enable this synchronization to bring down costs while delivering new levels of performance.</p>



<h2 class="wp-block-heading">The path to zero marginal cost</h2>



<p>AI inference costs remain stubbornly high, even with massive capital investment. Tech companies and cloud providers often run at negative margins, pouring money into inefficient systems that were never designed for the demands of modern inference.</p>



<p>The fundamental issue is marginal cost. In any scalable business, success depends on driving down the cost of producing one more unit. That’s what makes them profitable and what made the whole SaaS business viable and scalable.</p>



<p>The same principle applies to AI. To be truly transformative, the cost of generating additional tokens needs to approach zero. That’s when the market stops subsidizing and starts extracting real, repeatable business value.</p>



<p>We can get there by closing the gap between Moore’s Law and Huang’s Law and by making sure networks leap ahead of GPUs. Doing so demands architecture that works with, not against, the GPUs and XPUs already leading progress.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.<br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone 1 (2G) vs iPhone 17 Pro Max: Look at 18 Years of Progress]]></title>
<description><![CDATA[When Steve Jobs walked onto the stage at Macworld in January 2007 and said, “Today, Apple is going to reinvent the phone,” he wasn’t exaggerating. The original iPhone wasn’t just another gadget. It was the moment the phone stopped being a phone and became a pocket-sized computer. Fast forward 18 ...]]></description>
<link>https://tsecurity.de/de/3008663/ios-mac-os/iphone-1-2g-vs-iphone-17-pro-max-look-at-18-years-of-progress/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3008663/ios-mac-os/iphone-1-2g-vs-iphone-17-pro-max-look-at-18-years-of-progress/</guid>
<pubDate>Sun, 28 Sep 2025 11:21:01 +0200</pubDate>
<content:encoded><![CDATA[When Steve Jobs walked onto the stage at Macworld in January 2007 and said, “Today, Apple is going to reinvent the phone,” he wasn’t exaggerating. The original iPhone wasn’t just another gadget. It was the moment the phone stopped being a phone and became a pocket-sized computer. Fast forward 18 years, and the iPhone 17 Pro Max shows how far that idea has evolved, and how much of that original vision still shapes what we hold in our hands.



Risky Bet to a Global Standard



The first iPhone was a gamble. Apple had never built a phone, and the market was ruled by BlackBerry, Nokia, and Motorola. Jobs insisted on removing the physical keyboard, betting on a multi-touch display that could change its interface on the fly. That decision defined the next two decades of mobile computing.







Leadership played a key role in that evolution. Under Jobs, Apple’s early iPhones were about breaking conventions: no stylus, no removable battery, no cluttered interface. When Tim Cook took over in 2011, the focus shifted toward scale and refinement, with bigger screens, faster chips, longer battery life, and deeper ecosystem integration. Today, Apple sells over 200 million iPhones a year, and the device has become the company’s single most important product.



Then vs Now



Eighteen years is a lifetime in tech. Here’s how far the iPhone has come since 2007:



FeatureiPhone 1 (2007)iPhone 17 Pro Max (2025)Display3.5-inch LCD, 320×4806.9-inch OLED, 2868×1320, 120HzChipsetSamsung S5L8900, 412 MHzApple A19 Pro, 4.26 GHz + 2.6 GHzRAM128 MB12 GBStorage Options4 GB, 8 GB, 16 GB256 GB, 512 GB, 1 TB, 2 TBRear Camera2 MP, no videoTriple 48 MP, 8K ProRes, LiDARBattery~1400 mAh~5088 mAhCharging5W (30-pin)Up to 40W USB-CBuildAluminum &amp; plastic backAluminum &amp; Ceramic ShieldConnectivity2G EDGE5G, Wi-Fi 7, UWB 2OS at LaunchiPhone OS 1iOS 26Price at Launch$499 (4 GB)~$1199 (256 GB)



Evolution Beyond Specs



The numbers alone don’t tell the whole story. In 2007, iPhone OS didn’t support third-party apps, copy-paste, or even video recording. Yet its clean design and fluid gestures made everything else feel obsolete overnight. Apple built the App Store a year later, transforming the phone into a platform and creating an entire economy around mobile software.



Each new generation pushed the concept forward. The A-series chips turned iPhones into performance leaders. The camera system evolved from a simple sensor into a professional-grade imaging tool. And services like iCloud, Apple Pay, and iMessage made the iPhone more than hardware. They made it the center of a digital life.



From Idea to Infrastructure



The first iPhone created a foundation. The iPhone 17 Pro Max builds on it with capabilities Jobs couldn’t have imagined in 2007, including on-device AI processing, ProRes video capture, satellite communication, and machine learning models running locally. Yet the essence is the same. A single slab of glass and metal that adapts to your needs.



Eighteen years ago, Apple sold a dream. A phone that redefined what a phone could be. Today, it sells time. Faster tasks. Longer battery life. Cameras that replace your DSLR. Processing power that rivals laptops. The iPhone’s evolution isn’t just about better specs. It’s about how a bold idea became the standard for how we live, work, and connect.]]></content:encoded>
</item>
<item>
<title><![CDATA[From naval officer to tech executive: Lessons in reinventing leadership]]></title>
<description><![CDATA[Engines dead. Five Beaufort winds. A patrol ship drifting in open water. Twenty men staring at me — waiting for direction, waiting for calm, waiting for a decision. In those thirty minutes, while we fought to restart the engines, I felt the weight of accountability in its purest form. Fear was on...]]></description>
<link>https://tsecurity.de/de/3006130/it-security-nachrichten/from-naval-officer-to-tech-executive-lessons-in-reinventing-leadership/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3006130/it-security-nachrichten/from-naval-officer-to-tech-executive-lessons-in-reinventing-leadership/</guid>
<pubDate>Fri, 26 Sep 2025 14:19:57 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Engines dead. Five Beaufort winds. A patrol ship drifting in open water. Twenty men staring at me — waiting for direction, waiting for calm, waiting for a decision. In those thirty minutes, while we fought to restart the engines, I felt the weight of accountability in its purest form. Fear was on every face, including mine. My first job wasn’t to solve the problem — it was to steady myself so that I could steady them. Only then could we focus on the solution instead of the danger surrounding us.</p>



<p>Years later, as I led technology teams, I realized how familiar that feeling was. A system crash, a cyber incident, a project spiraling off-course — the team looks to the CIO in the same way my crew looked at me on that ship. The data is incomplete, the risks are real and the clock is merciless. And just like at sea, calm is contagious. If the leader panics, the team collapses.</p>



<p>My career has taken me from commanding a naval vessel to writing code as a junior engineer, to founding a company and eventually to executive roles leading global technology initiatives. Every stage forced me to reinvent myself, often painfully, always urgently. Reinvention isn’t optional — it’s the core skill that has kept me relevant across two completely different worlds.</p>



<p>That’s why I believe reinvention is the defining leadership challenge for today’s CIOs. Technology changes every day, regulations arrive faster than roadmaps and boards expect transformation without excuses. The leaders who thrive are the ones who can pivot, absorb pressure and help others rise to challenges they didn’t think they could handle.</p>



<h2 class="wp-block-heading">Reinventing teams</h2>



<p>On one mission, my crew and I were ordered to leave our base for more than two months, sailing to unknown ports with little certainty about what awaited us. At first, I worried about morale — long separations from home, new routines, constant change. I expected resistance, maybe even complaints. But something surprising happened. Once I set the expectation that this was our mission and we would succeed together, the crew adapted. More than that, they performed better than I thought possible.</p>



<p>It taught me a lasting lesson: people rise to the expectations you set. If you frame change as a burden, they’ll feel burdened. If you frame it as a mission, they’ll find the strength they didn’t know they had.</p>



<p>For CIOs, the same truth applies. Moving teams from on-prem to cloud, from waterfall to <a href="https://agilemanifesto.org/" target="_blank" rel="nofollow">Agile</a> or from manual workflows to AI-driven automation will always be uncomfortable. Leaders who over-index on empathy risk reinforcing fear. Leaders who set confident expectations create confidence in others.</p>



<h2 class="wp-block-heading">Pivoting with discipline</h2>



<p>When I left the Navy and entered the technology industry, I learned quickly that plans rarely survive the first contact. Early on, I embraced agile as a way to adapt. And while agile has undeniable value, I also saw how it can become an excuse for chaos. Too often, teams skipped preparation and architecture, assuming they could “pivot later.” The result wasn’t agility — it was debt.</p>



<p>As a CEO, I discovered the hard way that the quality of a Statement of Work (SoW) often determines the quality of the relationship. A strong SoW builds clarity and trust. A weak one breeds confusion and conflict. Agile doesn’t change that truth. Pivoting can be necessary, but without preparation and strong architecture, you’re not adapting — you’re gambling.</p>



<p>For CIOs, agility is vital, but it cannot replace discipline. The most vigorous transformations strike a balance between adaptability and structure, so pivots occur on a solid foundation.</p>



<h2 class="wp-block-heading">The power of letting go</h2>



<p>When I became CEO of my own firm, I thought the best way to protect the company was to be everywhere at once. In the morning, I was the project manager in the trenches with the client’s technical team. In the evening, I was the CEO negotiating with their executives. When a large customer tried to change the scope just weeks before delivery, I realized I had created the opposite effect. By being both PM and CEO, I blurred the lines, weakened our position and allowed the client to take us for granted.</p>



<p>We pulled through the project, but the lesson stuck: when leaders try to do everything, they actually harm the organization. They don’t give their teams room to grow, they dilute their authority and they create unhealthy dynamics with stakeholders.</p>



<p>CIOs often fall into the same trap. Out of responsibility, they insert themselves into every decision, every firefight, every meeting. But the higher the role, the more damaging this becomes. Authentic leadership is about empowering others while maintaining your authority for the moments that truly matter. Delegation isn’t abdication — it’s how organizations build strength.</p>



<h2 class="wp-block-heading">Reinventing self</h2>



<p>For years, I defined myself as an engineer. My job was to build what I was told to make. But over time, working side by side with customers, I realized the real value wasn’t in the code — it was in understanding what should be built. Customers didn’t always articulate needs in technical terms. Translating those fragments into real solutions was a different kind of leadership.</p>



<p>That was the moment I crossed the line from technologist to executive. Technology was no longer the end in itself — it was the tool. My responsibility had shifted from execution to vision, from building things right to creating the right things.</p>



<p>CIOs face a similar transformation. For decades, the role was centered on custodianship: maintaining systems, controlling costs and managing risks. Today, the CIO must be a strategist, shaping digital vision and influencing enterprise direction. Reinventing yourself from executor to visionary isn’t optional. It’s survival.</p>



<h2 class="wp-block-heading">Staying relevant</h2>



<p>When I transitioned from the Navy into tech, I didn’t have the luxury of endless resources. I had a 256MB USB stick and an internet café. I’d download documentation at night, study it after duty and repeat the next day — all while raising two young daughters. There was no shortcut, just focus and perseverance.</p>



<p>That discipline has been my most valuable asset. Today, I see professionals with smartphones, cloud platforms and AI copilots at their fingertips — yet many struggle to focus for more than a few seconds. The tools are better, but the mindset is weaker.</p>



<p>For CIOs, this isn’t just nostalgia. As <a href="https://hbr.org/2025/08/soft-skills-matter-now-more-than-ever-according-to-new-research" target="_blank" rel="nofollow">Harvard Business Review has discussed</a>, the half-life of knowledge is shrinking. What you know today may be irrelevant in twelve months. Reinvention requires continuous learning, the ability to block out noise and the discipline to focus when it matters. Tools change. Leadership discipline doesn’t.</p>



<h2 class="wp-block-heading">My 5 rules of reinvention</h2>



<p>Across both my naval and technology careers, I’ve found five rules that hold in any environment:</p>



<ol class="wp-block-list">
<li><strong>Calm is contagious.  </strong>Before addressing your team in a crisis, take two minutes to steady yourself — breathe, clarify the top priority, then communicate with focus.</li>



<li><strong>Expectations shape performance. </strong>Frame reskilling or transformation not as a burden, but as a mission. Instead of asking, “What worries you?”ask, “How will we make this succeed together?”</li>



<li><strong>Discipline anchors agility. </strong>When launching any major initiative, insist on a written “minimum viable architecture.” It doesn’t need to be perfect, but it must exist before pivots begin.</li>



<li><strong>Delegation builds authority. </strong>In your next project, identify one decision you usually make yourself — and assign it fully to a lieutenant. Then support their decision publicly.</li>



<li><strong>Focus is a superpower. </strong>Block two hours weekly in your calendar for uninterrupted learning or deep work. Treat it with the same respect as a board meeting — immovable and protected.</li>
</ol>



<h2 class="wp-block-heading">Reinvention as a leadership imperative</h2>



<p>Leadership, in every chapter of my career, has been reinvention. On a ship with no engines, I had to reinvent fear into focus. On long deployments, I had to reinvent uncertainty into confidence. In technology, I’ve had to reinvent failed plans into disciplined pivots, personal failures into lessons and myself from engineer into strategist.</p>



<p>CIOs face the same reality every day. Systems will fail. Strategies will collapse. Regulations like the<a href="https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence" target="_blank" rel="nofollow"> EU AI Act</a> will reshape compliance. Teams will resist new directions. None of that is optional. What is optional is how leaders respond: whether they cling to old habits or reinvent themselves and their organizations for the next challenge.</p>



<p>Technology will keep evolving daily. The leadership challenge doesn’t change. Reinvention isn’t a one-time act. It is the CIO’s career. And those who embrace it won’t just survive disruption — they’ll define the future of their enterprises.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><strong><br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.15 brings fixes for ROG Ally, Legion Go, wake-on-bluetooth returns for Steam Deck LCD and more]]></title>
<description><![CDATA[Valve released SteamOS 3.7.15 stable bringing improvements for the Steam Deck, Asus ROG Ally, Lenovo Legion Go and lots of security issues fixed..Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3005776/linux-tipps/steamos-3715-brings-fixes-for-rog-ally-legion-go-wake-on-bluetooth-returns-for-steam-deck-lcd-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3005776/linux-tipps/steamos-3715-brings-fixes-for-rog-ally-legion-go-wake-on-bluetooth-returns-for-steam-deck-lcd-and-more/</guid>
<pubDate>Fri, 26 Sep 2025 11:07:30 +0200</pubDate>
<content:encoded><![CDATA[Valve released SteamOS 3.7.15 stable bringing improvements for the Steam Deck, Asus ROG Ally, Lenovo Legion Go and lots of security issues fixed.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt>.</p><p>Read the full article on <a href="https://www.gamingonlinux.com/2025/09/steamos-3-7-15-brings-fixes-for-rog-ally-legion-go-wake-on-bluetooth-returns-for-steam-deck-lcd-and-more/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025]]></title>
<description><![CDATA[Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025

      
      
        
          
            
                



            
          
        
              
    
  Oliver Altvater
Fr., 26.09.2025 - 07:30


            Machen Sie Ihre Cloud- und Virtualisierungsinfrastruktur...]]></description>
<link>https://tsecurity.de/de/3005442/server/der-admin-leitfaden-cloud-und-virtualisierungssicherheit-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3005442/server/der-admin-leitfaden-cloud-und-virtualisierungssicherheit-2025/</guid>
<pubDate>Fri, 26 Sep 2025 08:50:24 +0200</pubDate>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/leitfaden-cloud-und-virtualisierungssicherheit"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Titelbild_Admin-Leitfaden_Cloud-%20und%20Virtualisierungssicherheit%202025.jpg?itok=UZWTy-FV" width="480" height="319" alt="Vektorgrafische Darstellung der Cloud- und Virtualisierungssicherheit" title="Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/146" lang about="https://www.it-administrator.de/user/146" typeof="schema:Person" property="schema:name" datatype class="username">Oliver Altvater</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2025-09-26T07:30:00+02:00" title="Freitag, September 26, 2025 - 07:30" class="datetime">Fr., 26.09.2025 - 07:30</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Machen Sie Ihre Cloud- und Virtualisierungsinfrastruktur mit diesem praktischen Admin-Leitfaden sofort sicherer. Entwickeln Sie mit praxisnahen Einblicken, konkreten Konfigurations-Tipps und hilfreichen Checklisten ein ganzheitliches Sicherheitskonzept und etablieren Sie Sicherheit als kontinuierlichen Prozess.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/grundlagen" hreflang="en">Grundlagen</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/leitfaden-cloud-und-virtualisierungssicherheit" rel="tag" title="Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025" hreflang="en">Weiterlesen<span class="visually-hidden"> über Der Admin-Leitfaden: Cloud- und Virtualisierungssicherheit 2025</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Demand for junior developers softens as AI takes over]]></title>
<description><![CDATA[Growing use of AI coding assistants and low-code development tools appears to be driving down demand for junior developers as many companies look to cut workforce expenses.



Outlooks for software developer jobs are mixed, with the US Bureau of Labor Statistics projecting 15% growth between 2024...]]></description>
<link>https://tsecurity.de/de/3001509/it-security-nachrichten/demand-for-junior-developers-softens-as-ai-takes-over/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3001509/it-security-nachrichten/demand-for-junior-developers-softens-as-ai-takes-over/</guid>
<pubDate>Wed, 24 Sep 2025 11:49:56 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Growing use of AI coding assistants and low-code development tools appears to be driving down demand for junior developers as many companies look to <a href="https://www.cio.com/article/4000546/company-boards-push-ceos-to-replace-it-workers-with-ai.html?utm=hybrid_search">cut workforce expenses</a>.</p>



<p>Outlooks for software developer jobs are mixed, with the <a href="https://www.bls.gov/ooh/Computer-and-Information-Technology/Software-developers.htm" rel="nofollow">US Bureau of Labor Statistics projecting</a> 15% growth between 2024 and 2034. But many IT experts see a softening job market for developers, particularly junior coders, with hiring freezes and layoffs on the horizon as organizations replace them with AI coding assistants.</p>



<p><a href="https://www.cio.com/article/4047844/ai-is-taking-over-junior-positions-in-it.html?utm=hybrid_search">Recent statistics</a> support this view. The unemployment rate for recent US graduates in computer engineering stands at 7.5%, with computer science grads sitting at 6.1%, and information systems and management at 5.6%, <a href="https://www.newyorkfed.org/research/college-labor-market#--:explore:outcomes-by-major" rel="nofollow">according to projections</a> from the US Federal Reserve Bank of New York.</p>



<p>Those percentages are higher than the overall US unemployment rate of 4.3% and significantly elevated compared to recent grads in nursing (1.4%), elementary education (1.8%), civil engineering (1%), and even art history (3%).</p>



<p>At the same time, a recent <a href="https://www.resume.org/6-in-10-companies-plan-to-lay-off-employees-in-2026-amid-economic-uncertainty/" rel="nofollow">Resume.org survey</a> of 1,000 US business leaders found that six in 10 companies are likely to lay off employees in 2026, with four in 10 planning to replace workers with AI by then. With <a href="https://www.cio.com/article/3509174/ai-coding-assistants-wave-goodbye-to-junior-developers.html?utm=hybrid_search">AI coding assistants</a> already <a href="https://github.blog/news-insights/research/survey-ai-wave-grows/" rel="nofollow">near universally used</a>, programmer jobs may be among the first on the chopping block.</p>



<p><a href="https://www.linkedin.com/in/agrawalchirag/" rel="nofollow">Chirag Agrawal</a>, a senior software engineer, sees junior developer roles disappearing as companies try to do more with less.</p>



<p>“Four years ago, I was that junior developer writing boilerplate CRUD code, proud of every clean PR I merged,” he says. “Today? I watch new grads struggle to land their first job, not because they’re unskilled, but because companies ask, ‘Why hire a junior for $90K when GitHub Copilot <a href="https://www.cloudeagle.ai/blogs/github-copilot-pricing-guide#:~:text=GitHub%20Copilot%20starts%20at%20%2410%2Fmonth%20for%20individuals%20and,real-time%20AI%20coding%20help%20directly%20in%20supported%20IDEs." rel="nofollow">costs $10</a>?’”</p>



<p>Still, Agrawal sees a future role for developers who can work with AI. The best software engineers won’t be the fastest coders, but instead, they will be those who know when to distrust AI, he says.</p>



<p>“At my company, my role has shifted from just coding to validating AI output, checking for edge cases, security risks, and logic gaps that AI can’t catch,” he says. “I’m not trying to out-code AI. I’m making myself essential by leading it with judgment.”</p>



<h2 class="wp-block-heading">Cuts vs. productivity</h2>



<p>There seem to be mixed responses to AI coding assistants, with some companies pushing for more productivity and others cutting jobs, adds <a href="https://www.linkedin.com/in/zeeljadia/" rel="nofollow">Zeel Jadia</a>, CEO and CTO at AI-based restaurant answering service ReachifyAI.</p>



<p>“Business priorities shift with economic conditions, and right now the baseline team is smaller, powered by AI-assisted developers,” he says. “Not every company is leaning in this direction, but private equity–backed groups and fast-moving incubators are already pushing the trend. Once the competitive advantage becomes too big to ignore, larger organizations will fall in line.”</p>



<p>Jadia predicts that hiring freezes for new developers will become common. Still, he sees a future role for developers who oversee AI-written code.</p>



<p>“Picture a future where AI handles the bulk of software development,” he says. “Fewer people will choose coding as a career, and those who do will command premium pay, more like lawyers today.”</p>



<p>This oversight will be necessary because AI still has problems with coordinating issues across multiple services, fixing security bugs, or resolving database lock scenarios, Jadia says.</p>



<p>“It becomes clear that you still need sharp engineers to step in and protect the house,” he adds. “At the end of the day, AI still depends on strong frameworks, high-quality documentation, and fundamental innovation to underlying technologies that AI cannot comprehend without the right technical mind guiding it.”</p>



<h2 class="wp-block-heading">Senior devs needed</h2>



<p>Other experts agree that roles for senior developers will continue to exist in the AI future. Junior developer jobs may be hard to come by, but coding jobs won’t go away, says Rachit Gupta, head of AI at AI-focused orchestration vendor Tredence.</p>



<p>“In the near term, it’s true that many of the tasks junior developers used to do like fixing bugs, writing test scripts, and cranking out boilerplate code, are now the kinds of things AI tools handle well,” he says. “That’s part of why new grads are having a harder time landing that first role.”</p>



<p>Gupta sees the developer role changing significantly in coming years.</p>



<p>“Instead of spending all day writing code from scratch, developers are increasingly guiding AI, stitching together outputs into larger systems, and focusing on higher-value problem-solving,” he says. “For juniors, that means the first rung on the ladder looks different; they are learning how to ask the right questions of AI, double-check its work, and put it into context.”</p>



<p>Senior developers will remain critical employees, he adds. “AI doesn’t make the tough calls on architecture, compliance, or security,” he says. “It can’t fully understand a company’s business logic or the ethical implications of a system. That oversight and judgment still rest with experienced engineers.”</p>



<p><a href="https://www.linkedin.com/in/raymond-kok-8022578/" rel="nofollow">Raymond Kok</a>, CEO of low-code development platform Mendix, agrees, saying the senior developer role will change from writing code to ensuring that agents and other AI tools work together.</p>



<p>“If you think about agentic application development, people will move away from being coders to being what I call composers,” he says. “It’s about composing agents, and it’s about building workflows and hierarchies of agents, as opposed to really being focused on low-level compute instructions that you typically work on when you do programming.”</p>



<h2 class="wp-block-heading">Replacing coders with technology</h2>



<p>Still, Kok sees traditional coding dying, as AI, low-code tools, and visual programming languages reinvent the developer role. It’s past time for software development to move away from command-line coding to these graphical and AI-based methods, he says.</p>



<p>“Software engineering never made kind of the mainstream leap into model-based development, but it’s going to happen shortly,” Kok adds. “Most of the <a href="https://en.wikipedia.org/wiki/Integrated_development_environment" rel="nofollow">agentic IDEs</a> that you see out there use visual abstractions, model-based abstractions, to build these chains of agents and to build out the agentic application experience that people want.”</p>



<p>IT leaders should prepare for this major change by redefining their software development lifecycles and embracing new tools, Kok advises. IT leaders also need to ensure that their employees are trained in these emerging coding techniques, he adds.</p>



<p>The way to define how a programmer is doing a good job will also change, he says.</p>



<p>“What will change is the definition of work,” Kok adds. “What people are going to be measured on going forward is, ‘How do you use properly this combination of generative AI and model-based software engineering and then implementing the right <a href="https://www.geeksforgeeks.org/software-engineering/non-functional-requirements-in-software-engineering/" rel="nofollow">NFRs [non-functional requirements]</a> into the application landscape that you want to go build?’”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Breaking the scale barrier: Lessons from global growth playbooks]]></title>
<description><![CDATA[When scale becomes the wall



Not long ago, I was in a boardroom when a CIO leaned across the table and asked me a deceptively simple question: “We’ve proven this works in one market. Why does scaling it to five markets feel like rebuilding the whole thing from scratch?”



That question has ech...]]></description>
<link>https://tsecurity.de/de/2997717/it-security-nachrichten/breaking-the-scale-barrier-lessons-from-global-growth-playbooks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2997717/it-security-nachrichten/breaking-the-scale-barrier-lessons-from-global-growth-playbooks/</guid>
<pubDate>Mon, 22 Sep 2025 15:04:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">When scale becomes the wall</h2>



<p>Not long ago, I was in a boardroom when a CIO leaned across the table and asked me a deceptively simple question: “We’ve proven this works in one market. Why does scaling it to five markets feel like rebuilding the whole thing from scratch?”</p>



<p>That question has echoed in my career ever since. I’ve heard it from enterprise executives in New York, from startup founders in Bangalore and from ecosystem builders in São Paulo. The problem is rarely the idea itself. It’s the ecosystem that determines whether innovation can scale without collapsing under its own weight.</p>



<p>Over time, I’ve come to realize the lesson is the same at both the startup and enterprise level: scalability isn’t just about technology. It’s about clouds, code and capital working together in harmony. CIOs who act as ecosystem architects, not just system owners, unlock growth that others struggle to replicate.</p>



<h2 class="wp-block-heading">Treat clouds like water, not a warehouse</h2>



<p>When I first led cloud migrations, I made the mistake many do: We treated the cloud as a shinier data center. Costs ballooned, agility stalled and developers still had to ask permission just to experiment.</p>



<p>The shift came when we started treating cloud like water, a utility. Always available, always measurable, always flowing to where it’s needed. That mindset changed everything. Suddenly, the conversation wasn’t about capacity, it was about speed, portability and cost per unit of value.</p>



<p>This is the same principle that enabled India’s startups to scale fintech apps to a billion people. They didn’t build everything themselves. They leaned on <a href="https://www.indiastack.org/" target="_blank" rel="nofollow">India Stack</a>, a set of digital identity, payments and document services available as APIs to anyone. Cloud became the rails, not the roadblock.</p>



<p>For CIOs, the lesson is clear: abstract the basics. Build internal digital rails identity, payments, notifications and logging that every team can plug into. The faster you turn those into utilities, the faster your enterprise scales like a startup.</p>



<h2 class="wp-block-heading">Write the rules once, share them everywhere</h2>



<p>I used to believe technology dictated scale. But the more ecosystems I studied, the clearer it became that the rules matter just as much as rails.</p>



<p>Take Brazil’s financial sector. Fintech didn’t explode there because banks suddenly became generous partners. It happened because regulators forced everyone into a shared framework called <a href="https://www.bcb.gov.br/en/financialstability/open_finance" target="_blank" rel="nofollow">Open Finance</a>. APIs were mandated, and once the rules were clear, startups sprinted.</p>



<p>Inside enterprises, I often see the opposite, where every team negotiates compliance separately, re-litigating the same security policies and slowing innovation to a crawl. The fix is simple but powerful: codify compliance once, then expose it as reusable services.</p>



<p>Think of it as compliance as code. Privacy rules, data residency requirements and logging standards are baked into APIs and SDKs that every team consumes automatically. That way, innovation compounds instead of stalling.</p>



<p>Great policy isn’t a brake pedal. <em>It’s a platform.</em></p>



<h2 class="wp-block-heading">Only scale what pays</h2>



<p>I’ve seen AI pilots win standing ovations in executive reviews only to die quietly six months later. The issue wasn’t the technology. It was the economics.</p>



<p>The best ecosystems don’t fall for hype. They scale only what pays.</p>



<ul class="wp-block-list">
<li><strong>AI</strong>, where cost per inference lines up with either revenue lift or risk reduction.</li>



<li><strong>Blockchain</strong>, where reconciliation costs justify distributed ledgers.</li>



<li><strong>IoT</strong> and <strong>edge</strong>, where latency and visibility directly change business outcomes.</li>
</ul>



<p>I’ve learned to be ruthless: pilot quickly, measure hard and kill what doesn’t earn its keep. In one enterprise program I led, we cut half the pilots in 60 days, but the ones that remained scaled profitably across multiple business lines.</p>



<p>The secret isn’t to chase every shiny technology. It’s to scale only the ones that have clear unit economics.</p>



<h2 class="wp-block-heading">Borrow shamelessly from global playbooks</h2>



<p>Each region of the world has developed its own scaling DNA. CIOs don’t need to reinvent the wheel; we just need to borrow wisely.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Country/Region</strong></td><td><strong>Approach</strong></td><td><strong>Enterprise Lesson</strong></td></tr><tr><td>United States</td><td>Market-driven speed and deep university ties.</td><td>Shorten kill cycles; tie pilots to metrics, not emotions.</td></tr><tr><td>India</td><td>Public digital rails like Aadhaar and UPI.</td><td>Package your own rails for teams to build on.</td></tr><tr><td>Europe</td><td>Compliance-first trust through GDPR and the <a href="https://artificialintelligenceact.eu/" target="_blank" rel="nofollow">AI Act</a>.</td><td>Make governance a feature, not a hurdle.</td></tr><tr><td>Africa</td><td>Mobile-first resilience. Products like M-Pesa proved you can scale even in infrastructure-poor environments.</td><td>Design for edge cases; resilience follows.</td></tr><tr><td>Southeast Asia</td><td>Government-orchestrated super apps. Grab and Gojek bundle entire customer journeys.</td><td>Bundle adjacent services to drive stickiness.</td></tr><tr><td>Brazil</td><td>Hybrid resilience in messy environments.</td><td>Plan for regulatory whiplash with adaptable APIs and modular architectures.</td></tr></tbody></table> </div></figure>



<p>Every one of these regions is solving at ecosystem scale the same challenges CIOs face inside the enterprise.</p>



<h2 class="wp-block-heading">Run the 90-day experiment</h2>



<p>I believe in starting small but deliberately. Here’s the framework I’ve used to shift enterprises from firefighting projects to building ecosystems:</p>



<ul class="wp-block-list">
<li><strong>Appoint an ecosystem PM.</strong> One accountable leader for digital rails and partner enablement.</li>



<li><strong>Expose a rails catalog.</strong> Package identity, payments, notifications, logging as APIs, documented like products.</li>



<li><strong>Launch two AI pilots.</strong> Pick use cases with measurable economics and enforce stop/go gates.</li>



<li><strong>Instrument cost and compliance.</strong> Dashboards that show unit economics and risk in real time.</li>



<li><strong>Open a sandbox.</strong> Synthetic data and mock APIs so partners and product teams can integrate quickly and safely.</li>
</ul>



<p>In 90 days, the cultural shift becomes tangible. Teams stop asking “Can we?” and start asking “How fast?”</p>



<h2 class="wp-block-heading">Don’t forget the people</h2>



<p>Even the best rails and rules fail without the right talent to use them. Ecosystems scale because people do.</p>



<p>That means CIOs need to think about talent as part of the architecture. Distributed teams. Startup visas. Upskilling programs. Diversity as a driver of creativity.</p>



<p>In my own experience, distributed teams allowed us to scale expertise across geographies without waiting for relocation approvals. Tools like Slack, GitHub and remote compliance platforms made it seamless. And when we diversified teams, performance improved not by accident but because different perspectives solved problems faster.</p>



<p>This isn’t just my observation. Research from <a href="https://www.mckinsey.com/capabilities/people-and-organizational-performance/our-insights/diversity-wins-how-inclusion-matters" target="_blank" rel="nofollow">McKinsey</a> found that companies with diverse leadership teams were significantly more likely to outperform on profitability. Ecosystems thrive on variety and so do enterprises.</p>



<h2 class="wp-block-heading">The leadership pivot</h2>



<p>Here’s the hard truth I’ve learned: CIOs who act as system owners will always be chasing. CIOs who embrace the role of ecosystem architects — balancing clouds, code, capital and people — will set the pace.</p>



<p>That CIO who asked me why scaling felt like rebuilding from scratch? They didn’t need bigger systems. They needed an ecosystem. Once they built it, scaling stopped being a wall and became their competitive edge.</p>



<p>And that’s the shift I believe every CIO must make from project leader to ecosystem builder. Because in today’s world, ecosystems scale innovation. Nothing else does.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><strong><br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[tvOS 26 Brings Custom Aerial Screen Saver Controls to Apple TV]]></title>
<description><![CDATA[Apple rolled out tvOS 26 earlier this week, and one of the most practical additions is greater control over Aerial screen savers on Apple TV 4K. For years, these high-definition visuals have been a defining part of the experience, but users had little say over which ones appeared. That changes wi...]]></description>
<link>https://tsecurity.de/de/2997660/ios-mac-os/tvos-26-brings-custom-aerial-screen-saver-controls-to-apple-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2997660/ios-mac-os/tvos-26-brings-custom-aerial-screen-saver-controls-to-apple-tv/</guid>
<pubDate>Mon, 22 Sep 2025 14:38:20 +0200</pubDate>
<content:encoded><![CDATA[Apple rolled out tvOS 26 earlier this week, and one of the most practical additions is greater control over Aerial screen savers on Apple TV 4K. For years, these high-definition visuals have been a defining part of the experience, but users had little say over which ones appeared. That changes with the new update.



Choose Your Own Aerials







In tvOS 26, you can now enable or disable individual Aerial screen savers. The option appears in Settings under the Screen Saver menu, where a new "Choose Aerials" section lists four categories: Cityscape, Earth, Landscape, and Underwater.



Instead of removing entire collections, you can now fine-tune the lineup and exclude only the visuals you dislike. This creates a curated "playlist" of screen savers that better reflects your preferences. Some users may prefer rotating landscapes, while others may want to avoid certain underwater shots. The feature gives you that level of control for the first time.



Expanding the Library



Apple is also adding new footage captured across India, including scenes from Goa and Kerala. These additions broaden the visual range and keep the Aerial feature fresh for long-time Apple TV owners.



The Aerials have long been more than filler content. They showcase the device’s display capabilities, highlight global locations, and add a sense of personality to what is otherwise a streaming box. With tvOS 26, that feature feels less like a static backdrop and more like something you can personalize.



More Than Just Screen Savers



The update also introduces other changes, including a redesigned TV app, a new profile selector when waking the device, and Apple’s Liquid Glass design refresh. Yet, the ability to handpick Aerial screen savers stands out because it gives users control over one of the Apple TV’s most recognizable features.



tvOS 26 doesn’t reinvent Apple TV, but it makes it more personal. And for many users, that matters just as much as the bigger headline updates.]]></content:encoded>
</item>
<item>
<title><![CDATA[Supporting Rowhammer research to protect the DRAM ecosystem]]></title>
<description><![CDATA[Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized ...]]></description>
<link>https://tsecurity.de/de/2985556/it-security-nachrichten/supporting-rowhammer-research-to-protect-the-dram-ecosystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2985556/it-security-nachrichten/supporting-rowhammer-research-to-protect-the-dram-ecosystem/</guid>
<pubDate>Mon, 15 Sep 2025 21:18:39 +0200</pubDate>
<content:encoded><![CDATA[<span class="byline-author">Posted by Daniel Moghimi</span><div><span face="Arial, sans-serif"><br></span></div><div><span face="Arial, sans-serif">Rowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized access to data, escalate privileges, or cause denial of service. Hardware vendors have deployed various mitigations, such as </span><a href="https://www.jedec.org/category/keywords/ecc"><span face="Arial, sans-serif">ECC</span></a><span face="Arial, sans-serif"> and Target Row Refresh (TRR) for DDR5 memory, to mitigate Rowhammer and enhance DRAM reliability. However, the resilience of those mitigations against sophisticated attackers remains an open question.</span></div><div><span><p dir="ltr"><span face="Arial, sans-serif">To address this gap and help the ecosystem with deploying robust defenses, Google has supported academic research and developed test platforms to analyze DDR5 memory. Our effort has led to the discovery of new attacks and a deeper understanding of Rowhammer on the current DRAM modules, helping to forge the way for further, stronger mitigations.</span></p><h2 dir="ltr"><span face="Arial, sans-serif">What is Rowhammer? </span></h2><p dir="ltr"><a href="https://dl.acm.org/doi/abs/10.1145/2678373.2665726"><span face="Arial, sans-serif">Rowhammer</span></a><span face="Arial, sans-serif"> exploits a vulnerability in DRAM. DRAM cells store data as electrical charges, but these electric charges leak over time, causing data corruption. To prevent data loss, the memory controller periodically refreshes the cells. However, if a cell discharges before the refresh cycle, its stored bit may corrupt. Initially considered a reliability issue, it has been leveraged by security researchers to demonstrate privilege escalation attacks. By repeatedly accessing a memory row, an attacker can cause bit flips in neighboring rows. An adversary can exploit Rowhammer via:</span></p><ol><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Reliably cause bit flips</span><span> by repeatedly accessing adjacent DRAM rows.</span></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Coerce other applications</span><span> or the OS into using these vulnerable memory pages.</span></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Target security-sensitive code or data</span><span> to achieve privilege escalation.</span></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Or simply corrupt system’s memory to </span><span>cause denial of service</span><span>. </span></p></li></ol><p dir="ltr"><span face="Arial, sans-serif">Previous work has repeatedly demonstrated the possibility of such attacks from software [</span><a href="https://ieeexplore.ieee.org/abstract/document/9138944/"><span face="Arial, sans-serif">Revisiting rowhammer</span></a><span face="Arial, sans-serif">, </span><a href="https://ieeexplore.ieee.org/abstract/document/9152654/"><span face="Arial, sans-serif">Are we susceptible to rowhammer?</span></a><span face="Arial, sans-serif">, </span><a href="https://dl.acm.org/doi/abs/10.1145/2976749.2978406"><span face="Arial, sans-serif">Drammer</span></a><span face="Arial, sans-serif">,  </span><a href="https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/razavi"><span face="Arial, sans-serif">Flip feng shui</span></a><span face="Arial, sans-serif">, </span><a href="https://eprint.iacr.org/2022/1669"><span face="Arial, sans-serif">Jolt</span></a><span face="Arial, sans-serif">]. As a result, defending against Rowhammer is required for secure isolation in multi-tenant environments like the cloud. </span></p><h2 dir="ltr"><span face="Arial, sans-serif">Rowhammer Mitigations </span></h2><p dir="ltr"><span face="Arial, sans-serif">The primary approach to mitigate Rowhammer is to detect which memory rows are being aggressively accessed and refreshing nearby rows before a bit flip occurs. TRR is a common example, which uses a number of counters to track accesses to a small number of rows adjacent to a potential victim row. If the access count for these aggressor rows reaches a certain threshold, the system issues a refresh to the victim row. TRR can be incorporated within the DRAM or in the host CPU.</span></p><p dir="ltr"><span face="Arial, sans-serif">However, this mitigation is not foolproof. For example, the </span><a href="https://ieeexplore.ieee.org/abstract/document/9152631"><span face="Arial, sans-serif">TRRespass</span></a><span face="Arial, sans-serif"> attack showed that by simultaneously hammering multiple, non-adjacent rows, TRR can be bypassed. Over the past couple of years, more sophisticated attacks [</span><a href="https://www.usenix.org/conference/usenixsecurity22/presentation/kogler-half-double"><span face="Arial, sans-serif">Half-Double</span></a><span face="Arial, sans-serif">, </span><a href="https://www.research-collection.ethz.ch/bitstream/handle/20.500.11850/525008/4/2021275594.pdf"><span face="Arial, sans-serif">Blacksmith</span></a><span face="Arial, sans-serif">] have emerged, introducing more efficient attack patterns. </span></p><p dir="ltr"><span face="Arial, sans-serif">In response, one of our efforts was to collaborate with </span><a href="https://www.jedec.org/"><span face="Arial, sans-serif">JEDEC</span></a><span face="Arial, sans-serif">, external researchers, and experts to define the</span><span face="Arial, sans-serif"> </span><a href="https://www.jedec.org/news/pressreleases/jedec-updates-jesd79-5c-ddr5-sdram-standard-elevating-performance-and-security"><span face="Arial, sans-serif">PRAC</span></a><span face="Arial, sans-serif"> as a new mitigation that deterministically detects Rowhammer by tracking all memory rows. </span></p><p dir="ltr"><span face="Arial, sans-serif">However, current systems equipped with DDR5 lack support for PRAC or other robust mitigations. As a result, they rely on probabilistic approaches such as ECC and enhanced TRR</span><span face="Arial, sans-serif"> </span><span face="Arial, sans-serif">to reduce the risk. While these measures have mitigated older attacks, their overall effectiveness against new techniques was not fully understood until our recent </span><a href="https://comsec.ethz.ch/phoenix"><span face="Arial, sans-serif">findings</span></a><span face="Arial, sans-serif">.</span></p><h2 dir="ltr"><span face="Arial, sans-serif">Challenges with Rowhammer Assessment </span></h2><p dir="ltr"><span face="Arial, sans-serif">Mitigating Rowhammer attacks involves making it difficult for an attacker to reliably cause bit flips from software. Therefore, for an effective mitigation, we have to understand how a determined adversary introduces memory accesses that bypass existing mitigations. Three key information components can help with such an analysis:</span></p><ol><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>How the improved TRR and in-DRAM ECC work.</span></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>How memory access patterns from software translate into low-level DDR commands.</span></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>(Optionally) How any mitigations (e.g., ECC or TRR) in the host processor work.</span></p></li></ol><p dir="ltr"><span face="Arial, sans-serif">The first step is particularly challenging and involves reverse-engineering the proprietary in-DRAM TRR mechanism, which varies significantly between different manufacturers and device models. This process requires the ability to issue precise DDR commands to DRAM and analyze its responses, which is difficult on an off-the-shelf system. Therefore, specialized test platforms are essential.</span></p><p dir="ltr"><span face="Arial, sans-serif">The second and third steps involve analyzing the DDR traffic between the host processor and the DRAM. This can be done using an off-the-shelf interposer, a tool that sits between the processor and DRAM. A crucial part of this analysis is understanding how a live system translates software-level memory accesses into the DDR protocol.</span></p><p dir="ltr"><span face="Arial, sans-serif">The third step, which involves analyzing host-side mitigations, is sometimes optional. For example, host-side ECC (Error Correcting Code) is enabled by default on servers, while host-side TRR has only been implemented in some CPUs. </span></p><h2 dir="ltr"><span face="Arial, sans-serif">Rowhammer testing platforms</span></h2><p dir="ltr"><span face="Arial, sans-serif">For the first challenge, we partnered with Antmicro to develop two specialized, open-source FPGA-based Rowhammer test platforms. These platforms allow us to conduct in-depth testing on different types of DDR5 modules.</span></p><ul><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><a href="https://antmicro.com/blog/2022/08/extending-the-open-source-rowhammer-testing-framework-to-ddr5/"><span>DDR5 RDIMM Platform:</span></a><span> A new DDR5 Tester board to meet the hardware requirements of Registered DIMM (RDIMM) memory, common in server computers.</span></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><a href="https://antmicro.com/blog/2024/02/versatile-so-dimm-lpddr5-rowhammer-testing-platform/"><span>SO-DIMM Platform:</span></a><span> A version that supports the standard SO-DIMM pinout compatible with off-the-shelf DDR5 SO-DIMM memory sticks, common in workstations and end-user devices.</span></p></li></ul><p dir="ltr"><span face="Arial, sans-serif">Antmicro designed and manufactured these </span><a href="https://github.com/antmicro/rowhammer-tester"><span face="Arial, sans-serif">open-source platforms</span></a><span face="Arial, sans-serif"> and we worked closely with them, and researchers from ETH Zurich, to test the applicability of these platforms for analyzing off-the-shelf memory modules in RDIMM and SO-DIMM forms.</span></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_gVyZNNM5VDayDqZdu0oTgJlszT_po_A7Fku8jToBlYJsNyu3KxoX6KopaNiwm2VjxhlxoXGYVbVEbX_9fkVUh54zV5tfVn2ZrMi2bUZ8zveOYAbzVgfAg1KliqaNgdkp9-iYwAvoaHPqv2x1UallmAEC_D71V9B-pSdJn3yhxRo5HT24qBpftZJC2NIi/s990/Screenshot%202025-09-12%20at%204.47.13%E2%80%AFPM.png" imageanchor="1"><img border="0" data-original-height="652" data-original-width="990" height="294" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_gVyZNNM5VDayDqZdu0oTgJlszT_po_A7Fku8jToBlYJsNyu3KxoX6KopaNiwm2VjxhlxoXGYVbVEbX_9fkVUh54zV5tfVn2ZrMi2bUZ8zveOYAbzVgfAg1KliqaNgdkp9-iYwAvoaHPqv2x1UallmAEC_D71V9B-pSdJn3yhxRo5HT24qBpftZJC2NIi/w446-h294/Screenshot%202025-09-12%20at%204.47.13%E2%80%AFPM.png" width="446"></a></div><p dir="ltr"><br></p><p dir="ltr"><span face="Arial, sans-serif">Antmicro DDR5 RDIMM FPGA test platform in action.</span></p><h2 dir="ltr"><span face="Arial, sans-serif">Phoenix Attacks on DDR5</span></h2><p dir="ltr"><span face="Arial, sans-serif">In collaboration with researchers from ETH, we applied the new Rowhammer test platforms to evaluate the effectiveness of current in-DRAM DDR5 mitigations. Our findings, detailed in the recently co-authored "</span><a href="https://comsec.ethz.ch/phoenix"><span face="Arial, sans-serif">Phoenix</span></a><span face="Arial, sans-serif">” research paper, reveal that we successfully developed custom attack patterns capable of bypassing enhanced TRR (Target Row Refresh) defense on DDR5 memory. We were able to create a novel self-correcting refresh synchronization attack technique, which allowed us to perform the first-ever Rowhammer privilege escalation exploit on a standard, production-grade desktop system equipped with DDR5 memory. While this experiment was conducted on an off-the-shelf workstation equipped with recent AMD Zen processors and SK Hynix DDR5 memory, we continue to investigate the applicability of our findings to other hardware configurations.</span></p><h2 dir="ltr"><span face="Arial, sans-serif">Lessons learned </span></h2><p dir="ltr"><span face="Arial, sans-serif">We showed that current mitigations for Rowhammer attacks are not sufficient, and the issue remains a widespread problem across the industry. They do make it more difficult “but not impossible” to carry out attacks, since an attacker needs an in-depth understanding of the specific memory subsystem architecture they wish to target.</span></p><br><p dir="ltr"><span face="Arial, sans-serif">Current mitigations based on TRR and ECC rely on probabilistic countermeasures that have insufficient entropy. Once an analyst understands how TRR operates, they can craft specific memory access patterns to bypass it. Furthermore, current ECC schemes were not designed as a security measure and are therefore incapable of reliably detecting errors.</span></p><br><p dir="ltr"><span face="Arial, sans-serif">Memory encryption is an alternative countermeasure for Rowhammer. However, our current assessment is that without cryptographic integrity, it offers no valuable defense against Rowhammer. More research is needed to develop viable, practical encryption and integrity solutions.</span></p><h2 dir="ltr"><span face="Arial, sans-serif">Path forward</span></h2><p dir="ltr"><span face="Arial, sans-serif">Google has been a leader in JEDEC standardization efforts, for instance with </span><a href="http://google.com/url?q=https://www.jedec.org/news/pressreleases/jedec-updates-jesd79-5c-ddr5-sdram-standard-elevating-performance-and-security&amp;sa=D&amp;source=docs&amp;ust=1757029496975020&amp;usg=AOvVaw1AVBpnQbJ_M_QYxPq8bfE3"><span face="Arial, sans-serif">PRAC</span></a><span face="Arial, sans-serif">, a fully approved standard to be supported in upcoming versions of </span><a href="https://www.jedec.org/news/pressreleases/jedec-updates-jesd79-5c-ddr5-sdram-standard-elevating-performance-and-security"><span face="Arial, sans-serif">DDR5</span></a><span face="Arial, sans-serif">/</span><a href="https://www.jedec.org/news/pressreleases/jedec%C2%AE-releases-new-lpddr6-standard-enhance-mobile-and-ai-memory-performance"><span face="Arial, sans-serif">LPDDR6</span></a><span face="Arial, sans-serif">. It works by accurately counting the number of times a DRAM wordline is activated and alerts the system if an excessive number of activations is detected. This close coordination between the DRAM and the system gives PRAC a reliable way to address Rowhammer. </span></p><br><p dir="ltr"><span face="Arial, sans-serif">In the meantime, we continue to evaluate and improve other countermeasures to ensure our workloads are resilient against Rowhammer. We collaborate with our academic and industry partners to improve analysis techniques and test platforms, and to share our findings with the broader ecosystem.</span></p><h2 dir="ltr"><span face="Arial, sans-serif">Want to learn more?</span></h2><p dir="ltr"><span face="Arial, sans-serif">“Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization” will be presented at </span><a href="https://www.ieee-security.org/TC/SP2026/"><span face="Arial, sans-serif">IEEE Security &amp; Privacy 2026</span></a><span face="Arial, sans-serif"> in San Francisco, CA (MAY 18-21, 2026).</span></p></span></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From pilot to profitability: How to approach enterprise AI adoption]]></title>
<description><![CDATA[Many of the leaders I talk to are struggling to move past the pilot stage of AI. They are in pilot purgatory. It’s not a lack of ambition that holds them back — it’s a lack of clarity. Questions about where to build, where to buy and how to structure teams for scale create a kind of organizationa...]]></description>
<link>https://tsecurity.de/de/2980577/it-security-nachrichten/from-pilot-to-profitability-how-to-approach-enterprise-ai-adoption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2980577/it-security-nachrichten/from-pilot-to-profitability-how-to-approach-enterprise-ai-adoption/</guid>
<pubDate>Fri, 12 Sep 2025 14:19:38 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Many of the leaders I talk to are struggling to move past the pilot stage of AI. They are in pilot purgatory. It’s not a lack of ambition that holds them back — it’s a lack of clarity. Questions about where to build, where to buy and how to structure teams for scale create a kind of organizational gridlock. I’ve faced the same challenges in my own experience leading digital transformation efforts, and I’ve found that what breaks the cycle is not hype or vision, but a practical, focused approach.</p>



<p>AI doesn’t need to be complicated to be effective. But it does require structure, prioritization and a willingness to rethink how work gets done.</p>



<p>Here’s how I think about it.</p>



<h2 class="wp-block-heading">Buying versus building: Start with a philosophy, not a spreadsheet</h2>



<p>Buying versus building: Start with a philosophy, not a spreadsheet</p>



<p>Early on, I heard IT leaders in my network trying to justify AI investments by comparing cost and performance between vendor platforms and in-house models. But I quickly realized that no spreadsheet could capture the broader trade-offs at play. Speed matters. So does the ability to scale, maintain and continuously improve what you build.</p>



<p>Over time, I settled on a general rule of thumb: aim to buy about 80% of the capabilities you need and build the remaining 20%. Some organizations may shift closer to 70/30, but the underlying idea holds: don’t reinvent what’s already working elsewhere.</p>



<p>Evidence backs this up. In a<a href="https://www.sahmcapital.com/news/content/is-massive-investment-in-ai-really-paying-off-morgan-stanley-tangible-returns-already-seen-in-three-major-sectors-2025-07-25" target="_blank" rel="nofollow"> July 2025 Morgan Stanley AI Adopter Survey</a>, analysts reported that AI is already delivering tangible returns across industries such as financial services, consumer goods and real estate — many of which are benefiting from off-the-shelf tools with embedded intelligence. That market reality is mirrored in the vendor landscape: enterprise software platforms are evolving at a remarkable pace. Vendors are embedding significant AI capabilities directly into their products. Gartner predicts that by 2026,<a href="https://telecomreseller.com/2023/10/14/generative-ai-apis/#:~:text=GenAI-Enabled%20Applications,%20Generative%20AI,limit%20widespread%20impact%20and%20adoption.%E2%80%9D" target="_blank" rel="nofollow"> more than 80% of software vendors will have embedded generative AI into enterprise applications</a>, up from just 1% in February 2024.</p>



<p>That’s why I’ve found it far more effective to treat enterprise software platforms as the foundation and then identify where custom development is truly needed. This frees up internal teams to focus on high-value use cases rather than duplicating what’s already available.</p>



<p>Of course, out-of-the-box solutions don’t cover every scenario. In some cases — like stitching together data and workflows across platforms — agentic AI or internal development has been essential to close integration gaps. It’s not about choosing one approach over the other; it’s about knowing when each one makes sense.</p>



<h2 class="wp-block-heading">Prioritizing problems, not projects</h2>



<p>AI is not the strategy. The business is the strategy. That’s a lesson I learned after watching too many proofs of concept fail to scale because they didn’t tie directly to outcomes that mattered.</p>



<p>To make progress, it’s best to shift the conversation away from AI as a technology and toward AI as a tool for solving real business problems. That starts with listening — really listening — to what customers, frontline employees and partners are experiencing.</p>



<p>I attended the CIO 100 event in August, where<a href="https://www.cio.com/article/3998156/avery-dennison-takes-culture-first-approach-to-ai-transformation.html" target="_blank"> Avery Dennison received an award</a> for<a href="https://www.cio.com/article/3998156/avery-dennison-takes-culture-first-approach-to-ai-transformation.html"> Program Loop</a>, our AI program. While there, I had the chance to compare notes with other IT leaders about how they were approaching AI opportunity selection. One common theme was the use of workshops with functional leaders to surface pain points from the customer’s perspective. From there, several leaders described bringing cross-functional teams together to weigh potential solutions.</p>



<p>What struck me most was the simplicity of the prioritization methods. One approach rated opportunities across three dimensions: business impact, level of effort and urgency — each on a simple high, medium or low scale. When you map those ratings, the opportunities that score high in impact and urgency but low in effort naturally rise to the top. Those become the logical first focus areas, and the clarity it provides helps build early momentum.</p>



<p>What made this approach effective was how it aligned teams around what truly mattered. Several leaders described reframing challenges as “How might we…” questions, which naturally broadened the discussion and sparked more creative solutions. AI was then introduced not as the starting point, but as one of many possible enablers.</p>



<p>From my perspective, this mindset shift changes the tone of the entire conversation. It’s no longer a debate about whether to adopt AI — it becomes a dialogue about driving business value. That’s where real momentum begins to build.</p>



<h2 class="wp-block-heading">From central authority to shared ownership</h2>



<p>In conversations with other IT leaders, I’ve noticed a common pattern in how AI programs evolve. Most began with a centralized team — a logical first step to establish standards, consistency and a safe space for early experiments. But over time, it became clear that no central group could keep pace with every business request or understand each domain deeply enough to deliver the best solutions.</p>



<p>Many organizations have since shifted toward a hub-and-spoke model. The hub — often an AI center of excellence — takes responsibility for governance, education, best practices and the technically complex use cases. The spokes, led by product or functional teams, experiment with AI features embedded in the tools they use every day. Because they’re closer to the business, these teams can test, iterate and deliver solutions at speed.</p>



<p>When I look across industries, the majority of AI innovation is now happening at the edge, not the center. That’s largely because so much intelligence is already embedded into enterprise software. A CRM platform, for instance, might now offer AI-based lead scoring or predictive churn models — capabilities a team can enable and deploy with little to no involvement from the center of excellence.</p>



<p>According to McKinsey, “<a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/superagency-in-the-workplace-empowering-people-to-unlock-ais-full-potential-at-work" target="_blank" rel="nofollow">Over the next three years, 92 percent of companies plan to increase their AI investments</a>. But while nearly all companies are investing in AI, only 1 percent of leaders call their companies ‘mature’ on the deployment spectrum, meaning that AI is fully integrated into workflows and drives substantial business outcomes. The big question is how business leaders can deploy capital and steer their organizations closer to AI maturity.” But the real insight is not the use of AI itself — it’s the decentralization of how it gets done.</p>



<p>This doesn’t mean the center becomes irrelevant. It means the center becomes an enabler. Its job is to create the conditions for responsible scale, not to own every initiative. That’s a subtle but important shift in how leadership needs to think about structure.</p>



<h2 class="wp-block-heading">When intelligence becomes invisible</h2>



<p>Some of the most powerful AI features are also the quietest. That’s something I’ve come to appreciate as adoption has matured. Early on, AI was treated as a distinct effort — something big and special. Today, the most valuable capabilities are often the ones that feel invisible. They just work.</p>



<p>Consider a finance process like accounts payable. In the past, automation meant scheduling payments strictly on invoice due dates. Now, embedded intelligence can recommend optimal timing based on supplier behavior, working capital goals and historical cash flow patterns. There’s no project name attached to it — just business value being delivered.</p>



<p>This shift — from AI as an initiative to AI as part of the foundation — is one of the most exciting developments I’ve seen. It doesn’t always require data scientists or specialized teams. It calls for product managers and business owners who understand the process and the outcomes they want to improve.</p>



<p>As more enterprise tools embed intelligent features, the role of IT leaders is increasingly about helping teams spot what’s already available, test it safely and scale what works.</p>



<h2 class="wp-block-heading">Measuring the value of AI</h2>



<p>One of the biggest hurdles I hear from leaders is how to measure the value of AI. The truth is, you don’t need a brand-new framework. Most organizations already track ROI, EBIT or productivity gains from the projects their IT teams deliver. The key is simply connecting those outcomes back to the fact that many of those projects are now powered by AI.</p>



<p>Take enterprise software as an example. Modern SaaS platforms — whether CRM, ERP, HR or supply chain — are increasingly embedded with AI features. In fact, most new systems already include intelligent capabilities as part of their core functionality. That means when IT delivers a new SaaS-based pricing system with an estimated ROI of 25% and $6 million in EBIT, the leader doesn’t need to invent a separate “AI metric.” All they need to recognize is that the $6M of EBIT is profitability driven in part by AI. There is no need to overthink it because in a few years, we will not be able to distinguish AI from modern software.</p>



<p>There’s another benefit: the stories about AI become much easier to tell. You no longer have to lean on anecdotes about experimental pilots running in some distant site. AI is already present in many of the enterprise solutions you’re deploying. That means you can add to the pure economic value of the new CRM system and also share stories about how it’s helping the commercial team work more efficiently — or even improving customer NPS.</p>



<p>Of course, not all value will come from enterprise software. There are also opportunities to monetize AI-first solutions — such as digital avatars, copilots and industry-specific applications — as well as custom-built models that solve unique challenges. These, too, should be captured and reported as part of the overall AI value story.</p>



<p>The main point is this: you don’t have to overengineer the measurement process. Simply ride the coattails of existing projects that are already leveraging AI in some way. By doing so, you give stakeholders both the numbers and the narratives they need to see AI as a driver of progress, not just an experiment.</p>



<h2 class="wp-block-heading">Final thoughts</h2>



<p>AI is not optional. But it’s also not magic. Turning AI into an advantage requires a clear sense of purpose, a willingness to let go of central control and the discipline to focus on what really matters.</p>



<p>I’ve learned that success has less to do with how advanced the technology is and more to do with how well it’s aligned with business needs. That means starting with the problem, picking the right approach and building a structure that allows teams to learn and adapt as they go.</p>



<p>It’s not about pilots. It’s about progress. And that starts with being honest about where you are, and bold and responsible enough to move forward.</p>



<p></p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><strong><br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber Incident Response Playbook Examples for 2025]]></title>
<description><![CDATA[Have you read about the massive Salesloft-Drift breach? Did you follow how the Marks and Spencer cyber attack brought the iconic retail brand to its knees? Recently luxury carmaker Jaguar Land Rover suffered a pretty similar fate.]]></description>
<link>https://tsecurity.de/de/2978111/it-security-nachrichten/cyber-incident-response-playbook-examples-for-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2978111/it-security-nachrichten/cyber-incident-response-playbook-examples-for-2025/</guid>
<pubDate>Thu, 11 Sep 2025 11:33:34 +0200</pubDate>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/cyber-incident-response-playbook-examples-for-2025" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/ChatGPT%20Image%20Sep%2011%2C%202025%2C%2002_06_14%20PM.webp" alt="Cyber Incident Response Playbook Examples 2025" class="hs-featured-image"> </a> 
</div> 
<p><span>Have you read about the massive <a href="https://www.cm-alliance.com/cybersecurity-blog/salesloft-drift-attack-one-compromised-integration-shakes-700-cos">Salesloft-Drift breach</a>? Did you follow how the Marks and Spencer cyber attack brought the iconic retail brand to its knees? Recently luxury carmaker Jaguar Land Rover suffered a pretty similar fate. </span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Admin-Leitfaden: Storage-Management 2025]]></title>
<description><![CDATA[Der Admin-Leitfaden: Storage-Management 2025

      
      
        
          
            
                



            
          
        
              
    
  Oliver Altvater
Fr., 05.09.2025 - 10:54


            IT-Administratoren müssen rasant wachsende Datenmengen speichern und immer ...]]></description>
<link>https://tsecurity.de/de/2971939/server/der-admin-leitfaden-storage-management-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2971939/server/der-admin-leitfaden-storage-management-2025/</guid>
<pubDate>Mon, 08 Sep 2025 12:21:01 +0200</pubDate>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Der Admin-Leitfaden: Storage-Management 2025</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/admin-leitfaden-storage-management"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Titelbild_Admin-Leitfaden_Storage-Management%202025.jpg?itok=0FiHa0Sx" width="480" height="319" alt="Fotografische Darstellung eines Speicher- und Rechenzentrums." title="Der Admin-Leitfaden: Storage-Management 2025" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/146" lang about="https://www.it-administrator.de/user/146" typeof="schema:Person" property="schema:name" datatype class="username">Oliver Altvater</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2025-09-05T10:54:00+02:00" title="Freitag, September 5, 2025 - 10:54" class="datetime">Fr., 05.09.2025 - 10:54</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">IT-Administratoren müssen rasant wachsende Datenmengen speichern und immer strengere Compliance-Anforderungen einhalten, ohne die Kosten aus den Augen zu verlieren. Dieser praktische Admin-Leitfaden gibt einen umfassenden Überblick über modernes Storage-Management und zeigt, wie Admins ihre IT-Infrastruktur zum strategischen Wettbewerbsvorteil weiterentwickeln.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/grundlagen" hreflang="en">Grundlagen</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/admin-leitfaden-storage-management" rel="tag" title="Der Admin-Leitfaden: Storage-Management 2025" hreflang="en">Weiterlesen<span class="visually-hidden"> über Der Admin-Leitfaden: Storage-Management 2025</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 tips for future-proofing your IT leadership career]]></title>
<description><![CDATA[Back in 2009 George Westerman and Richard Hunter introduced the idea of the CIO Plus in their book The Real Business of IT: How CIOs Create and Communicate Value.



Westerman says what he and Hunter noticed at the time was that the CIO role was expanding in both its responsibilities and its abil...]]></description>
<link>https://tsecurity.de/de/2971936/it-security-nachrichten/5-tips-for-future-proofing-your-it-leadership-career/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2971936/it-security-nachrichten/5-tips-for-future-proofing-your-it-leadership-career/</guid>
<pubDate>Mon, 08 Sep 2025 12:20:09 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Back in 2009 <a href="https://www.cio.com/article/4051052/George%20F%20Westerman%20%7C%20MIT%20Sloan">George Westerman</a> and Richard Hunter introduced the idea of the <a href="https://www.cio.com/article/419565/cios-step-up-to-fill-plus-size-leadership-roles.html">CIO Plus</a> in their book <em>The Real Business of IT: How CIOs Create and Communicate Value</em>.</p>



<p>Westerman says what he and Hunter noticed at the time was that the CIO role was expanding in both its responsibilities and its ability to make an impact.</p>



<p>Now, 15 years later, Westerman says the CIO role continues to expand. It’s still in charge of infrastructure, and it <a href="https://www.cio.com/article/4009145/who-should-really-be-driving-business-transformation-today.html">often owns transformation</a>. It should have strategy, too. It should become more visionary, too, looking around corners to learn about emerging technology and figuring out how their organizations will be impacted by it.</p>



<p>More than ever, the C-suite is counting on the CIO to deliver. Indeed, 94% of CIOs are now expected to regularly report to the board on technology investments and their ROIs, according to the <a href="https://www.cio.com/article/4051052/Logicalis%20CIO%20Report%202025%20%7C%20Logicalis%20%7C%20Download%20your%20copy">2025 Global CIO Report from IT services and solutions provider Logicalis</a>. Some 85% of surveyed CIOs also said they face growing pressure for technology to demonstrate tangible business impact within their organizations.</p>



<p>To deliver on such expectations and ensure career longevity, CIOs and executive advisers cite these five strategies for future-proofing IT leaders’ careers.</p>



<h2 class="wp-block-heading">1. Lead strategy, don’t just contribute</h2>



<p>The need for CIOs to be <a href="https://www.cio.com/article/220136/cio-playbook-4-steps-to-becoming-a-c-suite-strategic-advisor.html">strategic advisers to their C-suite colleagues</a> is not new.</p>



<p>“There has been a steady progression for years for CIOs to become more strategic leaders,” says Westerman, a senior lecturer at the MIT Sloan School of Management, founder of the <a href="https://gof.mit.edu/" rel="nofollow">Global Opportunity Forum</a>, and co-chair of the MIT Sloan CIO Leadership Award.</p>



<p>But as the world heads into a future where artificial intelligence will reshape nearly every job and process, many will expect the CIO to lead strategy, not merely contribute.</p>



<p>Westerman acknowledges that many CIOs are already doing that, but he also says many are not.</p>



<p>“There are a lot of IT leaders who don’t get it yet, and they now have to become the strategy leader they should have been all along,” he says, adding that this dynamic persists because most IT talent still rises to top IT positions because of their technical skills and not their management and leadership capabilities.</p>



<p>For CIOs who aren’t yet engaged in strategy, Westerman and others say the key is to understand in depth the organization’s goals and how technology can help them.</p>



<p>The next step — and the one to take for CIOs already contributing to strategy — is to identify where and how technology provides measurable value and revenue to the organization and lead those initiatives.</p>



<p>“As a CIO you still have to keep things running, secure, help drive transformation, but you’ve also got to help people be aware of what’s possible with technology,” Westerman says. “Help them understand how IT helps the business. Focus on how you communicate the value of technology.”</p>



<p><a href="https://www.linkedin.com/in/troyrydman/" rel="nofollow">Troy Rydman</a>, CIO and CISO of Packsize, has been attentive to this dynamic, saying he focuses on understanding business processes, as well as how and where technology can “grow the company more quickly.”</p>



<p>“It’s about having a strategy for growth, understanding the market, where your competitors are at, and what technology they’re using. As a CIO that falls upon me,” he adds.</p>



<h2 class="wp-block-heading">2. Embrace the technologist persona</h2>



<p>In recent years some questioned whether IT chiefs really needed a technology background, but experts now say it’s clear that modern CIOs do indeed need to be well versed in technology. The role, they say, needs the triad: deep technology skills, business acumen, and strategic vision.</p>



<p>“The CIO needs a vision of what IT needs to be and the ability to execute,” says <a href="https://mitsloan.mit.edu/faculty/directory/keri-pearlson" rel="nofollow">Keri Pearlson</a>, senior lecturer and principal research scientist at MIT Sloan School as well as founding president of the Austin Society for Information Management (SIM).</p>



<p><a href="https://www.linkedin.com/in/matthewerichard/" rel="nofollow">Matt Richard</a>, CIO of Laborers’ International Union of North America (LIUNA), says the AI revolution demonstrates just how valuable the CIO’s technical capabilities are, as it has been up to CIOs to dig into AI’s potential, limits, and risks then <a href="https://www.cio.com/article/3974090/state-of-the-cio-2025-cios-set-the-ai-agenda.html">devise the strategies for their organizations</a> on how to use it most effectively.</p>



<p>“We’re figuring out how AI will change how we live and work, but AI is just the latest revolution in technology. There was the internet, then the move to cloud, now AI. There will always be new tools, and we [CIOs] need to know how these things work, so we can inform others on how to use the tools,” Richard says.</p>



<p>To do that, Richard commits to learning about emerging technologies and “what they can do, how they’ll impact jobs, how they’re going to change how teams do work, how to implement them, how to find partners, how to manage expectations, and how to make sure we have security and guardrails.”</p>



<p>He takes sales calls from vendors and schedules demos, admitting he does so specifically to learn, not to buy.</p>



<p>And he still plays around with tech, breaking it and putting it back together, so to speak, to test its limits — a pastime many CIOs share.</p>



<p>“That’s important to do now and in the future. CIOs should be getting into the sandbox and trying to build things as the technology comes out,” Richard adds, noting that many did as much when generative AI appeared on the scene with the November 2022 launch of ChatGPT.</p>



<p><a href="https://www.hbs.edu/about/leadership/beth-clark" rel="nofollow">Beth Clark</a>, CIO at Harvard Business School, also embraces this part of CIO work.</p>



<p>“I think really deep understanding of AI, machine learning, and generative AI are so critical. I need an understanding of the benefits, the dangers, how they sit in our environment,” she says. “I’m doing deep dives into technologies, and it’s fascinating to me. The space is always evolving, and I’m always learning.”</p>



<h2 class="wp-block-heading">3. Drive change with agility, speed, and empathy</h2>



<p>Many CIOs have embraced the <a href="https://www.cio.com/article/2088578/state-of-the-cio-2024-change-makers-in-the-business-spotlight.html">change agent</a> aspects of their jobs. That, though, is not enough in an age where new technologies evolve at an ever-increasing pace, where change is constant, the impacts of that are significant, and fears of job loss and displacement are high.</p>



<p>“It can be an exciting time or a fearful time, but the CIOs who future-proof their careers are working on how they communicate around that, and how they show up and lead,” says executive coach <a href="https://llmcg.com/about/" rel="nofollow">Lacey Leone McLaughlin</a>, president and founder of LLM Consulting Group and host of the podcast “<a href="https://podcasts.apple.com/us/podcast/unfolding-leadership/id1599371169" rel="nofollow">Unfolding Leadership</a>.”</p>



<p>To be effective leaders now and tomorrow, Leone McLaughlin explains that CIOs must “communicate it in a way that excites versus elicits fear. They need to say, ‘We’ve gone through changes before; it just has to happen more often and faster, and [this new technology] will help us get smarter, help us do jobs better, help you spend time on tasks that really matter.’”</p>



<p>IT leaders must embody that mindset, too, she says. They need to have — or develop — agility. They must also embrace new technologies, adjust as technologies and markets change, and pivot without fear.</p>



<p>“They need to adapt and adjust to the changes coming, which are coming faster,” she adds. “A larger amount of adaptability is required today, and CIOs should be asking, ‘Am I adaptable enough?’”</p>



<p>Harvard Business School’s Clark sees technology reshaping jobs throughout the organization and believes CIOs will help shape the workforce of the future as a result.</p>



<p>“It’s change or die — at a really rapid pace,” she says.</p>



<p>Clark draws on the skills she gained as a social worker early in her career to lead through change now.</p>



<p>“I never stopped using those skills, those human behavior skills, and I need them for the future,” she says.</p>



<p>“Change is hard, and it’s harder now because we’re changing at warp speed, so I find those are skills I use every day,” Clark adds, explaining that such skills help her “ease people’s anxieties about things that are new, very fast, and threatening in many ways.”</p>



<h2 class="wp-block-heading">4. Use curiosity and constant learning to shape your vision of what’s ahead</h2>



<p>Quantum computing is on the horizon, and there’s the possibility that artificial general intelligence will become reality in the future. As such, CIOs say it’s critical that they don’t become complacent or wedded to the technologies they embrace today, because they will all be obsolete someday.</p>



<p>“CIOs can’t afford to be stuck in what worked in the past,” Leone McLaughlin says. “So CIOs have to be curious, ask the right questions, listen, learn, and hire people smarter than they are.”</p>



<p><a href="https://www.ensono.com/company/leadership/savio-lobo/" rel="nofollow">Savio Lobo</a>, CIO of IT services provider Ensono, agrees.</p>



<p>Although he has leveraged the transformative power of AI, he knows the arrival of other disruptive technologies is inevitable. “Today it’s AI; tomorrow it’s something else,” he says.</p>



<p>He’s focusing on learning what that “something else” will be by leaning into briefings, partner engagements, and public forums where people are speculating about what’s next.</p>



<p>“You have to continue to learn; you have to keep up to date,” he says, contending that the CIO is best positioned to create a vision of tomorrow for the executive team. “The CIO should be visionary.”</p>



<p>He expects his direct reports and others on his IT team to do the same, and he works to cultivate a “really good culture of learners” through formal training and development programs with names such as Summit 2025, Aspire, Ignite, and Ascend.</p>



<h2 class="wp-block-heading">5. Improve your leadership abilities</h2>



<p>The amount of change is impacting all jobs, including those in IT — up to and including the CIO role, Pearlson says. So CIOs need to be on top of emerging technology and all the implications that go with them. Otherwise, she says, they could be blindsided and see transformative work move from their office to another. That already happens, she notes, as evidenced by the creation of the <a href="https://www.cio.com/article/230768/what-is-a-chief-digital-officer-a-digital-strategist-and-evangelist-in-chief.html">chief digital officer</a>, <a href="https://www.cio.com/article/657416/the-rise-of-the-chief-transformation-officer.html">chief transformation officer</a>, and <a href="https://www.cio.com/article/657977/chief-ai-officer-what-it-takes-to-land-the-c-suites-hottest-new-job.html">chief AI officer positions</a>.</p>



<p>CIOs who want to work on the opportunities that, for example, quantum computing will present — and not lose that work to a new chief quantum officer — need to demonstrate exemplary leadership capabilities now.</p>



<p>“We are at another inflection point for the skill set and role of a CIO today,” Pearlson adds.</p>



<p>Westerman says many CIOs have work to do here, as they to date have advanced their careers due to their tech talent and not for their management and executive skills. As a result, CIOs often have more work to do to sharpen those skills than others in the C-suite.</p>



<p>CIOs have plenty of opportunities to improve — they just have to be intentional, Westerman says, noting that tried-and-true leadership development strategies continue to work.</p>



<p>Develop relationships, deliver on promised expectations, seek feedback on how to do better, and then find ways to improve. “CIOs should be asking themselves, ‘Am I getting enough feedback? Am I effective in my environment?’” he adds.</p>



<p>Clark sees improving her leadership talents as an ongoing task that takes commitment.</p>



<p>“I’m always looking at my own leadership skills. I make sure I get feedback, so I know I’m effective in what I’m trying to achieve. I’m evaluating if I’m an effective peer for my peers. I’m asking, ‘Am I an effective leader? Am I an effective communicator? Am I getting my message out clearly? I’m doing 360s and really taking in the results, because you can’t become a more effective leader if you don’t know what you need to work on,” Clark says. “It’s a journey, and you do it for the rest of your life.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.15 Beta brings fixes for audio, security issues, Asus ROG Ally and  Lenovo Legion Go]]></title>
<description><![CDATA[While we're all desperate to know what the heck the Steam Frame actually is, Valve released SteamOS 3.7.15 Beta "The Sound of Silence"..Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/2969706/linux-tipps/steamos-3715-beta-brings-fixes-for-audio-security-issues-asus-rog-ally-and-lenovo-legion-go/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2969706/linux-tipps/steamos-3715-beta-brings-fixes-for-audio-security-issues-asus-rog-ally-and-lenovo-legion-go/</guid>
<pubDate>Sat, 06 Sep 2025 23:40:39 +0200</pubDate>
<content:encoded><![CDATA[While we're all desperate to know what the heck the Steam Frame actually is, Valve released SteamOS 3.7.15 Beta "The Sound of Silence".<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt>.</p><p>Read the full article on <a href="https://www.gamingonlinux.com/2025/09/steamos-3-7-15-beta-brings-fixes-for-audio-security-issues-asus-rog-ally-and-lenovo-legion-go/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia networking roadmap: Ethernet, InfiniBand, co-packaged optics will shape data center of the future]]></title>
<description><![CDATA[Nvidia’s networking roadmap includes technology upgrades designed to transform data center compute, connectivity, and storage infrastructure into giant GPU-driven and network-defined AI factories.



Data centers are evolving into a new unit of computing, from a focus on CPUs to GPUs as the prima...]]></description>
<link>https://tsecurity.de/de/2968819/it-security-nachrichten/nvidia-networking-roadmap-ethernet-infiniband-co-packaged-optics-will-shape-data-center-of-the-future/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2968819/it-security-nachrichten/nvidia-networking-roadmap-ethernet-infiniband-co-packaged-optics-will-shape-data-center-of-the-future/</guid>
<pubDate>Sat, 06 Sep 2025 23:30:27 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nvidia’s networking roadmap includes technology upgrades designed to transform data center compute, connectivity, and storage infrastructure into giant GPU-driven and network-defined AI factories.</p>



<p>Data centers are evolving into a new unit of computing, from a focus on CPUs to <a href="https://www.networkworld.com/article/3966130/what-are-gpus-inside-the-processing-power-behind-ai.html">GPUs </a>as the primary computing units and from the distribution of functions across different components to support the infrastructure for AI workloads, <a href="https://www.linkedin.com/in/giladshainer/">Gilad Shainer</a>, senior vice president of networking at Nvidia, told <em>Network World</em>. This infrastructure evolution requires synchronized data movement and encompasses at least four networks: compute, scale-up, scale-out, and access.</p>



<h5 class="wp-block-heading">[ <strong>Related</strong>: <a href="https://www.networkworld.com/article/3562856"><strong>More Nvidia news and insights</strong></a><strong> ]</strong></h5>



<p>“Today, the scale of the data center has shifted. In the era of AI, the data center itself has become the unit of computing. Instead of asking ‘How many CPUs can I buy?’ the question is now, ‘How do I design a data center capable of running my workloads at maximum efficiency?’ Shainer said. “This shift fundamentally changes how we design, connect, and optimize infrastructure. The giant data center has become the new unit of computing, and one current network architecture won’t handle,” he said.</p>



<p>“What’s needed is a layered design with bleeding-edge technologies — like co-packaged optics that once seemed like science fiction,” Shainer explained further in a recent <a href="https://blogs.nvidia.com/blog/networking-matters-more-than-ever/">blog</a>.</p>



<p>“AI factories are rising — massive new data centers built not to serve up web pages or email, but to train and deploy intelligence itself,” Shainer wrote. “Welcome to the age of AI factories — where the rules are being rewritten and the wiring doesn’t look anything like the old internet. These aren’t typical hyperscale data centers. They’re something else entirely. Think of them as high-performance engines stitched together from tens to hundreds of thousands of GPUs — not just built, but orchestrated, operated and activated as a single unit. And that orchestration? It’s the whole game.”</p>



<p>It is this new data center network infrastructure that Nvidia has serious plans to develop now and in the future. Evidence of its intentions can be found in the vendor’s most recent announcement of extensions to Ethernet networking that will let widely distributed GPUs – in servers across multiple data centers, regardless of the distance between them – operate as a single, unified AI supercomputer.</p>



<p><a href="https://www.networkworld.com/article/4044525/nvidia-turns-to-software-to-speed-up-its-data-center-networking-hardware-for-ai.html">Nvidia is baking into its Spectrum-X Ethernet platform</a> a suite of algorithms that can implement networking protocols to allow Spectrum-X switches, ConnectX-8 SuperNICs, and systems with Blackwell GPUs to connect over wider distances without requiring hardware changes. These Spectrum-XGS algorithms use real-time telemetry — tracking traffic patterns, latency, congestion levels, and inter-site distances—to adjust controls dynamically.</p>



<h2 class="wp-block-heading">Ethernet and InfiniBand</h2>



<p>Developing and building Ethernet technology is a key part of Nvidia’s roadmap. Since it first introduced <a href="https://www.networkworld.com/article/1248855/nvidia-launches-spectrum-x-ethernet-stack-for-ai-workloads.html">Spectrum-X</a> in 2023, the vendor has rapidly made Ethernet a core development effort. This is in addition to InfiniBand development, which is still Nvidia’s bread-and-butter connectivity offering.</p>



<h5 class="wp-block-heading"><strong>[ Related: <a href="https://www.networkworld.com/article/4050973/inside-the-ai-optimized-data-center-why-next-gen-infrastructure-is-non-negotiable.html">What is an AI-optimized data center?</a> ]</strong></h5>



<p>“InfiniBand was designed from the ground up for synchronous, high-performance computing — with features like RDMA to bypass CPU jitter, adaptive routing, and congestion control,” Shainer said. “It’s the gold standard for AI training at scale, connecting more than 270 of the world’s top supercomputers. Ethernet is catching up, but traditional Ethernet designs — built for telco, enterprise, or hyperscale cloud — aren’t optimized for AI’s unique demands,” Shainer said.</p>



<p>Most industry analysts predict Ethernet deployment for<a href="https://www.networkworld.com/article/3609889/what-is-ai-networking-how-it-automates-your-infrastructure-but-faces-challenges.html"> AI networking </a>in enterprise and hyperscale deployments will increase in the next year; that makes Ethernet advancements a core direction for Nvidia and any vendor looking to offer AI connectivity options to customers.</p>



<p>“When we first initiated our coverage of AI back-end Networks in late 2023, the market was dominated by InfiniBand, holding over 80% share,” wrote <a href="https://www.linkedin.com/in/samehboujelbene/">Sameh Boujelbene</a>, vice president of Dell ’Oro Group, in a <a href="https://www.delloro.com/news/ethernet-is-winning-the-war-against-infiniband-in-ai-back-end-networks/">recent report</a>. “Despite its dominance, we have consistently predicted that Ethernet would ultimately prevail at scale. What is notable, however, is the rapid pace at which Ethernet gained ground in AI back-end networks. As the industry moves to 800 Gbps and beyond, we believe Ethernet is now firmly positioned to overtake InfiniBand in these high-performance deployments.”</p>



<p>In the coming year or two, “Ethernet will become the more prominent technology for networking, surpassing InfiniBand as 800G ramps and 1.6T take form,” predicts <a href="https://650group.com/">650 Group</a> in a <a href="https://650group.com/blog/ethernet-ai-networking-revenue-surges-over-150-y-y-bandwidth-over-200-y-y-in-2024/">recent report</a>. “The 800G cycle for AI will set records for revenue and ports.”</p>



<p>“Spectrum‑X is fully standards‑based Ethernet. In addition to supporting Cumulus Linux, it supports the open‑source <a href="https://www.networkworld.com/article/969241/meet-sonic-the-new-nos-definitely-not-the-same-as-the-old-nos.html">SONiC</a> network operating system — giving customers flexibility,” Shainer wrote. “A key ingredient is Nvidia SuperNICs — based on Nvidia BlueField-3 or ConnectX-8 — which provide up to 800 Gb/s RoCE connectivity and offload packet reordering and congestion management.”</p>



<p>“Spectrum-X brings InfiniBand’s best innovations — like telemetry-driven congestion control, adaptive load balancing and direct data placement — to Ethernet, enabling enterprises to scale to hundreds of thousands of GPUs,” Shainer wrote. “Large-scale systems with Spectrum‑X, including the world’s most colossal AI supercomputer, have achieved 95% data throughput with zero application latency degradation. Standard Ethernet fabrics would deliver only ~60% throughput due to flow collisions.”</p>



<h2 class="wp-block-heading">Copper and optics</h2>



<p>Optics is an important element in the connectivity for scale up networks, for Nvidia’s NVLink, because of the huge amount of bandwidth that runs between those connected GPU silicon devices.</p>



<p>“We are focusing on increasing the compute density inside of a single rack, so that single rack could use copper. Copper consumes zero power, it’s reliable, very cost effective. As long as you can use copper, use copper. But when customers scale out to greater distances, copper cannot be used because it cannot run those distances, and this is where need to go optics,” Shainer said.</p>



<p><a href="https://www.networkworld.com/article/3989598/nvidia-opens-nvlink-to-competitive-processors.html">NVLink</a> is the company’s flagship high-speed interconnect technology, born out of its Mellanox networking group, which lets multiple GPUs in a system or rack share compute and memory resources, thus making many GPUs appear to the system as a single processor.</p>



<p>Currently, NVLink features up to 1.8 TB/s of bi-directional bandwidth per GPU, supporting up to 72 GPUs per rack. Faster and higher capacity NVLink technology is expected to evolve rapidly in the new few years to handle higher speeds and even more GPU-to-GPU communications.</p>



<p>In the optical arena, Nvidia offers pluggable optics for its Ethernet and InfiniBand networking gear. But this summer, the vendor said it would jump headlong into the co-packaged optics (CPO) networking world. CPO integrates network optic components directly into a switch ASIC. CPO technology is expected to rapidly develop in the coming months and years to handle AI traffic and ultimately other network traffic that demands high performance. </p>



<p>For its part, Nvidia’s CPO-based products will come in the form of Spectrum-X Photonics for Ethernet and Quantum-X InfiniBand Photonics.</p>



<p>“Nvidia has designed CPO-based systems to meet unprecedented AI factory demands. By integrating optical engines directly onto the switch ASIC, the new Nvidia Quantum-X Photonics and Spectrum-X Photonics will replace legacy pluggable transceivers,” wrote <a href="https://www.linkedin.com/in/m-ashkan-seyedi-2358b66/">Ashkan Seyedi</a>, director of product marketing, in a <a href="https://developer.nvidia.com/blog/scaling-ai-factories-with-co-packaged-optics-for-better-power-efficiency/">blog about the new systems</a> in August. “The new offerings streamline the signal path for enhanced performance, efficiency, and reliability. These innovations not only set new records in bandwidth and port density but also fundamentally alter the economics and physical design of <a href="https://www.networkworld.com/article/4050973/inside-the-ai-optimized-data-center-why-next-gen-infrastructure-is-non-negotiable.html">AI data centers</a>.”</p>



<p>The result of Nvidia’s CPO suite is a 3.5x leap in power efficiency compared to previous architectures, and a 10x improvement in resiliency by reducing the number of overall optical components that may fail, Seyedi stated.</p>



<h2 class="wp-block-heading">Nvidia’s networking business</h2>



<p>Ultimately, workloads are continuing to advance, and they require more computing capabilities and bigger computing infrastructure, Shainer said.</p>



<p>“The AI factory has become a single unit, and the infrastructure, or the network, defines what that single unit can do. So that makes the infrastructure a critical item, and it needs to be designed in a consistent way, it needs to be designed together with everything else. This is where you will see innovation coming, innovation in software framework, especially in hardware science. You will see network functions being run on the NIC and GPU and more,” Shainer said.</p>



<p>The importance of networking for Nvidia’s business is already showing up in its financial reporting. </p>



<p>The Futurum Group <a href="https://futurumgroup.com/insights/nvidia-q2-fy-2026-earnings-networking-steals-the-spotlight/?utm_campaign=1812644_Futurum%20Tech%20News%20Research%20Update%20for%20September%203%2C%202025&amp;utm_medium=email&amp;utm_source=Futurum%20Research&amp;dm_i=4R13,12UN8,5UW2QT,52RCX,1">noted after Nvidia’s most recent quarterly financial call</a> that the vendor’s networking was a record bright spot, with revenue almost doubling year-over-year to $7.3 billion, driven by strong adoption of Spectrum-X Ethernet, InfiniBand XDR, and NVLink scale-up systems.</p>



<p>“Spectrum-X surpassed a $10 billion annualized run rate, and NVIDIA unveiled Spectrum-XGS, designed to interconnect multiple giga-scale AI factories. InfiniBand revenue nearly doubled sequentially, reflecting its role in low-latency networking for leading model makers. NVLink, now in its fifth generation, provides 14x the bandwidth of PCIe Gen 5, a critical enabler of rack-scale Blackwell systems. With networking efficiency gains directly translating to significant customer savings, this business is becoming a critical margin driver and reinforces Nvidia’s positioning as a full-stack AI infrastructure vendor,” Futurum wrote.</p>



<p>Networking emerged as the most impressive growth driver in Q3, Futurum wrote. “As of today, we still believe this segment remains underappreciated and underestimated by many. We expect investors’ awareness of the importance of networking, including scale-up, scale-out, and scale across, as well as the comparative advantage it provides to Nvida’s overall edge over its competitors and attractiveness to customers,” Futurum stated.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Admin-Leitfaden: Storage-Management 2025]]></title>
<description><![CDATA[Der Admin-Leitfaden: Storage-Management 2025

      
      
        
          
            
                



            
          
        
              
    
  Oliver Altvater
Fr., 29.08.2025 - 10:30


            IT-Administratoren müssen rasant wachsende Datenmengen speichern und immer ...]]></description>
<link>https://tsecurity.de/de/2964147/server/der-admin-leitfaden-storage-management-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2964147/server/der-admin-leitfaden-storage-management-2025/</guid>
<pubDate>Fri, 29 Aug 2025 10:50:13 +0200</pubDate>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Der Admin-Leitfaden: Storage-Management 2025</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/admin-leitfaden-storage-management-2025"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/Titelbild_Admin-Leitfaden_Storage-Management%202025.jpg?itok=0FiHa0Sx" width="480" height="319" alt="Fotografische Darstellung eines Speicher- und Rechenzentrums." title="Der Admin-Leitfaden: Storage-Management 2025" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/146" lang about="https://www.it-administrator.de/user/146" typeof="schema:Person" property="schema:name" datatype class="username">Oliver Altvater</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2025-08-29T10:30:00+02:00" title="Freitag, August 29, 2025 - 10:30" class="datetime">Fr., 29.08.2025 - 10:30</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">IT-Administratoren müssen rasant wachsende Datenmengen speichern und immer strengere Compliance-Anforderungen einhalten, ohne die Kosten aus den Augen zu verlieren. Dieser praktische Admin-Leitfaden gibt einen umfassenden Überblick über modernes Storage-Management und zeigt, wie Admins ihre IT-Infrastruktur zum strategischen Wettbewerbsvorteil weiterentwickeln.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/grundlagen" hreflang="en">Grundlagen</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/admin-leitfaden-storage-management-2025" rel="tag" title="Der Admin-Leitfaden: Storage-Management 2025" hreflang="en">Weiterlesen<span class="visually-hidden"> über Der Admin-Leitfaden: Storage-Management 2025</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Easing the pressure on the electrical grid with AI]]></title>
<description><![CDATA[It’s said that the U.S. electrical grid—a nationwide labyrinth of interconnected power plants, transmission lines, substations, and more—is the largest machine in the world. If that’s the case, this machine is starting to sputter.



After decades of flat electricity demand, this infrastructure-h...]]></description>
<link>https://tsecurity.de/de/2962860/it-security-nachrichten/easing-the-pressure-on-the-electrical-grid-with-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2962860/it-security-nachrichten/easing-the-pressure-on-the-electrical-grid-with-ai/</guid>
<pubDate>Thu, 28 Aug 2025 17:06:18 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It’s said that the U.S. electrical grid—a nationwide labyrinth of interconnected power plants, transmission lines, substations, and more—is the largest machine in the world. If that’s the case, this machine is starting to sputter.</p>



<p>After decades of flat electricity demand, this infrastructure-heavy ecosystem has begun an era of dramatic complexity: AI-driven data centers are proliferating rapidly, each demanding hundreds of megawatts; the electric vehicle (EV) industry is booming, along with its fast-growing charging infrastructure sector; and all the while, the energy transition continues to confound utilities, which must ‘park’ new energy from renewables in vast storage systems strewn across the country, until it can be safely released onto the grid.</p>



<p>The upshot: over the next five to 10 years, North America will be at “elevated or high risk” of energy shortfalls, according to the North American Electric Reliability Corp. (NERC).<sup>1</sup></p>



<p>There is a way through the complexities, however. For Hitachi, a company with a heritage in energy and industrial technologies, as well as decades in AI, such challenges require a methodical approach. They require boiling down the industrial problems into multiple, workable mathematical problems; tackling one challenge at a time, methodically with AI; and utilizing the unique capabilities and expertise from Hitachi Group companies. This is how Hitachi is easing the mounting pressures on the grid.</p>



<h2 class="wp-block-heading"><strong>Taming computational demand</strong></h2>



<p>It’s the kind of approach the company brought to a major regional grid operator in the U.S., that was looking for help reducing the extraordinary length of time needed for the requisite impact studies – formal reports needed before introducing new energy sources onto the grid. It’s also the approach Hitachi takes to build some of the most comprehensive and reputable datasets on energy generation and consumption, from which it can test models to achieve the most reliable outcomes.</p>



<p>And while some view industrial challenges with a disruptive mindset, Hitachi knows when to embrace industrial AI as a “co-pilot.” Its technology works alongside systems in which utilities have made significant investments, rather than replacing them. “We will be part of the utility ecosystem as an accelerator,” says Bo Yang, vice president and head of the Energy Solutions Lab at Hitachi America R&amp;D.</p>



<p>According to Yang, disruptive innovation has its place. But there’s also a practical reason for this approach: the computational demands are enormous. Federal Energy Regulatory Commission (FERC) guidelines require exhaustive analysis of how new power generation affects grid stability, not just under current conditions, but across future scenarios and potential system failures.</p>



<p>Take the grid project. When power companies apply to connect new generators, operator’s software must run tens of thousands of simulations to ensure grid stability. This process traditionally took years. Hitachi’s industrial AI technology speeds up the analysis by running multiple calculations simultaneously, a technique known as parallel processing, while the operator’s existing software stays in place to validate complex cases and final results.</p>



<p>This hybrid approach reduced analysis times by 80%—reducing total review time from 27 months to within a year—while maintaining the rigorous safety standards the industry demands.</p>



<h2 class="wp-block-heading"><strong>The village approach</strong></h2>



<p>Connecting new generators to the grid requires complex collaboration across the energy industry. Multiple stakeholders—project developers, independent system operators, transmission operators, regulators, and others—each rely on data-driven analysis to make critical decisions. The entire “village” must reach consensus before new generation can connect to the grid.</p>



<p>Success in this environment requires both deep industry knowledge and advanced AI capabilities. The Hitachi team working on the grid operator’s project includes power engineers with decades of experience who understand the mathematical and operational foundations of power system analysis.</p>



<p>This expertise enables them to pinpoint which parts of the process can be accelerated by AI and which require traditional approaches.</p>



<p>“AI specialists often have strong algorithmic skills, but they may not be focused on the right industry problems,” Yang says. “Meanwhile, legacy analytical tools—some dating back decades—have limitations that new AI methods can overcome when applied thoughtfully.”</p>



<h2 class="wp-block-heading"><strong>Breaking down complex problems</strong></h2>



<p>Industrial challenges often involve highly complex, interconnected processes that can be broken down into smaller mathematical problems. In power systems, for example, this means separating the analysis into distinct tasks. Every task focuses on different aspects of grid stability and performance.</p>



<p>Each component presents opportunities for AI acceleration while maintaining the physical constraints and safety requirements that govern power system operations. Industrial AI doesn’t need to reinvent the physics of power systems. It needs to accelerate the computational analysis that utilities already understand.</p>



<p>This systematic approach extends beyond individual projects. The same industrial AI framework developed for power grid applications applies to other physics-based analytical processes across industries—from rail transportation systems where safety is paramount, to manufacturing operations requiring precise control, to mobility solutions demanding real-time optimization.</p>



<p>“The key is understanding the specific problem you’re solving and then determining which AI technique to apply,” Yang says. This problem-first methodology suggests how the same framework might work across different industries.</p>



<h2 class="wp-block-heading"><strong>Industrial AI is different</strong></h2>



<p>Utilities carry enormous responsibility for infrastructure that powers entire regions. This creates a fundamental challenge for AI adoption: algorithms alone aren’t enough. Effective implementation requires deep understanding of operational constraints, regulatory requirements, and the physics of power systems that takes years to accumulate and validate.</p>



<p>This reality makes industrial AI fundamentally different. It’s not about disrupting existing systems. It’s about enhancing them with the precision that critical infrastructure demands. The most revolutionary AI is often the most methodical—not because it lacks ambition, but because it simply can’t afford to fail.</p>



<p class="has-text-align-center">_____________________</p>



<p><em>For more information about Hitachi’s industrial AI work, visit: </em><a href="https://hitachidigital.com/ai-resource-center/" rel="sponsored"><em>AI Resource Center – Hitachi Digital</em></a></p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p><sup>1 </sup><a href="https://www.publicpower.org/periodical/article/urgent-need-resources-over-10-year-horizon-electricity-demand-growth-accelerates-nerc?utm_source=chatgpt.com" rel="sponsored">Urgent Need for Resources Over 10-Year Horizon as Electricity Demand Growth Accelerates: NERC | American Public Power Association</a></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Biotechs Turn to Digital Coins, Crypto to Boost Stock Prices]]></title>
<description><![CDATA[Struggling small biotech firms are pivoting into cryptocurrencies, rebranding as "crypto treasuries" or stockpiling digital assets like Ether and Litecoin as a last-ditch effort to boost share prices amid stalled funding and weak drug pipelines. Bloomberg reports: Shares of 180 Life Sciences Corp...]]></description>
<link>https://tsecurity.de/de/2957436/it-security-nachrichten/biotechs-turn-to-digital-coins-crypto-to-boost-stock-prices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2957436/it-security-nachrichten/biotechs-turn-to-digital-coins-crypto-to-boost-stock-prices/</guid>
<pubDate>Tue, 26 Aug 2025 01:18:37 +0200</pubDate>
<content:encoded><![CDATA[Struggling small biotech firms are pivoting into cryptocurrencies, rebranding as "crypto treasuries" or stockpiling digital assets like Ether and Litecoin as a last-ditch effort to boost share prices amid stalled funding and weak drug pipelines. Bloomberg reports: Shares of 180 Life Sciences Corp., now doing business as ETHZilla, tripled after the Peter Thiel-backed company said it had accumulated Ether tokens worth over $350 million. Less than two weeks later, the stock's gains have been erased. In July, Sonnet BioTherapeutics Holdings soared 243% in one volatile session on plans to transform into a public crypto treasury while MEI Pharma Inc. initially doubled on plans to sell shares to fund a Litecoin treasury.
 
Such about-faces are a tried-and-true formula for small firms when funds are low and shares are under pressure. For drugmakers it can be a sudden shift to chase after trendy new treatment targets, still other companies rebrand with buzzwords like artificial intelligence to juice returns. Now some biotech executives are using digital coins to pump new life into flagging shares. So far in 2025, at least 10 biotechs have announced a pivot into digital assets. The announcements frequently spark frenzied, but short-lived, spikes in shares. "If they're low on ideas, if they can't find relevance in drug development, they're going to try to justify their existence as management in another way," according to Mike Taylor, lead portfolio manager of the Simplify Health Care ETF. "You have a handful of companies trying to reinvent themselves into some other tangent. And, most, if not all won't work out."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Biotechs+Turn+to+Digital+Coins%2C+Crypto+to+Boost+Stock+Prices%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F25%2F08%2F25%2F2145230%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F25%2F08%2F25%2F2145230%2Fbiotechs-turn-to-digital-coins-crypto-to-boost-stock-prices%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/25/08/25/2145230/biotechs-turn-to-digital-coins-crypto-to-boost-stock-prices?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Applying AI Analysis to PDF Threats]]></title>
<description><![CDATA[In our previous post we extended VirusTotal Code Insights to browser extensions and supply-chain artifacts. A key finding from that analysis was how our AI could apply contextual knowledge to its evaluation. It wasn’t just analyzing code in isolation, it was correlating a package's stated purpose...]]></description>
<link>https://tsecurity.de/de/2956989/malware-trojaner-viren/applying-ai-analysis-to-pdf-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2956989/malware-trojaner-viren/applying-ai-analysis-to-pdf-threats/</guid>
<pubDate>Mon, 25 Aug 2025 18:16:10 +0200</pubDate>
<content:encoded><![CDATA[<p>In our <a href="https://blog.virustotal.com/2025/08/code-insight-expands-to-uncover-risks.html">previous post</a> we extended VirusTotal Code Insights to browser extensions and supply-chain artifacts. A key finding from that analysis was how our AI could apply contextual knowledge to its evaluation. It wasn’t just analyzing code in isolation, it was correlating a package's stated purpose (its name and description) with its actual behavior, flagging malicious logic that contradicted its public description. We’re now applying the same idea to one of the most common file formats in the world, the PDF.
</p>
<br>
<center>
  Audio version of this post, created with NotebookLM Deep Dive<br>
  <audio controls preload="none">
    <source src="https://github.com/VirusTotalAudio/VirusTotalAudio/raw/b43df39bca78f6ffd61d32205f1e54198ddb02d5/Code_Insight_PDF.mp3" type="audio/mpeg">
    Your browser does not support the audio element.
  </audio>
</center>
<br>
<p>PDFs are multi-layered. There’s the object tree (catalog, pages, objects, streams, actions, embedded files) and there’s the visible layer (text/images the user reads). Code Insights analyzes both, then correlates: does the document content, claims, and branding make sense given its internal behaviors? That lets us surface not only classic PDF exploitation (e.g., auto-actions, JS, external launches) but also pure social engineering (phishing, vishing, QR-lures) even when the file has no executable logic. This dual approach allows the AI not only to detect malicious code but also to identify sophisticated scams.
</p>

<p>Let's look at real-world samples surfaced by Code Insights during its initial testing phase. We'll start with cases where the PDF contains no malicious code, which traditional engines often miss because there's no executable payload to detect. This is where Code Insights proves useful, identifying clear signs of fraud and social engineering that aim to manipulate the user, not the machine.
</p>
<br>
<p><b>Case 1 - Fake debt collection targeting financial fraud</b></p>

<p>This PDF is a real-world sample sent to VirusTotal and captured by Code Insights during early testing. It was flagged as malicious based entirely on its visible content, without relying on any embedded code or execution logic. The file was marked as clean by all other engines, likely because it contains no scripts, exploits, or embedded payloads.
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5GceEhdSFtYtw-QkggycE6fbf4uNba2bqXWFk9SMdBU49rEHQaBSsNOmRDLydlgN0gMaKpm5Lsz23KlmI-WpF-UzwCuYSaHI3bF7byPgoISS61s321bw2C71atBaYgfcKLuIEVdb7kH8-2cg3pWxlC6tKvoMtNauKIMuYXMvoTlQwoqVyp4JoII-Sjyg/s1600/Screenshot%202025-08-24%2021.59.16.png"><img alt="" border="0" data-original-height="1183" data-original-width="1593" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5GceEhdSFtYtw-QkggycE6fbf4uNba2bqXWFk9SMdBU49rEHQaBSsNOmRDLydlgN0gMaKpm5Lsz23KlmI-WpF-UzwCuYSaHI3bF7byPgoISS61s321bw2C71atBaYgfcKLuIEVdb7kH8-2cg3pWxlC6tKvoMtNauKIMuYXMvoTlQwoqVyp4JoII-Sjyg/s1600/Screenshot%202025-08-24%2021.59.16.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/d92a1a7460c580f8bf6af3cbd39c7840cfe6a146ee15ede8e23c50c2a85becb9"><span><span>d92a1a7460c580f8bf6af3cbd39c7840cfe6a146ee15ede8e23c50c2a85becb9</span></span></a></p>
</center>
<p>
</p><p>
The document pretends to be a debt collection notice from a German agency acting on behalf of Amazon. It includes a formal layout, legal threats, payment instructions, and multiple references to German addresses and regulations. Visually, it looks legitimate.
 </p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4T0_zii6n5_GOnCDZnW7HVM7kb9mRVqepB1KnXH8rALl87Brfh9TMotkP-BAwPQrb72oStyPyoltipPB4fwRzwPIKQoG2dxwHfEO4_eNxIoplltz5GbyHlF9c3M_B5L1xYfjYstpAHDx8-DGIZ9xjVMk5FsTN3gNbuYfzVVGCT7z_OHhFgNyIvC4lIKU/s1600/Screenshot%202025-08-24%2022.20.45.png"><img alt="" border="0" data-original-height="1212" data-original-width="919" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4T0_zii6n5_GOnCDZnW7HVM7kb9mRVqepB1KnXH8rALl87Brfh9TMotkP-BAwPQrb72oStyPyoltipPB4fwRzwPIKQoG2dxwHfEO4_eNxIoplltz5GbyHlF9c3M_B5L1xYfjYstpAHDx8-DGIZ9xjVMk5FsTN3gNbuYfzVVGCT7z_OHhFgNyIvC4lIKU/s1600/Screenshot%202025-08-24%2022.20.45.png"></a></div>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcw26qCKzwMQgLoV-xUmWbLdA9hyphenhyphen0kLQ_n531esBchQv7791mtKicszdAHqiPh6Mnt8wILE6MWIGnPqUgk3JFTjIIXgWDEqoLPCaqTCgkzhg06yUVugZRpV0G8vUvNQ6V5iCIcwDaq42PuROMKJfAD_loacqC3bDSpFlZfJF6X1hnpG3m_3cDWxGAxAII/s1600/Screenshot%202025-08-24%2022.20.06.png"><img alt="" border="0" data-original-height="1190" data-original-width="919" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcw26qCKzwMQgLoV-xUmWbLdA9hyphenhyphen0kLQ_n531esBchQv7791mtKicszdAHqiPh6Mnt8wILE6MWIGnPqUgk3JFTjIIXgWDEqoLPCaqTCgkzhg06yUVugZRpV0G8vUvNQ6V5iCIcwDaq42PuROMKJfAD_loacqC3bDSpFlZfJF6X1hnpG3m_3cDWxGAxAII/s1600/Screenshot%202025-08-24%2022.20.06.png"></a></div>
</center>
<br>
<p>
However, the AI flagged it as fraudulent based on several critical inconsistencies, the most important one being the destination bank account. The payment is requested to an IBAN starting with BG, indicating a Bulgarian account. This contradicts the sender's claimed German identity and would be highly unusual for a legitimate German debt agency. This mismatch alone was enough for Code Insights to classify the file as fraudulent. Additional content cues (urgent tone, fee breakdown, legal pressure) support the assessment.
 </p>
<p>
As described in the Code Insights analysis:
 </p>
<p><i>
“The visual and textual content confirms the document is a sophisticated phishing attack. It masquerades as an urgent payment demand from a German debt collection agency, supposedly on behalf of Amazon. The document employs high-pressure tactics, including threats of legal action, additional fees, and credit score damage, to compel the recipient to act quickly. The primary and most conclusive indicator of fraud is the demand for payment to a Bulgarian bank account, which is a stark and highly irregular contradiction to the agency's purported German location and registration.”
 </i></p>
<p>
This is a case where AI adds value by reasoning over the content semantics, not the file structure. 
 </p>
<br>
<p><b>Case 2 - QR-based phishing (quishing) campaign</b></p>
<p>
This is another real-world PDF captured during early testing of Code Insights. At the time of analysis, no antivirus or malware detection engines flagged the file as malicious. The PDF has no embedded scripts, exploits, or execution logic. From a technical perspective, it looks benign.
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKMejnzatP8kfFN1YSTFV8Cu6iAXaeiNKkdLEE66334ATONJH7dOJJX7tzl8TXsQNzdnyZrkR5r5I7wSQ5k7Wd4XFatSqJ7qJNT-G3vM_mzbRPzFYgQII28sZ9Tj-T61C6SjWZ9dhb9axV_Gc0NMdjC2yIgxfhC4hTQ-J9o5ZoPO-2o_1aQ3l54SZ0cBE/s1600/Screenshot%202025-08-25%2010.19.51.png"><img alt="" border="0" data-original-height="1258" data-original-width="1813" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKMejnzatP8kfFN1YSTFV8Cu6iAXaeiNKkdLEE66334ATONJH7dOJJX7tzl8TXsQNzdnyZrkR5r5I7wSQ5k7Wd4XFatSqJ7qJNT-G3vM_mzbRPzFYgQII28sZ9Tj-T61C6SjWZ9dhb9axV_Gc0NMdjC2yIgxfhC4hTQ-J9o5ZoPO-2o_1aQ3l54SZ0cBE/s1600/Screenshot%202025-08-25%2010.19.51.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/259e202847d04866acd76427f53bfd9a15372ed6ed56a9e54ba1c62442c945ee"><span><span>259e202847d04866acd76427f53bfd9a15372ed6ed56a9e54ba1c62442c945ee</span></span></a></p>
</center>
<p>
The visible content, however, impersonates an HR notification about a salary increase. It includes multiple social engineering red flags: awkward grammar, lack of personalization, and an irrelevant privacy disclaimer. The only call to action is a QR code, encouraging the recipient to scan it for more details.
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVqNE8rgKq151gYoXmmNaSJI4yJM7RSdWuOOmwN72CGugCQEKsRKeHubDoRCrPYRMqw_x4wwpewc_R2YSy0VHGiyn7BpLEHq6NFyVeeh6I1j-fob8nsCKzpjeAsV2YVkw0Rpdl2GZ6y3mnYRL805qgpxvjBydwAuPuo4TXjykEuU-xEGWrcCrY_NSLi1I/s1600/Screenshot%202025-08-25%2010.16.07.png"><img alt="" border="0" data-original-height="1643" data-original-width="911" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVqNE8rgKq151gYoXmmNaSJI4yJM7RSdWuOOmwN72CGugCQEKsRKeHubDoRCrPYRMqw_x4wwpewc_R2YSy0VHGiyn7BpLEHq6NFyVeeh6I1j-fob8nsCKzpjeAsV2YVkw0Rpdl2GZ6y3mnYRL805qgpxvjBydwAuPuo4TXjykEuU-xEGWrcCrY_NSLi1I/s1600/Screenshot%202025-08-25%2010.16.07.png"></a></div>
</center>
<br>
<p>
Code Insights analyzed and decoded the QR, extracting the hidden URL. The domain is non-corporate and clearly unrelated to HR or payroll systems. The combination of deceptive HR messaging with a QR code that conceals a phishing URL confirms the document is a credential harvesting fraud delivered via PDF.
</p>
<br>
<p><b>Case 3 - Vishing via fake PayPal alert</b></p>
<p>
This is another real-world PDF flagged by Code Insights during early evaluation. No antivirus or malware detection engines classified the file as malicious. Structurally, it’s simple and inert: there are no scripts, automatic actions, or embedded links. Minor stream decoding errors are present but considered low-risk anomalies.
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidHTXNal46PB7jeXXTebnqDjGdGcWWmEWfnHBGk3s9vkHgOwxt2lcDpOZ16aQL1l722ZVL-CkUkW45Ys0imRu3nx2En4xMHqyDp61OJBbihY5QRjIHYYZ29iCf-RBgcPspf9ypI5IbSGjuthAz9mVdNm70K1MhrhUGL1VdDJ7ZjVTUPOEvIHzJDklTG7I/s1600/Screenshot%202025-08-25%2010.27.57.png"><img alt="" border="0" data-original-height="1240" data-original-width="1819" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidHTXNal46PB7jeXXTebnqDjGdGcWWmEWfnHBGk3s9vkHgOwxt2lcDpOZ16aQL1l722ZVL-CkUkW45Ys0imRu3nx2En4xMHqyDp61OJBbihY5QRjIHYYZ29iCf-RBgcPspf9ypI5IbSGjuthAz9mVdNm70K1MhrhUGL1VdDJ7ZjVTUPOEvIHzJDklTG7I/s1600/Screenshot%202025-08-25%2010.27.57.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/d0bedc70085efff5218b901cdaba95d565df867495181544041ba4b8a6019cea"><span><span>d0bedc70085efff5218b901cdaba95d565df867495181544041ba4b8a6019cea</span></span></a></p>
</center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEih3db7oIRbWSba3a_uIUziQtRnpJg1etWQrurNsDrrjbOfxP6xpow0dm84WCfOMhN9qFe6CR5sy83IAj_8Qo5ZXxEpzTxuw2JPaddbhK4K2UgzoBcytg2b9JnCH2MfC59RXYCsrPntIoIj6Knn_LrEtrLBdU8geJr6EpF2Yi4SIA-yPriicbJIf5xyr6s/s1600/Screenshot%202025-08-25%2010.31.51.png"><img alt="" border="0" data-original-height="1581" data-original-width="1166" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEih3db7oIRbWSba3a_uIUziQtRnpJg1etWQrurNsDrrjbOfxP6xpow0dm84WCfOMhN9qFe6CR5sy83IAj_8Qo5ZXxEpzTxuw2JPaddbhK4K2UgzoBcytg2b9JnCH2MfC59RXYCsrPntIoIj6Knn_LrEtrLBdU8geJr6EpF2Yi4SIA-yPriicbJIf5xyr6s/s1600/Screenshot%202025-08-25%2010.31.51.png"></a></div>
<br>
<p>
The threat lies entirely in the content. The document impersonates PayPal and trusted brands like Visa to deliver a fake security alert about a high-value unauthorized purchase. The language is urgent and designed to induce panic.
</p>
<p>
According to Code Insights:
</p>
<p><i>
“[...]the visual content of the document is a clear social engineering lure designed for a voice phishing (vishing) attack. [...] The document's sole purpose is to persuade the user to call a specific phone number under the pretense of canceling the fraudulent order. The malicious nature is confirmed by several red flags, including an awkwardly phrased greeting and a phone number with a geographic area code (808) that is deceptively labeled as "Toll-Free." This tactic aims to route the victim to a scammer for social engineering and potential fraud.”
 </i></p>
<br>
<p><b>Case 4 - Fake Tax Refund from the Australian Taxation Office</b></p>
<p>
As with previous cases, this PDF wasn’t flagged by any antivirus engine in VirusTotal, but Code Insights identified it as a phishing lure that impersonates the Australian Taxation Office.
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3S2pwif1Un_3fzmq1S_fTu2gUUdpcPvzh6Q7tBvmcboVXYd_SCSvfy1La0uTXgc9_tHPGOOEUzUIzJl9DJ05i1yZNgqaT42Jt0anuIpGyqY-F8Ef2fMvIWMR5STxsZz-Znhz72Gmuxj9G4lniK-QHiD2e3Hpn4qQCEeONu4HANFpACRdZ0iA9FLXnxv8/s1600/Screenshot%202025-08-25%2010.54.40.png"><img alt="" border="0" data-original-height="1305" data-original-width="1823" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3S2pwif1Un_3fzmq1S_fTu2gUUdpcPvzh6Q7tBvmcboVXYd_SCSvfy1La0uTXgc9_tHPGOOEUzUIzJl9DJ05i1yZNgqaT42Jt0anuIpGyqY-F8Ef2fMvIWMR5STxsZz-Znhz72Gmuxj9G4lniK-QHiD2e3Hpn4qQCEeONu4HANFpACRdZ0iA9FLXnxv8/s1600/Screenshot%202025-08-25%2010.54.40.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/b9b763e4b091bc59e9b9f355617622dbabdc1ff2de6707a94ccb26aa7682300e"><span><span>b9b763e4b091bc59e9b9f355617622dbabdc1ff2de6707a94ccb26aa7682300e</span></span></a>
</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhdKge79N7Xcp_Q1vrQFyyJpSRINMWZF1Zow0r-fbErLe0MhFWdw2vs6dCMoFXo6r-iPTzx0_62ViEhLZ6wR9DqJCRIOlChd_k-Yj_9UKLiUNbQ2ReLFfaCXlBurONXAzxzB1VGGYE04I5y1vAAmKTnKSX3tyJF3nsRx8LcGKKYZPc2jNRhfFgFB0onlUQ/s1600/Screenshot%202025-08-25%2010.53.22.png"><img alt="" border="0" data-original-height="1016" data-original-width="957" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhdKge79N7Xcp_Q1vrQFyyJpSRINMWZF1Zow0r-fbErLe0MhFWdw2vs6dCMoFXo6r-iPTzx0_62ViEhLZ6wR9DqJCRIOlChd_k-Yj_9UKLiUNbQ2ReLFfaCXlBurONXAzxzB1VGGYE04I5y1vAAmKTnKSX3tyJF3nsRx8LcGKKYZPc2jNRhfFgFB0onlUQ/s1600/Screenshot%202025-08-25%2010.53.22.png"></a></div>
</center>
<br>  
<p>
As described by Code Insights:
</p>
<p><i>
“This document is a phishing lure designed to impersonate the Australian Taxation Office (ATO). The visual layer uses an authentic-looking government logo and the promise of a tax refund to entice the recipient into clicking an "Access Document" button. The purpose is to have the user provide an electronic signature for a supposed refund authorization, creating a sense of urgency and financial incentive.

The document exhibits multiple red flags common to phishing attacks. These include a generic greeting, a suspicious reference to a .doc file (a common malware vector), instructions that discourage direct replies, and a complete lack of legitimate contact information or alternative methods for verification. The entire premise relies on tricking the user into clicking the button, which likely leads to a malicious website for credential theft or malware download.”
 </i></p>
<br>
<p><b>Auto-executing PDF Posing as a Movie Download</b></p>
<p>
Unlike previous examples, this PDF was flagged by 13 antivirus engines in VirusTotal. In this case, the attack is embedded both in the internal structure of the file and its visual appearance. Code Insights correlates these two layers, the technical and the social, to expose the malicious intent.
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikW1wVAEr1K-KPmpABi30H8o7YvukePvAlm_l8hX3WYsCxwz2XIYqw2T58crhPMpjFljAKxtySIBXTJS5A1v9J1UrVTAHDc8wxsLEBnbAjsx3KTbJP0fPgY1XIZZqrY6UKsZ_FWBmU1Xr_BihuHL7EMBLFVQuW_MZ1_dGhryjD1GsMtx2qzGX-b5yr-yA/s1600/Screenshot%202025-08-25%2011.16.53.png"><img alt="" border="0" data-original-height="1123" data-original-width="1710" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikW1wVAEr1K-KPmpABi30H8o7YvukePvAlm_l8hX3WYsCxwz2XIYqw2T58crhPMpjFljAKxtySIBXTJS5A1v9J1UrVTAHDc8wxsLEBnbAjsx3KTbJP0fPgY1XIZZqrY6UKsZ_FWBmU1Xr_BihuHL7EMBLFVQuW_MZ1_dGhryjD1GsMtx2qzGX-b5yr-yA/s1600/Screenshot%202025-08-25%2011.16.53.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/44e653fe79d1ab160c784c06f4d99def6419e379ef3f802af9f48d595976d2c7"><span><span>44e653fe79d1ab160c784c06f4d99def6419e379ef3f802af9f48d595976d2c7</span></span></a></p>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPX8QOCcj7XAt7BeoDvcds7_qO7zYL5DoK8MrGvNBo4i3px-P00YYZyhZN1v1CN9daSEj4-AHcD0uJCt1WzCS_HWpYFfL3sKjkDJYFuiN_EFgAjN1frL0GG7DFCq8chW9YbfbRcLF3NRGsJuLgPmsiBGslXdIziY56nfiVSdLbl0K0F3ElXIIIq76jO-g/s1600/Screenshot%202025-08-25%2011.20.29.png"><img alt="" border="0" data-original-height="1357" data-original-width="917" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPX8QOCcj7XAt7BeoDvcds7_qO7zYL5DoK8MrGvNBo4i3px-P00YYZyhZN1v1CN9daSEj4-AHcD0uJCt1WzCS_HWpYFfL3sKjkDJYFuiN_EFgAjN1frL0GG7DFCq8chW9YbfbRcLF3NRGsJuLgPmsiBGslXdIziY56nfiVSdLbl0K0F3ElXIIIq76jO-g/s1600/Screenshot%202025-08-25%2011.20.29.png"></a></div>
</center>
<br>
<p>
As described by Code Insights:
</p>
<p><i>
“The document presents a social engineering lure, masquerading as a download page for pirated movies […] to entice users into clicking links. This theme, centered on illegal content distribution, is a common tactic for malware delivery.

Technical analysis of the PDF's internal structure corroborates the malicious intent. The file is configured with an /OpenAction command, a high-risk feature designed to automatically execute an action upon the document being opened […] The combination of a deceptive, high-risk theme with an automatic execution function indicates that the document’s purpose is to compromise the user's system.”
</i></p>
<p>
We are actively improving Code Insight based on what we learn from these early cases. PDF is the 6th most common file type submitted to VirusTotal, with around 100,000 new samples uploaded every day. That volume requires us to be strategic: for now, only a selected percentage of PDF files submitted via the public web interface are processed by Code Insight, as we test, tune, and scale the system.
</p>
<p>
These first results are helping us refine both effectiveness and performance. We’ll continue expanding coverage as we improve detection of threats.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The bi-modal imperative]]></title>
<description><![CDATA[AI has turned up the pressure on the C-suite. CEOs field relentless questions about AI strategy, competitors announce sweeping AI transformations and investors inundate earnings calls with questions about AI initiatives.



Yet for all the fanfare and investment, companies are discovering an unco...]]></description>
<link>https://tsecurity.de/de/2953508/it-security-nachrichten/the-bi-modal-imperative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2953508/it-security-nachrichten/the-bi-modal-imperative/</guid>
<pubDate>Fri, 22 Aug 2025 13:50:08 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI has turned up the pressure on the C-suite. CEOs field relentless questions about AI strategy, competitors announce sweeping AI transformations and investors inundate earnings calls with questions about AI initiatives.</p>



<p>Yet for all the fanfare and investment, companies are discovering an uncomfortable truth. Despite implementing AI tools, deploying chatbots and appointing Chief AI Officers, the transformational impact they were promised simply isn’t materializing. <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" target="_blank" rel="nofollow">According to McKinsey</a>, while 78% of organizations report using AI, over 80% of them saw no tangible enterprise-level impact on earnings. A <a href="https://www.bcg.com/publications/2024/wheres-value-in-ai" target="_blank" rel="nofollow">study by BCG</a> paints a similar picture: only 4% of companies create substantial value from AI initiatives, while 74% struggle to show any value at all.</p>



<p>According to the <a href="https://www.pwc.com/us/en/tech-effect/ai-analytics/ai-predictions.html" target="_blank" rel="nofollow">2025 AI Business Predictions by PwC</a>, 49% of technology leaders already claimed that AI was “fully integrated” into their companies’ core business strategy. That is an impressive but misleading number. While companies are undoubtedly integrating AI, they are largely doing it to do more of the same work, only now with AI.</p>



<p>We’re seeing the same mistake businesses made during the early days of digital transformation: using new technology to do old things slightly better rather than reimagining what’s possible. Compounding the issue, in the race to build the best large language models, organizations <a href="https://www.cio.com/article/3967159/thanks-to-ai-the-data-reckoning-has-arrived.html" target="_blank">focus on data quantity and quality</a>, overshadowing critical gaps in governance and problematic data.</p>



<p>But it’s not too late to get it right by harnessing AI to capitalize on its transformative potential. There’s a clear path forward, and it starts with understanding that AI transformation isn’t a single strategy but a dual one, centered around optimization and innovation.</p>



<h2 class="wp-block-heading">Banking on two modes</h2>



<p>I’ve been struck when speaking to customers in the finance sector how change doesn’t happen overnight and isn’t all or nothing. Financial institutions have seen breakneck-speed innovations and sweeping operational changes. Many customers have welcomed the change, carrying out transactions online and never going into a branch or interacting directly with an employee. Yet others continue to do everything in person, expect physical letters signed by the branch manager and want a teller to guide them. As a result, financial institutions have found themselves improving their current operations while also introducing technological innovations simultaneously.</p>



<p>This extends beyond consumer behavior into operational technology strategy, exemplified by the concept of <a href="https://www.gartner.com/en/information-technology/glossary/bimodal" target="_blank" rel="nofollow">bimodal IT</a> that Gartner introduced back in 2014. The core tenet of a bimodal strategy is to split focus between two distinct modes. Mode 1 focuses on stability, predictability and maintaining core systems. Mode 2 emphasizes agility, speed and innovation, often involving new digital initiatives and customer-facing applications.</p>



<p>As the financial industry has shown us, Modes 1 and 2 are not mutually exclusive. This is the essence of bimodal thinking: rather than thinking of the modes as two consequent steps, businesses should invest resources, strategy and measures in parallel, pursuing bimodal outcomes in performance and productivity optimization and value creation. With AI, this framework is more relevant and useful than ever.</p>



<h2 class="wp-block-heading">Changing the wings while flying</h2>



<p>In the rush for AI adoption, innovation and transformation, companies will need to run their existing business while leveraging AI to free up resources for organizational transformation, which will then drive business transformation. For many companies, the next two years will be the ultimate “change the wings while the plane is flying” exercise.</p>



<p>When evaluating AI objectives, the first step is to identify the prime use cases that extend beyond single-modal approaches. These strategies can be defined as:</p>



<ul class="wp-block-list">
<li><strong>Reduce bottom-line costs.</strong> Implement agentic solutions to automate and increase efficiency, remove friction and optimize throughput.</li>



<li><strong>Increase top-line revenue.</strong> Use AI to maintain production lines, optimize supply chains and streamline processes.</li>



<li><strong>Improve satisfaction.</strong> Enhance experiences for employees, customers and the entire ecosystem to improve satisfaction and the ease of doing business.</li>



<li><strong>Drive business transformation.</strong> Create capacity for entirely new business units, service offerings, products or geographical expansion.</li>
</ul>



<p>These are not mutually exclusive. Organizations can pursue single or multiple outcomes through a bimodal approach that enables parallel strategies. As Dan Priest, PwC US chief AI officer, notes: “Top performing companies will move from chasing AI use cases, to using AI to fulfill business strategy.” Like aircraft engineers redesigning and swapping out wings mid-flight, organizations must maintain operational altitude while simultaneously building capabilities that will define their competitive trajectory.</p>



<h2 class="wp-block-heading">Mode 1: Securing your mission-critical operations</h2>



<p>To evaluate your strategy, you must first establish what is essential to the business and use AI to operationalize effectiveness in Mode 1. Mode 1 focuses on establishing and optimizing your business-critical operations. These are the things that provide the core value to create the foundation for innovation. What simply cannot fail? What is generating the core revenue? This could be your production line, telecommunication network, sporting events, citizen services system or anything that drives your revenue and purpose.</p>



<p>In Mode 1, you want to apply AI to process improvement and optimization. What delivery bottlenecks could AI eliminate? Which customer or employee frustrations could be resolved? Could AI remove any of these constraints? The application of AI thinking to Mode 1 operations will reduce costs, increase revenue and improve operational experiences.</p>



<h2 class="wp-block-heading">Mode 2: Boundless innovation</h2>



<p>While Mode 1 creates operational excellence, Mode 2 transforms efficiency gains into exponential growth opportunities. This is where technology makes you faster, more agile and more innovative. The personnel, capital and capacity freed through Mode 1 optimization become the fuel for Mode 2 innovation.</p>



<p>This parallel approach enables new project launches, geographical expansion, product development and service line creation. Your strategic vision should drive Mode 2 initiatives, which will evolve alongside AI technologies and resulting capabilities. Mode 1 achieves linear gains through performance improvements and cost savings. Mode 2 unlocks exponential output.</p>



<p>It is important to note that this exponential output is possible without exponential growth. An AI-first company prioritizes bringing new offerings to the market and dramatically growing revenue without necessarily increasing its size. A <a href="https://www.mckinsey.com/mgi/our-research/americas-small-businesses-time-to-think-big" target="_blank" rel="nofollow">recent McKinsey report on micro-, small- and medium-sized enterprises (MSMEs)</a> highlights that some MSMEs from 2000 “now represent 17 percent of publicly traded companies valued at $10 billion or more as of 2023.” Tech companies show particularly strong performance — nearly 25% of large public tech firms were MSMEs within the past quarter-century. The lesson here is that nimble organizations accelerating innovation cycles will amplify transformation opportunities.</p>



<h2 class="wp-block-heading">The intelligence revolution, by the people and for the people</h2>



<p>The two strategies cannot thrive in isolation. What you wish to achieve in the future, potentially by using a Mode 2 strategy, should influence the design and implementation of your Mode 1 strategy. Have a plan for what those efficiency gains will be used for and prioritize building an organizational foundation that fosters innovation so you can put Mode 2 into action as you carry out Mode 1.</p>



<p>In “<a href="https://www.cio.com/article/3814778/how-ai-can-drive-business-transformation.html">How AI can drive business transformation</a>,” I argued that companies need to strategically reallocate the time freed up by AI rather than simply seeing it as an opportunity for cost-cutting. AI-generated efficiencies have the potential to reinvent your organization through upskilling, skills mapping and innovation initiatives that prepare businesses for an AI-driven future. Now is the time to foster environments where employees feel empowered to explore AI applications, take calculated risks and learn from both successes and failures.</p>



<p>We are in the midst of an intelligence revolution that offers unprecedented opportunities to embrace both optimization and innovation simultaneously. Your AI strategy isn’t about AI—it’s about how AI helps you achieve exponential performance, relevance and market leadership. Organizations mastering this dual approach will define the next generation of business.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><strong><br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Agents Need Data Integrity]]></title>
<description><![CDATA[Think of the Web as a digital territory with its own social contract. In 2014, Tim Berners-Lee called for a “Magna Carta for the Web” to restore the balance of power between individuals and institutions. This mirrors the original charter’s purpose: ensuring that those who occupy a territory have ...]]></description>
<link>https://tsecurity.de/de/2953451/reverse-engineering/ai-agents-need-data-integrity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2953451/reverse-engineering/ai-agents-need-data-integrity/</guid>
<pubDate>Fri, 22 Aug 2025 13:06:54 +0200</pubDate>
<content:encoded><![CDATA[<p>Think of the Web as a digital territory with its own social contract. In 2014, <a href="https://spectrum.ieee.org/the-fathers-of-the-internet-revolution-urge-todays-pioneers-to-reinvent-the-web">Tim Berners-Lee</a> called for a <a href="https://www.theguardian.com/technology/2014/mar/12/online-magna-carta-berners-lee-web">“Magna Carta for the Web”</a> to restore the balance of power between individuals and institutions. This mirrors the original charter’s purpose: ensuring that those who occupy a territory have a meaningful stake in its governance.</p>
<p><a href="https://en.wikipedia.org/wiki/Web3">Web 3.0</a>—the distributed, <a href="https://spectrum.ieee.org/tag/decentralized-web">decentralized Web</a> of tomorrow—is finally poised to change the Internet’s dynamic by returning ownership to data creators. This will change many things about what’s often described as the “CIA triad” of ...</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Architecting the next decade: Enterprise architecture as a strategic force]]></title>
<description><![CDATA[As enterprises navigate waves of emerging technologies and accelerate their digital transformation journeys, the evolution of enterprise architecture has moved to the forefront of technology strategy and future-readiness. No longer a siloed function or a passive blueprinting exercise, enterprise ...]]></description>
<link>https://tsecurity.de/de/2951658/it-security-nachrichten/architecting-the-next-decade-enterprise-architecture-as-a-strategic-force/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2951658/it-security-nachrichten/architecting-the-next-decade-enterprise-architecture-as-a-strategic-force/</guid>
<pubDate>Thu, 21 Aug 2025 13:33:59 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises navigate waves of emerging technologies and accelerate their digital transformation journeys, the evolution of enterprise architecture has moved to the forefront of technology strategy and future-readiness. No longer a siloed function or a passive blueprinting exercise, enterprise architecture is emerging as a strategic force that shapes how organizations respond to change, deliver value and prepare for an increasingly complex and uncertain future.</p>



<p>Today’s technology leaders are reimagining enterprise architecture not merely as a technical foundation, but as a catalyst for resilience, innovation and sustainable business value. The expectations are high: enterprise architecture must not only govern but enable. It must not only design but deliver. Most importantly, it must remain tightly aligned with fast-shifting business priorities.</p>



<p>This forward-looking, industry-agnostic article explores the defining themes of enterprise architecture and strategic technology investments for the remainder of the decade. It also outlines practical enablers that help shape modern investment strategies, ensuring that enterprise architecture keeps pace with both technological change and business imperatives.</p>



<h2 class="wp-block-heading">Enterprise architecture as a strategic catalyst</h2>



<p>Modern enterprise architecture now plays a critical role in aligning technology with business objectives, enabling agility, enhancing governance and accelerating value delivery. Gone are the days when enterprise architecture was seen as a gatekeeper or a compliance function. Today, it is a cross-functional partner driving tangible outcomes such as faster time-to-market, smarter investment decisions and improved customer experience.</p>



<p>According to Gartner, <a href="https://www.gartner.com/en/articles/the-future-of-enterprise-architecture" target="_blank" rel="nofollow">by 2027, 60–70% of enterprises will reposition their enterprise architecture functions to focus on business-outcome-driven transformation</a>, moving beyond traditional IT planning to shape real-time business architecture and adaptive execution strategies.</p>



<p>This implies a fundamental mindset shift from “what do we need to control?” to “how can we enable faster, safer innovation?”</p>



<p>Enterprise architects are increasingly expected to act as translators between boardroom strategy and digital execution. They are orchestrating technology decisions across functions, enabling common platforms and ensuring the reuse of digital capabilities while maintaining agility.</p>



<h2 class="wp-block-heading">AI-infused, dynamic architecture</h2>



<p>Artificial Intelligence is no longer a bolt-on capability; it’s becoming foundational to enterprise architecture. Organizations are moving from experimentation to widespread adoption, embedding AI across their value chains to automate decisions, optimize operations and unlock entirely new revenue models.</p>



<p>AI-ready enterprise architectures are evolving to support real-time data ingestion, scalable compute power, model training and responsible AI governance, which require a new level of coordination between business, data and technology layers.</p>



<p>As referenced in the <a href="https://www.ai.gov/action-plan" target="_blank" rel="nofollow">US Government’s Artificial Intelligence Action Plan</a>, AI is not just reshaping one industry; it’s reshaping them all. The plan outlines how AI is expected to revolutionize sectors such as healthcare, transportation, finance and education, reinforcing the need for architectures that are both adaptable and ethically aligned.</p>



<p>McKinsey’s 2023 report found that <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai-in-2023-generative-ais-breakout-year" target="_blank" rel="nofollow">66% of CEOs have already seen measurable ROI from AI initiatives</a>, with key value areas including sales optimization, supply chain forecasting and intelligent customer service. Enterprise architects are instrumental in scaling these wins by embedding AI enablement across platforms, services and workflows.</p>



<h2 class="wp-block-heading">Composability and modularity for agility</h2>



<p>Composable architecture is becoming the DNA of digital agility. By decomposing large systems into modular components — built on reusable APIs, microservices and event-driven interactions, organizations can deliver faster, innovate with lower risk and adapt to change without re-architecting from scratch.</p>



<p>According to Forrester, <a href="https://www.forrester.com/report/the-composable-enterprise/RES176288" target="_blank" rel="nofollow">composable enterprise initiatives lead to 40–60% faster delivery of digital capabilities</a>. This is because teams can leverage pre-built components, orchestrate new experiences on demand and swap services in or out without affecting core stability.</p>



<p>Composability is especially relevant as AI becomes embedded into business workflows. Modular architecture allows organizations to plug in AI models as interchangeable capabilities, whether it’s a vision model for inspections or a language model for document summarization — without overhauling the core infrastructure.</p>



<p>Furthermore, Gartner notes that <a href="https://www.gartner.com/smarterwithgartner/composable-enterprise" target="_blank" rel="nofollow">by 2026, composable architecture will be a competitive differentiator</a>, enabling businesses to continuously reinvent digital experiences and create new monetization models.</p>



<h2 class="wp-block-heading">Security-embedded, resilient foundations</h2>



<p>In an age of escalating cyber threats and expanding digital footprints, security can no longer be layered on; it must be architected in from the start. With the rise of AI, IoT and even quantum computing on the horizon, the threat landscape is more dynamic than ever.</p>



<p>Security-embedded architectures prioritize identity-first access control, continuous monitoring and zero-trust principles as baseline capabilities. These systems assume breach, verify explicitly and enforce the least privilege at every interaction point.</p>



<p>The <a href="https://csrc.nist.gov/publications/detail/sp/800-207/final" target="_blank" rel="nofollow">NIST Zero Trust Architecture framework</a> outlines the essential pillars of modern security architecture, emphasizing the need for constant evaluation, secure segmentation and strong user authentication.</p>



<p>IDC forecasts that <a href="https://www.idc.com/getdoc.jsp?containerId=US50132723" target="_blank">spending on zero-trust frameworks will exceed $60 billion annually by 2027</a>. This reflects the growing importance of making security adaptive, predictive and integrated into the enterprise’s digital nervous system, not just a defensive shell.</p>



<h2 class="wp-block-heading">Convergence of cloud, edge and data ecosystems</h2>



<p>As businesses become more decentralized and real-time, enterprise architecture must now support a fluid ecosystem of cloud, edge and on-premises technologies. The focus is no longer on where computing happens but on how effectively and securely it can happen everywhere.</p>



<p><a href="https://www.idc.com/getdoc.jsp?containerId=US50039123" target="_blank">Edge computing is expected to handle 75% of enterprise-generated data by 2025</a>, up from 10% in 2018, according to IDC. Whether it’s a manufacturing floor, a retail checkout or a healthcare device, edge systems enable low-latency decision-making and contextual processing without relying on centralized data centers.</p>



<p>This shift demands architectures that are designed for distributed intelligence. From federated learning models to lightweight APIs for device integration, Enterprise architecture must manage the complexity of edge-to-core synchronization, data sovereignty and operational resilience.</p>



<p>Research predicts that the <a href="https://www.precedenceresearch.com/edge-computing-market" target="_blank" rel="nofollow">global edge computing market will grow from $565 billion in 2025 to over $5 trillion by 2034</a>, driven by the convergence of 5G, AI and data-intensive applications.</p>



<h2 class="wp-block-heading">Sustainable, responsible architecture design</h2>



<p>Sustainability is no longer a side initiative; it’s becoming a first principle of enterprise architecture. As organizations face pressure from regulators, investors and customers to lower their carbon footprint, digital sustainability is gaining traction as a measurable design objective.</p>



<p>From energy-efficient data centers to cloud optimization strategies and greener software development practices, architects are now responsible for minimizing the environmental impact of IT systems.</p>



<p>The Green Software Foundation has emerged as a <a href="https://www.gartner.com/en/articles/top-strategic-technology-trends-in-sustainability" target="_blank" rel="nofollow">key ecosystem partner</a>, offering measurement standards like software carbon intensity (SCI) and tooling for emissions-aware development pipelines.</p>



<p>Additionally, Gartner predicts that by 2027, $500 billion in operational expenses will shift toward microgrid-based, renewable-energy-powered infrastructures. These investments not only reduce emissions but also help mitigate energy volatility and regulatory risk.</p>



<p>Enterprise architecture, when designed with sustainability in mind, helps organizations not only meet ESG goals but also <a href="https://greensoftware.foundation/" target="_blank" rel="nofollow">reduce costs, improve brand equity and foster long-term resilience</a>.</p>



<h2 class="wp-block-heading">Evolving role of the technology leader</h2>



<p>Today’s CIOs, CTOs and chief architects are no longer evaluated solely by system uptime or cost control. They are now strategic orchestrators of enterprise value, expected to translate business aspirations into scalable, intelligent and future-ready ecosystems.</p>



<p>Technology leaders must now foster a culture of innovation, build interdisciplinary partnerships and enable experimentation while ensuring alignment with long-term architectural principles. They must guide the enterprise through both transformation and stability, navigating short-term pressures and long-term horizons simultaneously.</p>



<p>Harvard Business Review notes that <a href="https://hbr.org/2022/07/the-new-cio-agenda" target="_blank" rel="nofollow">modern technology executives are being judged on their ability to deliver enterprise-wide innovation</a>, accelerate digital adoption and shape talent strategy in tandem with architecture. This requires a new playbook grounded in influence, foresight and continuous learning.</p>



<h2 class="wp-block-heading">Designing ecosystems for uncertainty and growth</h2>



<p>Enterprise architecture is no longer an isolated planning activity; it is now the strategic backbone of technology and innovation. With AI, modular design, embedded security and sustainability at its core, enterprise architecture enables organizations to build architectures that are adaptive, resilient and future-proof.</p>



<p>In a world marked by continuous change, enterprise architects who embrace this expanded mandate will deliver more than systems; they’ll design intelligent, dynamic ecosystems that power long-term growth and digital advantage.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><strong><br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Biggleboss Incident Review (PC)]]></title>
<description><![CDATA[In a world where AAA studios strive to outdo each other with hyperrealistic visuals and sprawling open worlds, The Biggleboss Incident arrives like a warm, nostalgic breeze from the ‘90s. Developed almost single-handedly by Adam Bunker, a veteran media creative turned indie game developer, this q...]]></description>
<link>https://tsecurity.de/de/2949545/it-security-nachrichten/the-biggleboss-incident-review-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2949545/it-security-nachrichten/the-biggleboss-incident-review-pc/</guid>
<pubDate>Wed, 20 Aug 2025 14:19:13 +0200</pubDate>
<content:encoded><![CDATA[In a world where AAA studios strive to outdo each other with hyperrealistic visuals and sprawling open worlds, The Biggleboss Incident arrives like a warm, nostalgic breeze from the ‘90s. Developed almost single-handedly by Adam Bunker, a veteran media creative turned indie game developer, this quirky point-and-click adventure proudly embraces the charm of retro gaming without trying to reinvent the wheel. Instead, it aims to do something far more admirable: entertain, delight, and pay tribute to a bygone era of gaming.

Bunker, who has spent nearly 20 years writing, strategizing, and crafting content across various media sectors, poured five years of work into this personal passion project. The result is a hand-drawn, fully voice-acted, compact adventure that invites players into the surreal office space of Biggleboss Inc. With a playtime of approximately 4–5 hours, it’s tailored for players who grew up with LucasArts classics and now have a bit less time on their h...]]></content:encoded>
</item>
<item>
<title><![CDATA[Code Insight Expands to Uncover Risks Across the Software Supply Chain]]></title>
<description><![CDATA[Audio version of this post, created with NotebookLM Deep Dive
  
    
    Your browser does not support the audio element.
  





When we launched Code Insight, we started by analyzing PowerShell scripts. Since then, we have been continuously expanding its capabilities to cover more file types. ...]]></description>
<link>https://tsecurity.de/de/2939047/malware-trojaner-viren/code-insight-expands-to-uncover-risks-across-the-software-supply-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2939047/malware-trojaner-viren/code-insight-expands-to-uncover-risks-across-the-software-supply-chain/</guid>
<pubDate>Thu, 14 Aug 2025 10:01:06 +0200</pubDate>
<content:encoded><![CDATA[<center>
  Audio version of this post, created with NotebookLM Deep Dive<br>
  <audio controls preload="none">
    <source src="https://github.com/VirusTotalAudio/VirusTotalAudio/raw/refs/heads/main/Code-Insight-Expands-to-Uncover-Risks-Across-the-Software-Supply-Chain.mp3" type="audio/mpeg">
    Your browser does not support the audio element.
  </audio>
</center>

<br>
<br>

<p>When we launched Code Insight, we started by analyzing PowerShell scripts. Since then, we have been continuously expanding its capabilities to cover more file types. Today, we announce that Code Insight can now analyze a broader range of formats crucial to the software supply chain. This includes browser extensions (CRX for Chrome, XPI for Firefox, VSIX for VS Code), software packages (Python Wheel, NPM), and protocols like MCP that enable Large Language Models to interact with external tools.
</p>

<p>Attackers are increasingly targeting these formats to distribute malware, steal data, or compromise systems. Traditional detection methods, which often rely on signatures or machine learning focused on classification, can struggle to keep up with the dynamic and obfuscated nature of these threats. This is where AI can make a real difference. By analyzing the underlying code logic, Code Insight can identify malicious behavior even in previously unseen threats, providing a deeper level of security analysis.
</p>

<p>This is particularly relevant in a landscape where even a single malicious browser extension can lead to significant data breaches, financial loss, or the compromise of corporate networks.
</p>
<br>
<p><b>A Viral Tweet and a Real-World Example</b></p>

<p>In the last few hours, a tweet from a seasoned crypto user (zak.eth) went viral, narrating how his wallet was drained by a malicious browser extension for the first time in over ten years of activity. This incident is a stark reminder that anyone can be a target.
</p>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoZ75IlNIXsx6GQn2o7JMcQeXIDkzrZ4cLhpSj_uexKMmRSXDmuVChMETmTpX6tgAKhbOC6N1hSzzx58hG4EOh-k3RukCY5mjUwg7qxhw086A1uSueIGa9wxpvdR0HE_irfplWEukhsaAX670MkS6ojsrq6QEOBKY1unI9F7W-tNHtOkoIFG_4wsQFTKw/s1600/Screenshot%202025-08-13%2011.26.02.png"><img alt="" border="0" data-original-height="557" data-original-width="894" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoZ75IlNIXsx6GQn2o7JMcQeXIDkzrZ4cLhpSj_uexKMmRSXDmuVChMETmTpX6tgAKhbOC6N1hSzzx58hG4EOh-k3RukCY5mjUwg7qxhw086A1uSueIGa9wxpvdR0HE_irfplWEukhsaAX670MkS6ojsrq6QEOBKY1unI9F7W-tNHtOkoIFG_4wsQFTKw/s1600/Screenshot%202025-08-13%2011.26.02.png"></a></div>
<br>
<p>
This is a prime example of where Code Insight can be instrumental. It can analyze one of the suspicious extensions mentioned in the thread and reveal its malicious nature:
 </p>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHUUeBlMnjENPVxONsoz6aSgDxtHMn6Q9kN8fNrWlAxdvD79MRupxvHO1U4Vjbw8snWy8l8N-lsoW7InKIdtw9TE1uYE6rjxxCrTjtrBxoM8j0R7FVraDbn7NDZr4n9l6oo8J_4aPEdSnDz86eoklmcCvzdvQMkyVyF7WcNmSC2k_p9PmUP3aBYDJwTUo/s1600/Screenshot%202025-08-13%2011.20.38.png"><img alt="" border="0" data-original-height="479" data-original-width="1439" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHUUeBlMnjENPVxONsoz6aSgDxtHMn6Q9kN8fNrWlAxdvD79MRupxvHO1U4Vjbw8snWy8l8N-lsoW7InKIdtw9TE1uYE6rjxxCrTjtrBxoM8j0R7FVraDbn7NDZr4n9l6oo8J_4aPEdSnDz86eoklmcCvzdvQMkyVyF7WcNmSC2k_p9PmUP3aBYDJwTUo/s1600/Screenshot%202025-08-13%2011.20.38.png"></a></div>
<p>
From here, we will explore different examples of the new formats supported by Code Insight and  specific examples where traditional engines fail to detect a threat.
 </p>
<br>
<p><b>CRX (Chrome Extensions)</b></p>
<p>
CRX files are the format used for packaging Google Chrome browser extensions. While they can enhance browsing, they also represent an attack vector if they contain malicious code. Here is an example of a seemingly legitimate "Norton Safe Search" extension. However, Code Insight's analysis reveals its true, malicious purpose:
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIqgY9L7NFjkxK9F_kIcl0pcDfwNZvORgj8A1QVM8V2Kqcf7q-PvaXFzWW0dOsf7AuHxb_jGjmIR47DuFgWvWHm0Udoj3hiGlrL1QagLVczpm5HEytvWPBTz5i3C63yOr30fPdjw00BrS6FMBobzGp8HmuG1tBCUEOLBNN4oRAsmUN3vHphyphenhyphenV1gE4TqJY/s1600/Screenshot%202025-08-12%2009.40.46.png"><img alt="" border="0" data-original-height="1070" data-original-width="1488" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIqgY9L7NFjkxK9F_kIcl0pcDfwNZvORgj8A1QVM8V2Kqcf7q-PvaXFzWW0dOsf7AuHxb_jGjmIR47DuFgWvWHm0Udoj3hiGlrL1QagLVczpm5HEytvWPBTz5i3C63yOr30fPdjw00BrS6FMBobzGp8HmuG1tBCUEOLBNN4oRAsmUN3vHphyphenhyphenV1gE4TqJY/s1600/Screenshot%202025-08-12%2009.40.46.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/6ca4466baf5ff09bab90a5d06bf113667717400daa59a287393e8f3f10959aba"><span><span>6ca4466baf5ff09bab90a5d06bf113667717400daa59a287393e8f3f10959aba</span></span></a></p>
</center>
<p>
The extension is obfuscated to hide its true purpose. The code in js/background.js communicates with a command and control (C2) server located at a domain unrelated to Norton. The most critical malicious behavior is its capability to fetch and execute arbitrary code from the C2 server. This allows the attacker to dynamically change the extension's functionality after installation, effectively turning the user's browser into a bot.
</p>
<p>
In another case, a banking trojan targeting Westpac customers was identified:
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqtIxWclDvhaowRcxMc9YIWXcNnldXPI7RWDWp0x7Qp7QulmlY0onyYHc0xgs0WYuiXQOVRGjvh16dPZaTPLuGqJqsI33KFBomoAWajss7JforKB-XPZLck32DM9l91BR1tQxhc8e65NmrZ-2Hicbu9Y2PV8dZkzkUAkFhXBWWZkDXdIq3L4QWRP6hZFs/s1600/Screenshot%202025-08-12%2015.05.04.png"><img alt="" border="0" data-original-height="875" data-original-width="1313" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqtIxWclDvhaowRcxMc9YIWXcNnldXPI7RWDWp0x7Qp7QulmlY0onyYHc0xgs0WYuiXQOVRGjvh16dPZaTPLuGqJqsI33KFBomoAWajss7JforKB-XPZLck32DM9l91BR1tQxhc8e65NmrZ-2Hicbu9Y2PV8dZkzkUAkFhXBWWZkDXdIq3L4QWRP6hZFs/s1600/Screenshot%202025-08-12%2015.05.04.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/34244257f633e104d06b0c4273caca96eb916d26540eeea68495707cbc920bdb"><span><span>34244257f633e104d06b0c4273caca96eb916d26540eeea68495707cbc920bdb</span></span></a></p>
</center>
<p>
This extension is a banking trojan specifically targeting Westpac customers. It operates as a Man-in-the-Browser (MitB) malware to steal credentials, session data, and funds. It establishes a persistent WebSocket connection to a hardcoded C2 server, collects all cookies from the browser and intercepts form submissions, specifically targeting the input field for the 'AuthorisationCode' (a 2FA/OTP token).
</p>
<br>
<p><b>VSIX (Visual Studio Code Extensions)</b></p>
<p>
VSIX files are used for extensions in Visual Studio Code, a popular code editor. Developers can be targeted through these extensions, potentially compromising their development environment and projects.
</p>
<p>
A deceptive "Zoom" extension for VS Code was found to be stealing user data:
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhcd7BkIAdc5UXXT_h9yCLb-OJBRKFdD-4opzxpRL3ytvzyp7yRLw1uTO7We-br5s8r5OuhmruRXGrE7CAZ3k8SjxsmVU3yC1WFBhubL3zERKFh8OPXlhxpSxcekjgbQUHxnfHEUfgWcLoVmzqH5_Yz3ELo4beI54QjSvc_TmCxtdgxPnn53D3QfzX4rJE/s1600/Screenshot%202025-08-12%2009.57.22.png"><img alt="" border="0" data-original-height="423" data-original-width="1278" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhcd7BkIAdc5UXXT_h9yCLb-OJBRKFdD-4opzxpRL3ytvzyp7yRLw1uTO7We-br5s8r5OuhmruRXGrE7CAZ3k8SjxsmVU3yC1WFBhubL3zERKFh8OPXlhxpSxcekjgbQUHxnfHEUfgWcLoVmzqH5_Yz3ELo4beI54QjSvc_TmCxtdgxPnn53D3QfzX4rJE/s1600/Screenshot%202025-08-12%2009.57.22.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/5c89ba9e1bbb7ef869e4553081a40cabbd91a70506d759fd4e97eefb0434c074"><span><span>5c89ba9e1bbb7ef869e4553081a40cabbd91a70506d759fd4e97eefb0434c074</span></span></a></p>
</center>
<p>
The extension attempts to access sensitive user data by reading browser cookies from a known local SQLite database file. It also includes functionality to make external network requests to an unusual domain. which could be used to exfiltrate the collected sensitive data. This combination of local data collection and external communication is an indicator of malicious intent, specifically information theft.
</p>
<br>
<p><b>XPI (Firefox Extensions)</b></p>
<p>
XPI files are used for Firefox browser add-ons. Similar to Chrome extensions, they can be used to distribute malware.
</p>
<p>
A "Mass Tiktok Video Downloader" extension was found to be a phishing and data exfiltration tool:
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6k-EI3RuqO6gFmFFGwfEWrSDQIFqg6JGYYHDEqLSN4e3ajaJuol6Vx5oqwmMhkqkwrX3DUHYAo_K4-ltyW_B4jOyxmyS0z86UyUDzMNCfpuAxzyAtjflYoIfj2O-YiHt2uJk6KcxqudX6dSXxV5Xqi3AuWKOMEB2B6Mst88OQYyNb5wctROxgrNv0SCA/s1600/Screenshot%202025-08-12%2014.33.36.png"><img alt="" border="0" data-original-height="467" data-original-width="1317" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6k-EI3RuqO6gFmFFGwfEWrSDQIFqg6JGYYHDEqLSN4e3ajaJuol6Vx5oqwmMhkqkwrX3DUHYAo_K4-ltyW_B4jOyxmyS0z86UyUDzMNCfpuAxzyAtjflYoIfj2O-YiHt2uJk6KcxqudX6dSXxV5Xqi3AuWKOMEB2B6Mst88OQYyNb5wctROxgrNv0SCA/s1600/Screenshot%202025-08-12%2014.33.36.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/2c0c8bd05a4942b389feaeb02c372b6443efac9d0931e0bdc602474178b54e7f"><span><span>2c0c8bd05a4942b389feaeb02c372b6443efac9d0931e0bdc602474178b54e7f</span></span></a></p>
</center>
<p>
It presents a fake Facebook password confirmation popup to phish user credentials. Concurrently, its background script actively collects all browser cookies. All collected data, including the phished passwords, are exfiltrated to a Telegram bot API endpoint.
</p>
<br>
<p><b>WHL (Python Wheel)</b></p>
<p>
WHL files are a standard for distributing Python packages. The threats in these examples are not limited to intentionally malicious code, it also includes packages with critical vulnerabilities or insecure coding patterns that can be exploited in supply chain attacks.
</p>
<p>
An "hh-applicant-tool" designed to interact with an API was found to have a suspicious telemetry feature:
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2u3p3VW1_W3RYpqlqN66ph-oRJeO_KwE8WpYo6f4FfiPdntPzG8dNFikyhqCZsWkVREEDr4TM9QLXt37fQ5pOhFnv91_3lmzhZUHQUAHFLCSs7unwGVgtRGbqo4FfMvowYGyYWhsp5cUAWmjuvEbsqRthE0_kQY53DOU4o4tlADqwqnU_dTtBsA4wdrM/s1600/Screenshot%202025-08-12%2010.52.53.png"><img alt="" border="0" data-original-height="658" data-original-width="1119" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2u3p3VW1_W3RYpqlqN66ph-oRJeO_KwE8WpYo6f4FfiPdntPzG8dNFikyhqCZsWkVREEDr4TM9QLXt37fQ5pOhFnv91_3lmzhZUHQUAHFLCSs7unwGVgtRGbqo4FfMvowYGyYWhsp5cUAWmjuvEbsqRthE0_kQY53DOU4o4tlADqwqnU_dTtBsA4wdrM/s1600/Screenshot%202025-08-12%2010.52.53.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/1a168e47cb2d81f54fe504e66e353251a772164959ec71517d2070bf96fee957"><span><span>1a168e47cb2d81f54fe504e66e353251a772164959ec71517d2070bf96fee957</span></span></a></p>
</center>
<p>
It collects data, including vacancy details, employer information, and Google Docs links found in messages, and sends it to a custom server. This communication explicitly disables SSL certificate verification (verify=False), making the data transfer vulnerable to Man-in-the-Middle attacks.
</p>
<p>
In another instance, a package named "ncatbot" contained a critical security vulnerability:
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5apOluHEVPmj6L8uF2Kv2riOpa9v2DMuORtWxyq6Tq_nCNRnzZOheJUwwombfbut6NNV7lwpWwBBeUuWAAV7irKR9VGwLsnjjErMU01jHO81PxicdaXK7aiqiDze9Aes55qUZoklMRt7u5UddnEsYMx1Fqi6v_ORumOAFVl6nuqcnEVwdVwEkTYY-KOg/s1600/Screenshot%202025-08-12%2010.54.42.png"><img alt="" border="0" data-original-height="631" data-original-width="1119" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5apOluHEVPmj6L8uF2Kv2riOpa9v2DMuORtWxyq6Tq_nCNRnzZOheJUwwombfbut6NNV7lwpWwBBeUuWAAV7irKR9VGwLsnjjErMU01jHO81PxicdaXK7aiqiDze9Aes55qUZoklMRt7u5UddnEsYMx1Fqi6v_ORumOAFVl6nuqcnEVwdVwEkTYY-KOg/s1600/Screenshot%202025-08-12%2010.54.42.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/f2714f6b87689c4d631a587813d14c4e463be7251bf16ff383ad2b7940ca7a4d"><span><span>f2714f6b87689c4d631a587813d14c4e463be7251bf16ff383ad2b7940ca7a4d</span></span></a></p>
</center>
<p>
A critical security vulnerability exists in the Linux installation process, which executes a remote script with root privileges using curl | sudo bash. This allows for arbitrary code execution and system compromise if the remote script is malicious or its source is compromised.
</p>
<br>
<p><b>NPM (Node Package Manager)</b></p>
<p>
NPM is the default package manager for Node.js and is central to the JavaScript ecosystem.
Malicious NPM packages are a constant threat to developers and applications.
</p>
<p>
A package named "serverless-shop-functions" presented as a benign e-commerce application but contained two malicious Python scripts:
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2PvJrCuEZzOMtjBiCnd8Vq4KyBzOdUdl8__yjUFuCt3LlmNFHEFVehHiI_DPrMyCZ9O-Hv3junwYXCs5M0goSyew9klkL6CFjYHdYDMtS6eQhrKw33NMPiF2glSl7J0fVYAJXlm8-lqXlNbqxpYS0mAgG0IVxfqVqfbOcyqhbf3CrZp2Ec0wf0_Lzozc/s1600/Screenshot%202025-08-12%2015.03.43.png"><img alt="" border="0" data-original-height="1015" data-original-width="1313" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2PvJrCuEZzOMtjBiCnd8Vq4KyBzOdUdl8__yjUFuCt3LlmNFHEFVehHiI_DPrMyCZ9O-Hv3junwYXCs5M0goSyew9klkL6CFjYHdYDMtS6eQhrKw33NMPiF2glSl7J0fVYAJXlm8-lqXlNbqxpYS0mAgG0IVxfqVqfbOcyqhbf3CrZp2Ec0wf0_Lzozc/s1600/Screenshot%202025-08-12%2015.03.43.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/8f7a061901c935493e17f3f897a2b98b5ab21350593fda10a6936a84db5b28b7"><span><span>8f7a061901c935493e17f3f897a2b98b5ab21350593fda10a6936a84db5b28b7</span></span></a></p>
</center>
<p>
Backdoor.Python.PolymorphNecro.h is identified as a polymorphic IRC botnet client. Its capabilities include: network sniffing,  ARP poisoning, various DDoS attack methods. Main.py is a Discord-controlled Remote Access Trojan (RAT) with extensive capabilities, including: establishing persistence, executing arbitrary PowerShell commands, capturing and exfiltrating screenshots and webcam photos.
</p>
<br>
<p><b>PyPI (Python Package Index)</b></p>
<p>
PyPI is the official third-party software repository for Python. It's a common target for attackers looking to distribute malicious packages. However, the threat also comes from packages that, while not intentionally malicious, contain critical vulnerabilities in their design.
</p>
<p>
A package named python-mcp-client was found to have severe vulnerabilities allowing for remote code execution:
</p>
<center>
<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1OV1KTZUhESOLcCO8jAxTbz52uT3I_ag1fBNbB8y-_-AeYhWE1OXtvfjvMSuq7_26RQkrWLScx_oe9GHRkfTcKNyD_6DeFnqztNXpzOYoyS4cDVP9MqcfF0yXfHzXuWHEzfJqj1dgKM_p_v5e8iGsYgjuhhN8h9p0ipOKQUvpabCmd3-53Hh7Ckg5L7E/s1600/Screenshot%202025-08-12%2015.23.23.png"><img alt="" border="0" data-original-height="724" data-original-width="1308" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1OV1KTZUhESOLcCO8jAxTbz52uT3I_ag1fBNbB8y-_-AeYhWE1OXtvfjvMSuq7_26RQkrWLScx_oe9GHRkfTcKNyD_6DeFnqztNXpzOYoyS4cDVP9MqcfF0yXfHzXuWHEzfJqj1dgKM_p_v5e8iGsYgjuhhN8h9p0ipOKQUvpabCmd3-53Hh7Ckg5L7E/s1600/Screenshot%202025-08-12%2015.23.23.png"></a></div>
<p dir="ltr">
<a href="https://www.virustotal.com/gui/file/83c4c8d38e3eea555666e26ed85953b7479d46d9b4d2c12c521ae5f505b343d2"><span><span>83c4c8d38e3eea555666e26ed85953b7479d46d9b4d2c12c521ae5f505b343d2</span></span></a></p>
</center>
<p>
The package exposes severe vulnerabilities that allow for remote code execution (RCE) and arbitrary file system operations. The flask_app.py component allows users to dynamically add new MCP servers via the /api/add_server endpoint. This endpoint directly accepts user-provided command and args parameters, enabling an attacker to execute arbitrary shell commands on the host system.
</p>
<p>By expanding Code Insight's capabilities, we aim to provide the cybersecurity community with a tool to better understand and mitigate the evolving threats within the software supply chain. Stay tuned as we continue to enhance our platform to counter new attack vecto</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Create value with AI agents]]></title>
<description><![CDATA[AI agentic systems are evolving faster than any technology in recent memory. Mastering them requires robust data infrastructure, clear ROI metrics, security and trust, and a forward-looking operating model. Starting now can help you leverage AI agents for genuine business transformation. And beyo...]]></description>
<link>https://tsecurity.de/de/2936337/it-security-nachrichten/create-value-with-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2936337/it-security-nachrichten/create-value-with-ai-agents/</guid>
<pubDate>Tue, 12 Aug 2025 21:04:32 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI agentic systems are evolving faster than any technology in recent memory. Mastering them requires robust data infrastructure, clear ROI metrics, security and trust, and a forward-looking operating model. Starting now can help you leverage AI agents for genuine business transformation. And beyond productivity, they are increasingly viewed as catalysts for tangible ROI and market disruption. <a href="https://kpmg.com/us/en/articles/2025/ai-agents-technology-value.html?utm_source=cio.com&amp;utm_medium=referral&amp;utm_campaign=701dV00000EbWAYQA3&amp;cid=701dV00000EbWAYQA3" rel="sponsored">AI agents can help you deliver value.</a></p>



<p>At a recent Wall Street Journal CIO Network Summit,<sup>1</sup> 67% of attendees indicated they’re actively piloting or deploying AI agents. In a poll conducted at roughly the same time by Salesforce, 93% of enterprise IT leaders said they have implemented or plan to implement AI agents in the next two years.<sup>2</sup> This remarkable rise underscores how AI has shifted from a speculative technology to near-mainstream in under two years. </p>



<p>AI agents are often described as a paradigm shift.</p>



<ul class="wp-block-list">
<li>They move AI from passive information retrieval to proactive execution and decision-making.</li>



<li>They possess higher levels of autonomy and intelligence, enabling them to adapt and optimize their actions in response to changes in their environment.</li>



<li>They are evolving from simple “taskers” designed to automate single functions to “orchestrators” where multiple AI agents interact to achieve complex tasks at scale.</li>



<li>They can operate across different domains—for example, in healthcare, they reduce administrative overhead, while in financial services, they help optimize complex trading strategies—demonstrating true cross-industry applicability. </li>
</ul>



<p>KPMG suggests that the paradigm shift lies not just in AI, but in IT as a whole. AI agents are forcing IT to reinvent itself. We would even go so far as to say AI could fundamentally challenge the software as a service (SaaS) model.</p>



<p>Today, many agents are still being considered in the “lift-and-shift” phase, where the only question being asked is, “How can I take advantage of this technology to improve what I do, but without fundamentally changing what I do?” AI agentic systems have yet to be widely embraced as an enabler of business transformation or a catalyst for entirely new business models that can redefine product or service offerings, disrupt markets, and solve sector-wide challenges. </p>



<p>But pressure is mounting to change that. CIOs are hearing from their boards: “<em>We need transformative value, not just incremental efficiency gains</em>.” AI agents may be the answer. </p>



<p><strong><em>Where do you begin?</em></strong><strong><em> </em></strong><strong><em></em></strong></p>



<p>The disruptive potential of AI agentic systems demands a focus on fundamentals to prepare IT to take advantage of the opportunities created. There are three phases of exploration that organizations should consider to help AI agents perform:</p>



<p><strong>Phase 1:</strong> Measure your AI readiness </p>



<p><strong>Phase 2:</strong> Conduct a holistic opportunity assessment </p>



<p><strong>Phase 3:</strong> Implement an AI operating model designed for value, scalability, and sustainability </p>



<p>Learn more about the foundation you’ll need to integrate AI agents, foster innovation, and develop a competitive edge in our <a href="https://kpmg.com/us/en/articles/2025/ai-agents-technology-value.html?utm_source=cio.com&amp;utm_medium=referral&amp;utm_campaign=701dV00000EbWAYQA3&amp;cid=701dV00000EbWAYQA3" rel="sponsored">article on creating value with AI Agents. </a></p>



<p><strong><em>Why time is of the essence:</em></strong> </p>



<p>Just as the cloud forced IT to transform from an organization designed to maintain on-premise servers, AI agents are now challenging existing models and forcing another reinvention. This disruption is accelerating far faster than previous technology shifts, making it critical to initiate your transformation now. </p>



<p> <br>To learn more about how AI agents can help you deliver value, visit <a href="https://kpmg.com/us/en/articles/2025/ai-agents-technology-value.html?utm_source=cio.com&amp;utm_medium=referral&amp;utm_campaign=701dV00000EbWAYQA3&amp;cid=701dV00000EbWAYQA3" rel="sponsored">here</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Paid Ads for Fake Tesla Websites, (Sun, Aug 10th)]]></title>
<description><![CDATA[In recent media events, Tesla has demoed progressively more sophisticated versions of its Optimus robots. The sales pitch is pretty simple: "Current AI" is fun, but what we really need is not something to create more funny kitten pictures. We need AI to load and empty dishwashers, fold laundry, a...]]></description>
<link>https://tsecurity.de/de/2932250/it-security-nachrichten/google-paid-ads-for-fake-tesla-websites-sun-aug-10th/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2932250/it-security-nachrichten/google-paid-ads-for-fake-tesla-websites-sun-aug-10th/</guid>
<pubDate>Sun, 10 Aug 2025 17:07:14 +0200</pubDate>
<content:encoded><![CDATA[<p>In recent media events, Tesla has demoed progressively more sophisticated versions of its Optimus robots. The sales pitch is pretty simple: "Current AI" is fun, but what we really need is not something to create more funny kitten pictures. We need AI to load and empty dishwashers, fold laundry, and mow lawns. But the robot has not been for sale yet, and there is no firm release date.</p>&amp;#x26;#xd&amp;#x26;#x3b; <img alt="screen shot of three different optimus models." src="https://isc.sans.edu/diaryimages/images/Screenshot&amp;#x26;%23x25&amp;%23x26;%23x3b;202025-08-10&amp;%23x26;%23x25&amp;%23x26;%23x3b;20at&amp;%23x26;%23x25&amp;%23x26;%23x3b;208&amp;%23x26;%23x5f&amp;%23x26;%23x3b;37&amp;%23x26;%23x5f&amp;%23x26;%23x3b;11&amp;%23x26;%23x25&amp;%23x26;%23x3b;E2&amp;%23x26;%23x25&amp;%23x26;%23x3b;80&amp;%23x26;%23x25&amp;%23x26;%23x3b;AFAM.png">&amp;#x26;#xd&amp;#x26;#x3b; <p>In the past, Tesla has accepted preorders for future products, asking for a deposit, which in some cases was even refundable. But aside from an April Fool&amp;#x26;#39&amp;#x26;#x3b;s posting announcing such a presale, as far as I can tell, no presale has been offered by Tesla.</p>&amp;#x26;#xd&amp;#x26;#x3b;]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic commerce: How AI is reinventing the way customers discover and buy]]></title>
<description><![CDATA[The way consumers discover, evaluate and purchase products is fundamentally shifting. Traditional commerce experiences — even those considered modern — are built around customers doing the work: searching, filtering, comparing, clicking. But what if the commerce experience could do the work for t...]]></description>
<link>https://tsecurity.de/de/2927702/it-security-nachrichten/agentic-commerce-how-ai-is-reinventing-the-way-customers-discover-and-buy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2927702/it-security-nachrichten/agentic-commerce-how-ai-is-reinventing-the-way-customers-discover-and-buy/</guid>
<pubDate>Thu, 07 Aug 2025 16:03:55 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The way consumers discover, evaluate and purchase products is fundamentally shifting. Traditional commerce experiences — even those considered modern — are built around customers doing the work: searching, filtering, comparing, clicking. But what if the commerce experience could do the work for the customer? That’s the promise of agentic commerce.</p>



<p>As a practitioner leading digital and e-commerce transformation at a leading lifestyle brand, I have seen firsthand how rapidly customer expectations are evolving. They want relevance, speed, simplicity — and they increasingly expect technology to anticipate their needs. Agentic commerce offers a vision of the future where intelligent systems do more than personalize; they participate.</p>



<p>While most customers still rely on filters and categories today, there is a clear shift underway — toward discovery driven by questions, needs and intent-based prompts. Agentic commerce meets them at that moment.</p>



<h2 class="wp-block-heading">What is agentic commerce?</h2>



<p>Agentic commerce refers to a shopping experience powered by intelligent, autonomous and customer-aligned agents. These agents can learn preferences, make suggestions, automate purchases and even negotiate or personalize offers in real time (see <a href="https://www.digitalcommerce360.com/2025/03/20/agentic-commerce-ecommerce-trends/" target="_blank" rel="nofollow">Digital Commerce 360’s overview of agentic commerce for online retail</a>).</p>



<p>It moves beyond rules-based personalization or basic chatbots. Think: a proactive shopping assistant that knows your style, budget, calendar and values and helps you make better choices faster.</p>



<p>This isn’t science fiction. From AI-driven recommendations to dynamic bundles and replenishment nudges, we’re already seeing the building blocks of agentic commerce emerge across categories. In my current role, we’re exploring different options in this space, including allowing our product content to be indexed by LLMs like ChatGPT and Perplexity. The goal? Let customers discover and shop directly through intelligent agents, without ever landing on our website.</p>



<p>By making product content discoverable by AI agents, we’re not just enabling new purchase paths — we’re building a new kind of search experience, where the customer starts outside the site and still finds the perfect product.</p>



<h2 class="wp-block-heading">From personalization to participation: The agentic maturity curve</h2>



<p>Retailers have long relied on reactive personalization — “you bought this, so you might like that.” But agentic commerce introduces a more proactive model: systems that anticipate intent and act on behalf of the customer.</p>



<p>Forward-thinking brands are embedding AI into key customer moments — from discovery and bundling to adaptive checkout — building the infrastructure and behavioral trust required for agent-led transactions. These near-term investments are training grounds for a broader transformation.</p>



<p>As agentic commerce evolves, a maturity model is beginning to take shape across the industry:</p>



<ul class="wp-block-list">
<li><strong>Level 1: Personalized nudges.</strong> Systems react to prior behavior with basic recommendations. </li>



<li><strong>Level 2: Predictive guidance</strong>. AI anticipates intent and proactively suggests bundles or next-best actions. </li>



<li><strong>Level 3: Delegated action</strong>. Intelligent agents complete purchases, manage fulfillment or negotiate offers on the customer’s behalf. </li>
</ul>



<p>Most retailers today operate between Level 1 and 2. Advancing to Level 3 will require not only technical enablement but also executive readiness to delegate decision-making and design for trust.</p>



<p>Customers increasingly expect more than suggestions. This shift challenges the dominance of traditional search engines and even on-site search bars. Instead of users typing in what they want, they increasingly expect the system to surface the right product through a dialogue — or simply deliver it.</p>



<h2 class="wp-block-heading">Checkout innovation: Toward zero-click commerce</h2>



<p>One of the clearest near-term use cases for agentic commerce lies at the point of conversion: checkout. Traditional checkout flows are designed around static steps. But intelligent agents can collapse those steps entirely.</p>



<p>Imagine a system where the moment a customer expresses interest through an agent, the purchase is already 90% complete — size selected, payment method confirmed, shipping pre-filled. This is no longer speculative. We’re seeing early momentum through single-click checkout, stored wallet integrations and adaptive checkout pods that preempt customer needs — and the future is clearly pointing toward zero-click checkout, where agents can complete transactions entirely on the customer’s behalf.</p>



<p>In our own work, we’ve focused on streamlining mobile checkout as a foundation for this shift. From single-page flows to one-click experiences, each improvement reduces friction and sets the stage for agents to handle future transactions autonomously.</p>



<p>Just as agentic systems reinvent how customers find products, they also have the power to redefine how purchases are completed — quietly removing friction in the background while trust and relevance take center stage (read <a href="https://www.forrester.com/blogs/standing-out-in-a-zero-click-world-starts-with-stronger-collaboration/" target="_blank" rel="nofollow">Forrester’s take on thriving in a zero-click world</a>).</p>



<h2 class="wp-block-heading">The technology enablers: A layered stack for agentic commerce</h2>



<p>While agentic commerce is still emerging, this layered model reflects my perspective on how it can scale successfully. Powering agentic commerce at scale requires multiple interconnected layers working in harmony — each critical to enabling intelligent, adaptive and autonomous customer journeys. In this model, the website evolves into both an emotional interface for humans and an intelligence surface for machines. These capabilities align across three layers:</p>



<h3 class="wp-block-heading">Foundation</h3>



<ul class="wp-block-list">
<li><strong>Data orchestration:</strong> Unifies data from across channels-transactional, behavioral, contextual and third party-into real-time customer profiles that agents can act on instantly. </li>



<li><strong>Product catalog enrichment:</strong> Transforms product data into AI-friendly content using structured attributes, rich metadata and natural language. This ensures agents can match products with intent, power dynamic discovery and drive conversion in conversational or zero-UI environments.</li>
</ul>



<h3 class="wp-block-heading">Core logic </h3>



<ul class="wp-block-list">
<li><strong>Decisioning engines:</strong> Drive journey orchestration by using real-time context to select the next best action, message or recommendation for each customer moment (see <a href="https://sloanreview.mit.edu/article/the-great-power-shift-how-intelligent-choice-architectures-rewrite-decision-rights/" target="_blank" rel="nofollow">MIT Sloan on how ICAs rewrite decision rights</a>).</li>
</ul>



<h3 class="wp-block-heading">Experience layer </h3>



<ul class="wp-block-list">
<li><strong>Generative AI:</strong> Powers natural conversations, dynamic product storytelling and image generation-creating rich, human-like engagement across platforms (read <a href="https://www.mckinsey.com/industries/retail/our-insights/llm-to-roi-how-to-scale-gen-ai-in-retail?utm_source=chatgpt.com" target="_blank" rel="nofollow">McKinsey’s research on scaling generative AI in retail</a>). </li>



<li><strong>Composable architecture:</strong> Enables rapid innovation through modular, API-first systems-allowing seamless integration of agents into the digital experience. </li>
</ul>



<p>Not every enabler must be present on day one, but the combination of data readiness, modular systems and enriched content sets the foundation for success. Retailers who invest early in these areas will be better positioned to grow with the pace of agent ecosystem adoption. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?w=1024" alt="The agentic commerce enablement stack" class="wp-image-4035022" srcset="https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?quality=50&amp;strip=all 1175w, https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?resize=300%2C263&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?resize=768%2C675&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?resize=1024%2C899&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?resize=794%2C697&amp;quality=50&amp;strip=all 794w, https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?resize=191%2C168&amp;quality=50&amp;strip=all 191w, https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?resize=96%2C84&amp;quality=50&amp;strip=all 96w, https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?resize=547%2C480&amp;quality=50&amp;strip=all 547w, https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?resize=410%2C360&amp;quality=50&amp;strip=all 410w, https://b2b-contenthub.com/wp-content/uploads/2025/08/agentic-commerce-enablement-stack.png?resize=285%2C250&amp;quality=50&amp;strip=all 285w" width="1024" height="899" sizes="(max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kamanasish Kundu</p></div>



<h2 class="wp-block-heading">From signals to stakes: The case for agentic commerce now</h2>



<p>Agentic commerce is no longer hypothetical — leading companies are already making bold moves to operationalize it. Walmart recently announced four internal “super agents” and two EVP-level hires focused on enterprise AI adoption. OpenAI is testing hosted checkout inside ChatGPT, hinting at a future where conversational agents complete purchases directly. And PayPal’s CEO has forecast that 25% of e-commerce spend could be agent-driven by 2030. </p>



<p>The stakes are equally significant. According to Bernstein, agent-driven experiences could lift global e-commerce conversion by 1.5–2.5% annually, unlocking over $240 billion in incremental retail revenue.</p>



<h2 class="wp-block-heading">What this means for retail leaders</h2>



<p>Agentic commerce isn’t just a technology shift — it’s a structural, economic and competitive one. And early movers stand to lead it. It changes how teams think about product pages, search, merchandising and loyalty</p>



<p>Instead of optimizing funnels, brands must design systems that think with the customer. This means:</p>



<ul class="wp-block-list">
<li>Less focus on traditional segmentation, more on moment-based intent. </li>



<li>Less rigid site structure, more adaptive journeys. </li>



<li>Less push messaging, more collaborative dialogue. </li>
</ul>



<p>For CEOs and the C-suite, agentic commerce presents both a competitive advantage and a wake-up call. If intelligent agents become the first point of discovery, brands that are not indexed, accessible and API ready — risk becoming invisible. The shift demands executive alignment across marketing, product, technology and legal, building trust-based agent ecosystems that meet customers where they are going, not where they’ve been.</p>



<p>Leaders must also ask tough questions:</p>



<ul class="wp-block-list">
<li>What decisions are we willing to delegate to AI? </li>



<li>How do we build trust in autonomous systems? </li>



<li>Where does the brand voice end and the agents begin? </li>
</ul>



<h2 class="wp-block-heading">Looking ahead</h2>



<p>Agentic commerce isn’t a replacement for human connection. It’s a tool to enhance it. By reducing friction, surfacing better choices and respecting individual preferences, agentic systems can help retailers become more personal at scale (see <a href="https://www.bcg.com/publications/2025/how-ai-agents-opening-golden-era-customer-experience" target="_blank" rel="nofollow">BCG’s insight on how AI agents herald a “golden era” of customer experience</a>). </p>



<p>We’re just at the beginning. But in a world where traditional search is declining and intelligent agents are becoming the new discovery layer, agentic commerce isn’t just a future play: it may be how your next customer finds you.</p>



<p></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><strong><br></strong><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cut costs and complexity: 5 strategies for reducing tool sprawl with Dynatrace]]></title>
<description><![CDATA[Almost daily, teams have requests for new tools—for database management, CI/CD, security, and collaboration—to address specific needs. Increasingly, those tools involve AI capabilities to potentially boost productivity and automate routine tasks. But proliferating tools across different teams for...]]></description>
<link>https://tsecurity.de/de/2918601/it-security-nachrichten/cut-costs-and-complexity-5-strategies-for-reducing-tool-sprawl-with-dynatrace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2918601/it-security-nachrichten/cut-costs-and-complexity-5-strategies-for-reducing-tool-sprawl-with-dynatrace/</guid>
<pubDate>Sat, 02 Aug 2025 00:38:22 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Almost daily, teams have requests for new tools—for database management, CI/CD, security, and collaboration—to address specific needs. Increasingly, those tools involve AI capabilities to potentially boost productivity and automate routine tasks. But proliferating tools across different teams for different uses can also balloon costs, introduce operational inefficiency, increase complexity, and actually break collaboration. Moreover, tool sprawl can increase risks for reliability, security, and compliance.</p>



<p>As an executive, I am always seeking simplicity and efficiency to make sure the architecture of the business is as streamlined as possible. Here are five strategies executives can pursue to reduce tool sprawl, lower costs, and increase operational efficiency.</p>



<p>Key insights for executives:</p>



<ol start="1" class="wp-block-list">
<li>Increase operational efficiency with automation and AI to foster seamless collaboration: With AI and automated workflows, teams work from shared data, automate repetitive tasks, and accelerate resolution—focusing more on business outcomes.</li>



<li>Unify tools to eliminate redundancies, rein in costs, and ease compliance: This not only lowers the total cost of ownership but also simplifies regulatory audits and improves software quality and security.</li>



<li>Break data silos and add context for faster, more strategic decisions: Unifying metrics, logs, traces, and user behavior within a single platform enables real-time decisions rooted in full context, not guesswork.</li>



<li>Minimize security risks by reducing complexity with unified observability: Converging security with end-to-end observability gives security teams the deep, real-time context they need to strengthen security posture and accelerate detection and response in complex cloud environments.</li>



<li>Simplify data ingestion and up-level storage for better, faster querying: With Dynatrace, petabytes of data are always ”hot” for real-time insights, at a “cold” cost. No delays and overhead of reindexing and rehydration.</li>
</ol>



<h3 class="wp-block-heading"><strong>1. Increase operational efficiency to foster seamless collaboration</strong></h3>



<p>❌ Reinventing the wheel: One of the biggest challenges organizations face is connecting all the dots so teams can take swift action that’s meaningful to the business. Too many signals from point solutions and DIY tools spread across multiple teams hinder collaboration. Moreover, inconsistency in the tech stack and a lack of enterprise-ready integration and authentication approaches means teams must reinvent the wheel, forcing repeated builds and solving the same problems, instead of focusing on delivering business goals.</p>



<p>✅ Automate and collaborate on answers from data: By uniting data from across the organization in a single platform, teams can focus on making faster, high-quality decisions in a shared context. With AI they can trust, teams can understand the real-time context of digital services, enabling automation that can predict and prevent issues before they occur, such as service-level violations or third-party software vulnerabilities. The Dynatrace <a href="https://www.dynatrace.com/platform/automationengine/" target="_blank" rel="sponsored">AutomationEngine</a> orchestrates workflows across teams to implement automated remediations, while with <a href="https://www.dynatrace.com/platform/appengine/" target="_blank" rel="sponsored">AppEngine</a>, teams can tailor solutions to meet custom needs without creating silos.</p>



<h3 class="wp-block-heading"><strong>2. Unify tools to rein in costs and ease compliance</strong></h3>



<p>❌ High costs: Organizations often feel the pain of tool sprawl first in the pocketbook. Multiple tools increase the total cost of ownership through the sum of license fees, reduced negotiation power, and redundant maintenance and operations efforts. For example, organizations typically utilize <a href="https://www.ijsr.net/archive/v13i10/SR241011212840.pdf?utm_source=chatgpt.com" target="_blank" rel="sponsored">only 60% of their security tools</a>. Too many tools and DIY solutions also complicate regulatory compliance and make integrations harder, which reduces agility and drives up costs through wasted time.</p>



<p>✅ Business-focused, unified platform approach: A unified platform approach enables platform engineering and self-service portals, simplifying operations and reducing costs. The Dynatrace AI-powered unified platform has been recognized for its ability to not only streamline operations and reduce costs but also to provide better, faster data analysis. Standardizing platforms minimizes inconsistencies, eases regulatory compliance, and enhances software quality and security. Dynatrace integrates application performance monitoring (APM), infrastructure monitoring, and real-user monitoring (RUM) into a single platform, with its <a href="https://www.dynatrace.com/platform/infrastructure-observability/foundation-and-discovery/" target="_blank" rel="sponsored">Foundation &amp; Discovery</a> mode offering a cost-effective, unified view of the entire infrastructure, including non-critical applications previously monitored using legacy APM tools.</p>



<h3 class="wp-block-heading"><strong>3. Break data silos and add context for faster, more strategic decisions</strong></h3>



<p>❌ Data silos: When every team adopts their own toolset, organizations wind up with different query technologies, heterogeneous datatypes, and incongruous storage speeds. Last year <a href="https://www.dynatrace.com/news/blog/unified-observability-key-to-consolidating-tool-sprawl/" target="_blank" rel="sponsored">Dynatrace research</a> revealed that the average multi-cloud environment spans 12 different platforms and services, exacerbating the issue of data silos. Worsened by separate tools to track metrics, logs, traces, and user behavior—crucial, interconnected details are separated into different storage. It becomes practically impossible for teams to stitch them back together to get quick answers in context and make strategic decisions.</p>



<p>✅ All data in context: By bringing together metrics, logs, traces, user behavior, and security events into one platform, Dynatrace eliminates silos and delivers real-time, end-to-end visibility.</p>



<ul class="wp-block-list">
<li>The Smartscape® topology map automatically tracks every component and dependency, offering precise observability across the entire stack.</li>



<li>Davis®, the causal AI engine, instantly identifies root causes and predicts service degradation before it impacts users.</li>



<li>Generative AI enhances response speed and clarity, accelerating incident resolution and boosting team productivity.</li>



<li>Fully contextualized data enables faster, more strategic decisions, without jumping between tools or waiting on correlation across teams.</li>
</ul>



<p>This unified approach gives teams trustworthy, real-time answers, which is critical for navigating today’s complex digital ecosystem.</p>



<h3 class="wp-block-heading"><strong>4. Strengthen security with unified observability</strong></h3>



<p>❌ On average, organizations rely on <a href="https://www.dynatrace.com/news/blog/the-state-of-observability-in-2024/" target="_blank" rel="sponsored">10 different observability solutions</a> and nearly <a href="https://panaseer.com/resources/reports/2024-security-leaders-peer-report" target="_blank" rel="sponsored">100 different security tools</a> to manage their applications, infrastructure, and user experience. Traditional network-based security approaches are evolving. Enhanced security measures, such as encryption and zero-trust, are making it increasingly difficult to analyze security threats using network packets. This shift is forcing security teams to focus instead on the application layer. While network security remains relevant, the emphasis is now on application observability and threat detection. As a result, many organizations are facing the burden of managing separate systems for network security and application observability, leading to redundant configurations, duplicated data collection, and operational overhead.</p>



<p>✅ The convergence of security and observability tools is becoming essential, especially for cloud- and AI-native projects, as traditional network-based security approaches evolve. Platforms such as Dynatrace address these challenges by combining security and observability into a single platform. This integration eliminates the need for separate data collection, transfer, configuration, storage, and analytics, streamlining operations and reducing costs.</p>



<p>From a security risk mitigation perspective, integrating security and observability not only reduces overhead but also enhances security and risk management, providing organizations with better visibility into potential threats and breaches in today’s complex, encrypted environments. Such an approach is in line with my personal mantra and Dynatrace founding principle: reduce to the max.</p>



<h3 class="wp-block-heading"><strong>5. Simplify data ingestion and up-level storage for better, faster querying</strong></h3>



<p>❌ Complex data optimization: As organizations adopt more distributed services and AI-driven technologies, data is proliferating at steep rates. IT teams must now ingest petabytes of data and then store, process, and query it cost-effectively and securely. To save on storage and query costs, teams transition older data to cold storage, trimming out valuable details to save space. Re-indexing data and rehydrating it from cold storage for incident investigation and forensics causes query latency and additional management overhead and cost.</p>



<p>✅ Unified data ingest, storage, and querying: With Dynatrace <a href="https://www.dynatrace.com/platform/openpipeline/" rel="sponsored">OpenPipeline</a>, teams can ingest data from any source, in any format, and at any scale: think hundreds of terabytes per day and more. That volume and flexibility eliminate the need for extra data ingest tools and ease data normalization, filtering, and pre-processing, which makes data more reliable.</p>



<p>With the <a href="https://www.dynatrace.com/platform/grail/" target="_blank" rel="sponsored">Grail data lakehouse</a>, Dynatrace also reduces the need for countless tools to store, index, retrieve, and query data. Grail’s always-on hydration removes the burden of cold and hot storage management without incurring extra costs. Unique data warping technology allows for index-free, schema-on-read, high-performance queries, reducing storage costs further while giving teams the ability to query all data at any time. With this unrestricted availability, organizations can gain insights significantly faster by consolidating data storage and analytics models into a single, standardized approach. Executives can empower their teams to unlock the goldmine of value locked up in their data far more easily and cost-effectively.</p>



<h3 class="wp-block-heading"><strong>Integrating observability and security to reduce tool sprawl</strong></h3>



<p>Today’s need for optimization and efficiency pushes executives to see alternative setups and architectures, which often leads them to Dynatrace as a unified platform that can cover all these needs at once.</p>



<p>Here is a typical array of tools found in common IT environment architectures of Fortune 500 companies. Each category shows the limits of numerous tools and services an enterprise may use for their observability and security needs, and the benefits organizations have when these architectures are addressed with Dynatrace.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/blog2_toolsprawl.png?w=1024" alt="" class="wp-image-4033081" srcset="https://b2b-contenthub.com/wp-content/uploads/2025/08/blog2_toolsprawl.png?quality=50&amp;strip=all 1200w, https://b2b-contenthub.com/wp-content/uploads/2025/08/blog2_toolsprawl.png?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/08/blog2_toolsprawl.png?resize=768%2C428&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/08/blog2_toolsprawl.png?resize=1024%2C571&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/08/blog2_toolsprawl.png?resize=150%2C84&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2025/08/blog2_toolsprawl.png?resize=854%2C476&amp;quality=50&amp;strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2025/08/blog2_toolsprawl.png?resize=640%2C357&amp;quality=50&amp;strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2025/08/blog2_toolsprawl.png?resize=444%2C248&amp;quality=50&amp;strip=all 444w" width="1024" height="571" sizes="(max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Dynatrace</p></div>



<p>To meet the immediate needs of individual teams, organizations often find themselves bound up in a network of disparate tools and data silos that hamper productivity. Change takes time, and IT teams are under significant pressure already: many leaders hesitate to take on new challenges unnecessarily, and in many cases they are right. That’s why executives must lead the shift—because consolidation isn’t just about cost, it’s about unlocking better ways to work, collaborate, and create value.</p>



<p><strong>Want to learn more about all 9 use cases? Visit us <a href="https://www.dynatrace.com/company/dynatrace-for-executives/" target="_blank" rel="sponsored">here</a>.</strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[“When the Guardrails Erode” Series]]></title>
<description><![CDATA[Bringing together expert analysis that traces this erosion, assesses the risks for democratic governance, and outlines pathways to rebuild or even reinvent these safeguards.
The post “When the Guardrails Erode” Series appeared first on Just Security.]]></description>
<link>https://tsecurity.de/de/2902311/it-security-nachrichten/when-the-guardrails-erode-series/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2902311/it-security-nachrichten/when-the-guardrails-erode-series/</guid>
<pubDate>Wed, 23 Jul 2025 16:48:44 +0200</pubDate>
<content:encoded><![CDATA[<p>Bringing together expert analysis that traces this erosion, assesses the risks for democratic governance, and outlines pathways to rebuild or even reinvent these safeguards.</p>
<p>The post <a href="https://www.justsecurity.org/117692/when-the-guardrails-erode-series/">“When the Guardrails Erode” Series</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accenture reimagines IT operations with agentic AI]]></title>
<description><![CDATA[One of the challenges of IT operations at a global consulting firm like Accenture is it runs a huge and diverse portfolio of technologies to drive its digital core. Maintaining and operating that core requires continuously developing deep skillsets that are becoming rarer as every industry compet...]]></description>
<link>https://tsecurity.de/de/2894396/it-security-nachrichten/accenture-reimagines-it-operations-with-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2894396/it-security-nachrichten/accenture-reimagines-it-operations-with-agentic-ai/</guid>
<pubDate>Fri, 18 Jul 2025 12:19:08 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>One of the challenges of IT operations at a global consulting firm like Accenture is it runs a huge and diverse portfolio of technologies to drive its digital core. Maintaining and operating that core requires continuously developing deep skillsets that are becoming rarer as every industry competes within a limited talent pool.</p>



<p>Accenture’s answer is the Accenture Advanced Technology Agent (AATA), an agentic AI-powered integration platform that sits between the company’s human workforce and its technology platforms, and something that’s earned the company a <a href="https://event.foundryco.com/cio100-symposium-and-awards/" rel="nofollow">2025 CIO 100 Award in IT Excellence</a>.</p>



<p>“IT operations largely run through automation, either RPA, scripts, or CICD pipelines,” says Steven Courtney,  Accenture’s MD of global IT, technology vision, and strategy. “Wouldn’t it be great if we could add an orchestration layer above that, as an aggregation of AI agents, that we could apply to all our IT operations, one-by-one, as agents become available.”</p>



<h2 class="wp-block-heading">Core means to efficiency</h2>



<p>Like many large enterprises, Accenture has a highly complex digital core that contains a variety of IT solutions ranging from office architectures and multi-cloud, to data fabric and security platforms. The digital core is essential to run the business and enable quick onboarding of emerging technology, but the complex service chains and multiple technology stacks require a significant amount of human support. That, in turn, has made the rapid adoption of new technology difficult to integrate throughout the business.</p>



<p>To smooth that process, AATA is an agnostic, open system with agentic architecture that enables IT teams and end users to interact with the core to resolve issues or deliver customer solutions without having to connect to an agent or file a single ticket.</p>



<p>Accenture started working on AATA in 2023, starting with a conceptual architectural model. “Then we started to think about how people would consume the technology to derive value, so we wanted it to be largely democratized,” Courtney says. “You could have an open standards orchestration layer and a consistent prompt layer, but then enable teams to be able to either consume natively available agents, plug in existing automation or gen AI processes, or actually create custom agents if that was what required.”</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?quality=50&amp;strip=all 1800w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=300%2C200&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=768%2C512&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=1024%2C683&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=1536%2C1024&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=1240%2C826&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=150%2C100&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=1046%2C697&amp;quality=50&amp;strip=all 1046w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=252%2C168&amp;quality=50&amp;strip=all 252w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=126%2C84&amp;quality=50&amp;strip=all 126w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=720%2C480&amp;quality=50&amp;strip=all 720w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=540%2C360&amp;quality=50&amp;strip=all 540w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Steven-Courtney-MD-of-global-IT-technology-vision-and-strategy-Accenture.jpg?resize=375%2C250&amp;quality=50&amp;strip=all 375w" width="1240" height="827" sizes="(max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Steven Courtney, MD of global IT, technology vision, and strategy, Accenture</p>
</figcaption></figure><p class="imageCredit">Accenture</p></div>



<p>Some specific focus areas for AATA included variations in AI maturity. Recognizing not every organization will be in the same place when it comes to AI, Accenture built AATA to have open architecture with the flexibility to swap models in and out, allowing it to stay model agnostic and keep pace with the market.</p>



<p>There was also the importance of data availability and accuracy. AATA had to not only crawl Accenture’s internal content resources and repositories, but execute tasks based on the information in the firm’s living systems. That required secure access to the right data. Accenture’s global IT had already built a platform to bring all the company’s enterprise data together into a fabric, so AATA was able to capitalize on that work with common log lakes of critical data needed for operational decisions.</p>



<p>AATA also supports audio prompts and text chat embedded in Accenture’s collaboration tools, with a cloud-based workflow automation platform sitting behind the user interface. That platform acts as an orchestrator across various technologies and copilot solutions to collect data, create code, execute pipelines, or provide status based on the operational needs of the user.</p>



<h2 class="wp-block-heading">Striving for continuous improvement</h2>



<p>Building AATA wasn’t without problem solving. Upskilling was one focus area because consuming gen AI requires Accenture’s teams to behave and operate differently. But Courtney notes that the culture of continuous innovation at the firm meant that upskilling was part of the regular cycle of technology operations. Another area of concern was data.</p>



<p>“One of the biggest challenges we found in terms of making this happen on the ground was data and data accuracy,” Courtney says. “It’s nothing new, but it’s the fuel behind all the issues you find with gen AI and agentic architectures.”</p>



<p>He notes the framework calls on enormous amounts of telemetry.</p>



<p>“Every piece of telemetry that’s delivered from all of our infrastructure platforms, and some of our software platforms, we had to be comfortable that it was good, accurate, compliant, and that we were using it in a responsible and secure way,” Courtney adds.</p>



<p>The trick, adds Rajendra Prasad, Accenture’s chief information and asset engineering officer, is to not implement technology for technology’s sake.</p>


<div class="extendedBlock-wrapper block-coreImage left"><figure class="wp-block-image alignleft size-1240-r3:2 is-resized"> srcset="https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?quality=50&amp;strip=all 1800w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=300%2C200&amp;quality=50&amp;strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=768%2C512&amp;quality=50&amp;strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=1024%2C683&amp;quality=50&amp;strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=1536%2C1024&amp;quality=50&amp;strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=1240%2C826&amp;quality=50&amp;strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=150%2C100&amp;quality=50&amp;strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=1046%2C697&amp;quality=50&amp;strip=all 1046w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=252%2C168&amp;quality=50&amp;strip=all 252w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=126%2C84&amp;quality=50&amp;strip=all 126w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=720%2C480&amp;quality=50&amp;strip=all 720w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=540%2C360&amp;quality=50&amp;strip=all 540w, https://b2b-contenthub.com/wp-content/uploads/2025/07/Rajendra-Prasad-CIO-and-asset-engineering-officer-Accenture.jpg?resize=375%2C250&amp;quality=50&amp;strip=all 375w" width="1240" height="827" sizes="(max-width: 1240px) 100vw, 1240px"&gt;<figcaption class="wp-element-caption"><p>Rajendra Prasad, CIO and asset engineering officer, Accenture</p>
</figcaption></figure><p class="imageCredit">Accenture</p></div>



<p>“You need to get your business processes reinvented before you infuse technology,” he says. “If you have a very inefficient business process, adding very high-powered agentic tech to that inefficient process just makes your inefficiency run more efficiently.”</p>



<p>Prasad also says that CIOs should use agentic AI as an innovative lens to reinvent and redefine processes.</p>



<h2 class="wp-block-heading">Getting accustomed to the pace</h2>



<p>Today, AATA has more than 100 active agents, and some results include being able to facilitate the configuration of VPN connections with much greater speed and accuracy. Configuring these connections used to require a highly skilled engineer 30 minutes, but AATA can now do it in two minutes, which is more than a 93% reduction with a lower risk of error. The platform also assists Accenture’s roughly 800,000 employees around the world with troubleshooting. Users can chat with AATA and receive a near-immediate response, facilitating auto-remediation of issues to close tickets faster. And cloud engineers also use AATA as an embedded partner.</p>



<p>“Adoption has been fantastic,” Courtney says. “We’re seeing about an 80% increase in terms of speed to provision and change, and the rate of agent growth about 15% week-on-week at the moment. We’re also finding that as people become more used to building an agent rather than using legacy techniques, things just accelerate.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agent orchestration: The CIO’s crucial next step]]></title>
<description><![CDATA[In the near agentic AI future, enterprises will run dozens if not hundreds of AI agents, with CIOs in charge of orchestrating and connecting them to help employees navigate a range of interconnected business processes.



Take onboarding a new employee. In the not distant future, an HR rep might ...]]></description>
<link>https://tsecurity.de/de/2887162/it-security-nachrichten/ai-agent-orchestration-the-cios-crucial-next-step/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2887162/it-security-nachrichten/ai-agent-orchestration-the-cios-crucial-next-step/</guid>
<pubDate>Tue, 15 Jul 2025 12:18:49 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In the near agentic AI future, enterprises will run dozens if not hundreds of AI agents, with CIOs in charge of orchestrating and connecting them to help employees navigate a range of interconnected business processes.</p>



<p>Take onboarding a new employee. In the not distant future, an HR rep might ask a chatbot to set up the new employee. By coordinating several agents, the chatbot would in turn enter the employee into the payroll system, walk her through health insurance options, and set up her email and videoconferencing services. Further agent coordination could also deliver the new employee training, issue a building entry badge, and even ship her a laptop or assign her a desk, all with minimal human input.</p>



<p>This vision of AI orchestration and integration is already being rolled out by some companies, and as organizations deploy multiple large language models (LLMs) and dozens of AI agents in the coming years, mass adoption of AI integration and orchestration tools is likely.</p>



<p>By 2028, 70% of organizations building multi-LLM applications and <a href="https://www.cio.com/article/3603856/agentic-ai-promising-use-cases-for-business.html">AI agents</a> will use integration platforms to optimize and orchestrate connectivity and data access, Gartner predicted in <a href="https://www.gartner.com/en/documents/6580502" rel="nofollow">a recent report</a>. Less than 5% of similar organizations were using AI integration platforms in 2024.</p>



<p>Some AI experts see that orchestration function, where many AI agents are tied together to create wide-ranging and autonomous workflows, as the point when <a href="https://www.cio.com/article/4003880/how-ai-agents-and-agentic-ai-differ-from-each-other.html">agents become agentic</a>.</p>



<h2 class="wp-block-heading">Connecting data and decision-makers</h2>



<p>AI integration and orchestration tools will be vital for most enterprises because <a href="https://www.cio.com/article/3496519/agentic-ai-decisive-operational-ai-arrives-in-business.html">AI agents</a> and LLMs need to be connected to fully reach their potential, says <a href="https://www.gartner.com/en/experts/andrew-humphreys" rel="nofollow">Andrew Humphreys</a>, a senior director and analyst at Gartner. Recent releases of <a href="https://www.cio.com/article/3991302/ai-protocols-set-standards-for-scalable-results.html">several agent protocols</a> take the first step toward this widespread integration, he notes.</p>



<p>“AI has to have access to data in order to make decisions, and it has to have the ability to actually take some kind of action,” he says. “An agent is useless if it can’t have access to data, and it can’t make a decision.”</p>



<p>Agent integration and orchestration will help CIOs address several emerging questions about the coming agentic AI world, he adds. “How do I make it easier for my AI developer or my agent to be able to connect to things and get data?” Humphreys says. “How can I observe what’s actually happening within my IT architecture?”</p>



<p>As CIOs’ AI strategies become more complex, the need for agent orchestration platforms becomes readily apparent, adds <a href="https://www.linkedin.com/in/beth-scagnoli/" rel="nofollow">Beth Scagnoli</a>, vice president of product management at data readiness solution provider Redpoint Global.</p>



<p>“Most organizations today aren’t just experimenting with a single AI model; they’re working across multiple LLMs, legacy systems, and newer AI agents simultaneously,” she says. “Without orchestration, that ecosystem risks quickly becoming fragmented, redundant, and inefficient.”</p>



<p>The orchestration layer will manage how AI tools access, move, and act on data across systems, she adds. “This is not just for outputs, but also for maintaining enterprise standards around governance and trust,” Scagnoli says. “AI orchestration is quickly becoming the critical link between data strategy and AI execution.”</p>



<h2 class="wp-block-heading">A market emerges</h2>



<p>CIOs adding orchestration tools should look for interoperability, Scagnoli says.</p>



<p>“Orchestration layers that are flexible and AI-agnostic will be where the true value shines,” she says. “Tools that can sit above any LLM or agent, allowing for organizations to plug in the right model for the job all while managing security, versioning, and data lineage behind the scenes,” will be IT leaders’ best bet.</p>



<p>Gartner’s Humphreys sees a burgeoning marketplace for AI integration and orchestration platforms, with many small players currently offering out-of-the-box solutions. As the market becomes more profitable, larger IT and AI players will get into the game.</p>



<p>Some companies will also build orchestration tools themselves, Humphreys says, but he urges IT leaders to take the lessons learned from past integration efforts, including orchestration of API calls.</p>



<p>“You’ve probably already put together your existing API integrations,” he says. “Tweak that rather than thinking that you’ve got to completely reinvent the whole bit. Just adjust that to meet the way that your AI needs to talk to it, rather than thinking, ‘Oh, it’s AI, I’d better rewrite everything I’ve learned in the past.’”</p>



<h2 class="wp-block-heading">Experimenting with orchestration</h2>



<p>IBM is one company that’s taking on agent integration in house. The tech giant began experimenting with agent-like tools eight years ago, and it now has agents deployed in several workflows, including IBM’s sales and <a href="https://www.cio.com/article/4018133/its-time-to-retire-the-ticket-an-it-roadmap-for-agentic-ai.html">IT departments</a>, says <a href="https://www.linkedin.com/in/solivingston/" rel="nofollow">Suzanne Livingston</a>, vice president at IBM watsonx Orchestrate Agent Domains. HR was the early test case, and now, agents operate many HR functions.</p>



<p>“There are a lot of processes in HR, and it’s difficult for employees to understand how to work with the HR system,” she says. “We use one [app] at the time, and if you’ve ever used one of these enterprise HR systems, you had to find the instructions to know exactly what you wanted to do. And, by the way, those instructions changed every month.”</p>



<p>Now, IBM employees can interact with an AI agent to create salary increase requests, transfer employees between departments, create job descriptions, and accomplish a range of other HR functions, she says. An AI orchestration layer is needed to interact with the agents operating all those individual HR tools to accomplish multistep workflows, such as employee onboarding, she notes.</p>



<p>Still, for most companies, a vendor-supported out-of-the-box tool may be an easier way to get started, Livingston says.</p>



<p>“It’s a great way to not have to start by building something from scratch,” she says. “It’s a great way to trial it out and get a feel for it, and then, it may lead you to bigger projects as a result, but it is useful on its own.”</p>



<p>She also suggests that CIOs look for <a href="https://www.cio.com/article/3829620/how-to-know-a-business-process-is-ripe-for-agentic-ai.html">low-hanging fruit where there are a lot of employee pain points</a>, for example, time-off requests. “Everyone has to submit time off, and no, no one wants to do it because it is clunky,” she says. “But it’s an easy one to get started with, and you get immediate value.”</p>



<p>The future will be agents everywhere, Livingston adds.</p>



<p>“It’s like a never-ending realm of underlying agents,” she says. “As companies evolve and bring on board new processes, or reduce complexity of processes, it’s its own positive loop of an experience.</p>



<p>“It’s getting companies to adopt that mindset, ‘I don’t have to train my employees on 500 different systems, I can help them understand how to utilize the benefit of these systems through an agent.’”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I 10 ostacoli più impegnativi che l’IT di oggi si trova ad affrontare]]></title>
<description><![CDATA[I Chief Information Officer devono affrontare una lunga serie di ostacoli, la cui crescente diversità è degna di nota.



Permangono preoccupazioni di lunga data, come la sicurezza dell’azienda e il contenimento dei costi. Tuttavia, l’intelligenza artificiale e l’attuale clima economico stanno ri...]]></description>
<link>https://tsecurity.de/de/2877656/it-security-nachrichten/i-10-ostacoli-pi-impegnativi-che-lit-di-oggi-si-trova-ad-affrontare/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2877656/it-security-nachrichten/i-10-ostacoli-pi-impegnativi-che-lit-di-oggi-si-trova-ad-affrontare/</guid>
<pubDate>Thu, 10 Jul 2025 07:04:10 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I Chief Information Officer devono affrontare una lunga serie di ostacoli, la cui crescente diversità è degna di nota.</p>



<p>Permangono preoccupazioni di lunga data, come la sicurezza dell’azienda e il contenimento dei costi. Tuttavia, l’intelligenza artificiale e l’attuale clima economico stanno rivoluzionando il business as usual, aggiungendo complessità e sfumature sempre maggiori ai compiti dei CIO.</p>



<p>Quindi, quali sono esattamente le principali preoccupazioni dei CIO in questo momento? Abbiamo chiesto ai leader IT di individuare le grandi difficoltà che devono affrontare oggi.</p>



<h2 class="wp-block-heading">1. La rapida evoluzione dell’AI</h2>



<p>La maggior parte dei dirigenti che si occupano di IT implementa l’intelligenza artificiale nelle proprie aziende da molti anni, ma sta assistendo a un’evoluzione sempre più rapida di questa tecnologia, che rende lo stare al passo con i progressi dell’AI una delle principali priorità.</p>



<p>“L’esplosione dell’intelligenza artificiale e la rapidità con cui si è diffusa sono la mia principale preoccupazione”, racconta Mark Sherwood, vice president esecutivo e CIO di Wolters Kluwer, un’azienda globale di software e servizi professionali. “Nella mia esperienza, l’AI è cambiata e progredita più rapidamente di qualsiasi altra cosa io abbia mai visto”.</p>



<p>Per stare al passo con questa rapida evoluzione, secondo Sherwood, occorre concentrarsi sull’integrazione dell’innovazione nel lavoro quotidiano del suo team di ingegneri. “Desidero che i nostri esperti innovino, ma non è qualcosa che si può programmare; l’innovazione arriva quando arriva, quindi trovare modi per consentire al team di progredire nell’evoluzione tecnologica è stato un obiettivo importante”, aggiunge.</p>



<p>Il manager si concentra anche sul <a href="https://www.cio.com/article/3836084/it-leaders-brace-for-the-ai-agent-management-challenge.html"><strong>change management [in inglese]</strong></a>. “Desideriamo che le persone acquisiscano sempre maggiore familiarità con l’intelligenza artificiale”, afferma. “Quindi ora quello che diciamo è: non chiedete ‘Dove possiamo utilizzare l’AI?’, ma ‘Perché non la stiamo utilizzando in quel caso?’”.</p>



<h2 class="wp-block-heading">2. L’AI per l’IT</h2>



<p>I CIO stanno chiedendo a se stessi e ai propri team IT di identificare dove è possibile <a href="https://www.cio.com/article/2139989/10-ways-ai-can-make-it-more-productive.html"><strong>utilizzare l’AI per migliorare la produttività IT [in inglese]</strong></a>.</p>



<p>Jamie Smith, CIO dell’Università di Phoenix, si sta occupando da tempo di questa questione e ha trovato molte risposte. “L’intelligenza artificiale sta ridefinendo l’organizzazione tecnologica”, dice.</p>



<p>Come esempio, cita i cambiamenti nel modo in cui il suo reparto tecnologico crea il software. In questo reparto, molti dei suoi circa 40 team di prodotto sono passati da sette-nove membri a soli tre, poiché hanno adottato l’AI per svolgere una parte maggiore del lavoro. Inoltre, ciascuno dei membri di questi team abilitati si occupa di una gamma più ampia di attività, invece di specializzarsi.</p>



<p>Smith sostiene che i lavoratori IT necessitino di competenze e di caratteristiche specifiche per utilizzare con successo l’intelligenza artificiale. Devono essere a proprio agio e saper agire rapidamente. Devono possedere competenze tecniche ampie, non solo altamente specializzate. E, naturalmente, hanno bisogno di skill specifiche in materia.</p>



<h2 class="wp-block-heading">3. Attacchi informatici basati sull’AI</h2>



<p>L’aumento degli<strong> </strong><a href="https://www.csoonline.com/article/564321/6-ways-hackers-will-use-machine-learning-to-launch-attacks.html"><strong>attacchi informatici basati sull’intelligenza artificiale [in inglese]</strong></a> è un’altra questione prioritaria per i CIO.</p>



<p>“La sicurezza informatica è sempre un problema. Ogni anno ho paura per motivi diversi. Quest’anno è l’aumento della sofisticazione del phishing, dei deepfake e di altri attacchi che utilizzano l’AI”, puntualizza Smith.</p>



<p>Come esempio, il manager cita gli hacker che utilizzano l’intelligenza artificiale per creare siti web realistici che imitano i fornitori per inviare fatture alla contabilità. Sottolinea anche l’utilizzo dell’intelligenza artificiale da parte degli hacker per estrarre i profili online dei dirigenti e <a href="https://www.csoonline.com/article/3982379/deepfake-attacks-are-inevitable-cisos-cant-prepare-soon-enough.html"><strong>creare deepfake [in inglese]</strong></a> che li impersonano per scopi illeciti.</p>



<p>“L’elemento emergente è lo sfruttamento dell’AI per sofisticati attacchi di ingegneria sociale e il loro utilizzo per colpire l’anello più debole della sicurezza, ovvero le persone”, sottolinea.</p>



<h2 class="wp-block-heading">4. Sfruttare al massimo l’AIOps e l’event intelligence</h2>



<p>Anche Mike Trkay, CIO di FICO, una società di analisi dei dati, considera l’intelligenza artificiale per l’IT una questione prioritaria. Tuttavia, cita specificamente <a href="https://www.cio.com/article/196239/what-is-aiops-injecting-intelligence-into-it-operations.html"><strong>l’AIOps [in inglese]</strong></a> e l’event intelligence.</p>



<p>“Le moderne piattaforme digitali generano volumi impressionanti di telemetria, log e metriche in un’architettura sempre più complessa e distribuita. Senza sistemi intelligenti, i team IT sono sommersi da allarmi o perdono segnali critici nel rumore di fondo”, spiega. “Quella che una volta era una sfida gestibile basata su regole di monitoraggio si è evoluta in un problema di big data e machine learning”.</p>



<p>Continua dicendo: “Questo cambiamento richiede alle organizzazioni IT di ripensare il modo in cui acquisiscono, gestiscono e agiscono sui dati operativi. Non si tratta solo di osservabilità, ma anche di interpretabilità e attuabilità su larga scala. Nell’era delle infrastrutture basate sull’AI, i sistemi devono andare oltre gli avvisi di soglia per arrivare a informazioni contestualizzate e rimedi intelligenti. Ciò ha un impatto diretto sull’uptime, sulla velocità di risposta agli incidenti e sulla customer experience”.</p>



<p>Trkay racconta che FICO sta applicando modelli di intelligenza artificiale per il rilevamento delle anomalie, la definizione dinamica delle soglie, la correlazione degli eventi e l’identificazione delle cause probabili. Inoltre, sta integrando il triage e l’automazione assistiti dall’AI per aumentare la velocità operativa e ridurre il lavoro.</p>



<h2 class="wp-block-heading">5. Ottenere valore, e ottenerlo rapidamente</h2>



<p>Mentre valutano dove e come utilizzare l’AI e altre tecnologie, i Chief Information Officer sono anche alla ricerca di iniziative che apportino valore alle loro aziende, rileva Thomas Squeo, CTO presso la società di consulenza tecnologica Thoughtworks Americas, che collabora con i CIO per affrontare le loro principali problematiche e priorità IT.</p>



<p>“La maggior parte delle conversazioni che ho con questa tipologia di manager verte su come ridurre il time-to-value”, confida.</p>



<p>Anche altri lo notano.</p>



<p>Info-Tech Research Group tiene a precisare che <a href="https://www.infotech.com/research/ss/cio-priorities-2025" rel="nofollow"><strong>la creazione di “team di prodotto esponenziali per realizzare il valore dell’AI” è una delle cinque priorità principali per i CIO nel 2025 [in inglese]</strong></a>. “Sfruttare le possibilità offerte dall’intelligenza artificiale richiede una risposta esponenziale”, si legge nel rapporto Info-Tech. “È responsabilità del Chief Information Officer abbattere i silos tra l’IT e il resto dell’azienda per cogliere questa opportunità”.</p>



<p><a href="https://www.cio.com/article/228199/Logicalis%20CIO%20Report%202025%20%7C%20Logicalis%20%7C%20Download%20your%20copy"><strong>Il rapporto 2025 Global CIO Report di Logicalis [in inglese]</strong></a>, un fornitore di infrastrutture e servizi tecnologici con sede nel Regno Unito, sottolinea che “i leader tecnologici devono bilanciare l’innovazione con la creazione di valore reale” e che “il 95% delle organizzazioni sta investendo in tecnologia per creare flussi di entrate completamente nuovi”.</p>



<p>Tuttavia, il rapporto ha evidenziato il fatto che “un gran numero di essi riconosce che gli investimenti in tecnologie di nuova generazione non hanno ancora prodotto i rendimenti previsti. Questo divario tra investimenti e valore realizzato ha intensificato la pressione sui CIO”.</p>



<h2 class="wp-block-heading">6. Geopolitica</h2>



<p>I Chief Information Officer oggi prestano anche maggiore attenzione alle notizie geopolitiche e cercano di determinare quali potrebbero essere le conseguenze di ciò che accade nel mondo per loro, per i loro reparti IT e per le loro aziende.</p>



<p>“Questi sono tempi di grande incertezza e i CIO si chiedono come influenzeranno i portafogli, i budget e le iniziative IT”, commenta Squeo.</p>



<p>Per esempio, alcuni leader tech stanno rimpatriando i team all’estero, fa notare. Altri stanno facendo lavorare le loro squadre solo su iniziative a sostegno del lavoro dell’azienda negli stessi Paesi in cui si trovano i lavoratori, aggiunge.</p>



<p>Anche Sherwood di Wolters Kluwer ha avvertito l’impatto del clima geopolitico, per esempio <a href="https://www.cio.com/article/3965384/global-tariffs-shake-up-cios-it-agendas.html"><strong>in tema di dazi [in inglese]</strong></a>.</p>



<p>“Non siamo un’azienda manifatturiera, quindi non siamo colpiti come altri, ma resta comunque un problema”, riflette, sottolineando che l’aumento del costo delle attrezzature tecnologiche per la sua azienda a seguito dei dazi potrebbe essere notevole.</p>



<p>Dichiara, inoltre, che lui e i suoi colleghi dirigenti hanno resistito alla tentazione di adottare misure reazionarie e stanno invece seguendo un “approccio attendista su molte delle notizie”. Tuttavia, sta già valutando quali fornitori potrebbero essere nella posizione migliore per aiutare ad attenuare l’impatto delle guerre commerciali e dei dazi, qualora fosse necessario.</p>



<h2 class="wp-block-heading">7. I costi e come contenerli</h2>



<p>I costi sono una questione ricorrente per i CIO, ma quest’anno hanno assunto un’importanza ancora maggiore a causa dei <a href="https://www.cio.com/article/3810955/sharply-rising-it-costs-have-cios-threading-the-needle-on-innovation.html"><strong>significativi aumenti dei beni e dei servizi [in inglese]</strong></a> che si sono verificati a causa dell’inflazione e del contesto geopolitico.</p>



<p>“Il contenimento e il controllo delle spese continuano a essere questioni importanti, poiché stiamo assistendo a aumenti massicci di alcuni costi tecnologici, come le licenze. Alcuni CIO stanno registrando aumenti multipli nei casi di rinnovo e hanno poche alternative se non quella di pagare”, dichiara Dave Borowski, senior partner e responsabile dell’ufficio di Washington della società di servizi digitali West Monroe.</p>



<p>Anche Trkay di FICO indica la gestione delle spese come una delle questioni principali, sebbene citi i <a href="https://www.cio.com/article/657832/cios-sharpen-cloud-cost-strategies-just-as-gen-ai-spikes-loom.html"><strong>costi relativi all’intelligenza artificiale e al cloud [in inglese]</strong></a> come fattori primari.</p>



<p>“La rapida adozione della GenAI ha portato a un aumento delle spese per il cloud, spesso imprevedibili, in particolare a causa dei carichi di lavoro intensivi per le GPU e dei progetti pilota frammentati”, dice, aggiungendo che i CIO devono trovare un equilibrio tra innovazione e responsabilità fiscale.</p>



<p> “Ciò implica non solo l’adozione di soluzioni di intelligenza artificiale all’avanguardia, ma anche la garanzia che queste iniziative siano convenienti e in linea con gli obiettivi aziendali. I reparti IT devono implementare solidi framework di governance per valutare il ritorno sull’investimento (ROI) dei progetti di AI e prevenire lo spreco di risorse”.</p>



<p>Per farlo, Trkay sostieneche FICO sta adottando un approccio più disciplinato agli investimenti nell’AI, dando priorità ai casi d’uso ad alto valore e concentrandosi su <a href="https://www.cio.com/article/3629824/gen-ai-in-2025-playtime-is-over-time-to-get-practical.html"><strong>progetti con vantaggi chiari e misurabili [in inglese]</strong></a>; implementando <a href="https://www.cio.com/article/189652/top-13-cloud-cost-management-tools.html"><strong>strumenti di ottimizzazione dei costi [in inglese]</strong></a> e applicando l’intelligenza artificiale per ottimizzare se stessa; migliorando l’infrastruttura e <a href="https://www.cio.com/article/3567171/cios-recalibrate-multicloud-strategies-as-challenges-remain.html"><strong>sfruttando strategie multicloud [in inglese]</strong></a> per selezionare le generazioni di GPU e i tipi di istanze appropriati in base ai requisiti prestazionali.</p>



<p>“Questo passaggio da una sperimentazione su larga scala a iniziative di intelligenza artificiale mirate e orientate al ROI rappresenta una maturazione nel modo in cui le imprese approcciano l’AI, bilanciando l’innovazione con pratiche finanziarie sostenibili e le prestazioni con la responsabilità”, aggiunge.</p>



<h2 class="wp-block-heading">8. Talento</h2>



<p>“Il talento è stato un problema importante per anni e continua ad esserlo”, racconta Borowski di West Monroe, spiegando che i CIO sono concentrati sulla disponibilità e sulla concorrenza per i talenti IT, entrambi aspetti che rimangono critici.</p>



<p>Sono inoltre concentrati sulla determinazione delle competenze di cui avranno bisogno nel prossimo anno o nei prossimi due anni, che ora più che mai rappresentano un obiettivo in continua evoluzione.</p>



<p>Secondo il <a href="https://www.revature.com/revatures-2025-state-of-it-skills-survey-report" rel="nofollow"><strong>sondaggio 2025 State of IT Skills Survey [in inglese]</strong></a> condotto dal fornitore di talenti tecnologici Revature, il 77% delle aziende intervistate ha dichiarato di essere stato colpito dal divario di competenze IT, e l’84% dei responsabili delle decisioni era preoccupato di trovare risorse IT nel 2025. Inoltre, gli intervistati hanno dichiarato di essere maggiormente preoccupati per la ricerca di figure qualificate con le competenze necessarie (71%), per ottenere più rapidamente talenti dalle società di reclutamento di personale IT (57%) e per <a href="https://www.cio.com/article/3998201/cios-get-serious-about-closing-the-skills-gap-mainly-from-within.html"><strong>l’upskilling/reskilling di risorse interne (53%) [in inglese]</strong></a>.</p>



<h2 class="wp-block-heading">9. Sicurezza, compresi i rischi legati a terzi</h2>



<p><a href="https://www.cio.com/article/3976500/state-of-the-cio-survey-2025.html"><strong>Il sondaggio “2025 State of the CIO” di CIO.com [in inglese]</strong></a> ha indicato le iniziative tecnologiche relative alla sicurezza e alla gestione dei rischi come una delle principali aree di spesa IT, al secondo posto nell’elenco delle principali iniziative tecnologiche pianificate dagli intervistati per l’anno in corso. (L’apprendimento automatico/l’intelligenza artificiale era al primo posto).</p>



<p>Secondo Sherwood, questa spesa è giustificata.</p>



<p>“I malintenzionati continuano a diventare più intelligenti e a disporre di maggiori risorse finanziarie, e stanno sfruttando l’AI più di chiunque altro”, afferma. “È questo che ci tiene svegli la notte”.</p>



<p>Sherwood fa leva su questa vigilanza, sostenendo: “Voglio che siamo sempre preoccupati, perché la fiducia crea un falso senso di sicurezza”. Allo stesso tempo, riconosce che i CIO non possono essere sicuri al 100%. Pertanto, si affida al registro dei rischi della sua aziende per prendere decisioni strategiche, rivedendolo mensilmente e adeguandolo alle circostanze.</p>



<p>Diane Carco, ex CIO e ora presidente della società di consulenza gestionale Swingtide, fa notare che negli ultimi anni il <a href="https://www.csoonline.com/article/1305977/6-best-practices-for-third-party-risk-management.html"><strong>rischio legato a terzi [in inglese]</strong></a> è diventato una preoccupazione molto più significativa per i leader IT.</p>



<p>“Quasi tutti i rischi per la sicurezza provengono ora da terze parti e sempre più organizzazioni tecnologiche devono rafforzare la gestione dei rischi di questo tipo”, aggiunge.</p>



<h2 class="wp-block-heading">10. Prepararsi al futuro</h2>



<p>I progressi nell’intelligenza artificiale, nel quantum computing e in altre tecnologie, insieme alle continue trasformazioni dirompenti dell’era attuale e alla natura imprevedibile del mondo, spingono i dirigenti più esperti, compresi i CIO, a rendere le loro imprese a prova di futuro.</p>



<p>“Mi chiedo sempre: ‘Stiamo continuando ad adattarci ai cambiamenti?’, fa notare Sherwood. ”Se penso a quanto tempo dedicavo a riflettere sul futuro 10 anni fa, era molto meno. Allora i cambiamenti erano più lenti. Ora è un processo mentale quotidiano o almeno settimanale, mi chiedo se stiamo costruendo un’azienda in grado di prosperare con tutti questi cambiamenti”.</p>



<p>Per esempio, ora desidera avere nel suo team più “atleti multisport” che specialisti puri, per assicurarsi di avere collaboratori disposti e in grado di evolversi al mutare del lavoro. Inoltre, cerca <a href="https://www.cio.com/article/2144181/provider-or-partner-it-leaders-rethink-vendor-relationships-for-value.html"><strong>aziende tecnologiche che possano lavorare come partner [in inglese]</strong></a>, ampliando gli ecosistemi che apportano ai loro accordi per aiutarlo a prepararsi al futuro.</p>



<p>Anche i CIO leader stanno evolvendo, poiché il loro ruolo continua a trasformarsi in quello di <a href="https://www.cio.com/article/2088578/state-of-the-cio-2024-change-makers-in-the-business-spotlight.html"><strong>agenti del cambiamento e partner strategici [in inglese]</strong></a>, conclude Borowski di West Monroe. I CIO devono possedere le capacità di leadership necessarie per guidare l’innovazione e sviluppare strategie man mano che il loro ruolo evolve, se anche loro vogliono essere pronti per il futuro.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Reinventing the Python wheel]]></title>
<description><![CDATA[It is no secret that the Python packaging world is at something of a
crossroads; there have been debates and discussions about the packaging
landscape that started long before our 2023
series describing some of the difficulties.  There has been progress
since then—and incremental improvements all...]]></description>
<link>https://tsecurity.de/de/2876538/linux-tipps/reinventing-the-python-wheel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2876538/linux-tipps/reinventing-the-python-wheel/</guid>
<pubDate>Wed, 09 Jul 2025 16:08:16 +0200</pubDate>
<content:encoded><![CDATA[It is no secret that the Python packaging world is at something of a
crossroads; there have been debates and discussions about the packaging
landscape that started long before our <a href="https://lwn.net/Articles/924104/">2023
series</a> describing some of the difficulties.  There has been progress
since then—and incremental improvements all along, in truth—but a new
initiative is looking to overhaul packaging for the language.  At <a href="https://us.pycon.org/2025/">PyCon US 2025</a>, Barry Warsaw and
Jonathan Dekhtiar gave a presentation on the <a href="https://wheelnext.dev/">WheelNext project</a>, which is a community
effort that aims improve the experience for users and providers of Python
packages while also working with toolmakers and other parts of the
ecosystem to "<q>reinvent the wheel</q>".  While the project's name refers
to Python's <a href="https://packaging.python.org/en/latest/specifications/binary-distribution-format/">wheel</a>
binary distribution format, its goals stretch much further than simply the
format.]]></content:encoded>
</item>
<item>
<title><![CDATA[Advancing Protection in Chrome on Android]]></title>
<description><![CDATA[Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team


Android recently announced Advanced Protection, which extends Google’s Advanced Protection Program to a device-level security setting for Android users that need heightened security—such as journalists, elected official...]]></description>
<link>https://tsecurity.de/de/2874995/it-security-nachrichten/advancing-protection-in-chrome-on-android/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2874995/it-security-nachrichten/advancing-protection-in-chrome-on-android/</guid>
<pubDate>Tue, 08 Jul 2025 21:19:30 +0200</pubDate>
<content:encoded><![CDATA[<span class="byline-author">Posted by David Adrian, Javier Castro &amp; Peter Kotwicz, Chrome Security Team</span>

<p>
Android recently announced <a href="https://security.googleblog.com/2025/05/advanced-protection-mobile-devices.html">Advanced Protection</a>, which extends Google’s <a href="https://landing.google.com/intl/en_in/advancedprotection/">Advanced Protection Program</a> to a device-level security setting for Android users that need heightened security—such as journalists, elected officials, and public figures. Advanced Protection gives you the ability to activate Google’s strongest security for mobile devices, providing greater peace of mind that you’re better protected against the most sophisticated threats.
</p>
<p>
Advanced Protection acts as a single control point for at-risk users on Android that enables important security settings across applications, including many of your favorite Google apps, including Chrome. In this post, we’d like to do a deep dive into the Chrome features that are integrated with Advanced Protection, and how enterprises and users outside of Advanced Protection can leverage them.
</p>
<p>
Android Advanced Protection integrates with Chrome on Android in three main ways:
</p>
<ul>

<li><strong>Enables the “Always Use Secure Connections” </strong>setting for both public and private sites, so that users are protected from attackers reading confidential data or injecting malicious content into insecure plaintext HTTP connections. Insecure HTTP represents less than 1% of page loads for Chrome on Android. </li>

<li><strong>Enables full Site Isolation </strong>on mobile devices<strong> </strong>with 4GB+ RAM, so that potentially malicious sites are never loaded in the same process as legitimate websites. Desktop Chrome clients already have full Site Isolation.</li>

<li><strong>Reduces attack surface </strong>by disabling Javascript optimizations, so that Chrome has a smaller attack surface and is harder to exploit.</li>
</ul>
<p>
Let’s take a look at all three, learn what they do, and how they can be controlled outside of Advanced Protection.
</p>
<h3>Always Use Secure Connections</h3>


<p>
“Always Use Secure Connections” (also known as HTTPS-First Mode in blog posts and HTTPS-Only Mode in the enterprise policy) is a Chrome setting that forces HTTPS wherever possible, and asks for explicit permission from you before connecting to a site insecurely. There may be attackers attempting to interpose on connections on any network, whether that network is a coffee shop, airport, or an Internet backbone. This setting protects users from these attackers reading confidential data and injecting malicious content into otherwise innocuous webpages. This is particularly useful for Advanced Protection users, since in 2023, plaintext HTTP was <a href="https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/">used as an exploitation vector during the Egyptian election</a>.
</p>
<p>
Beyond Advanced Protection, we <a href="https://blog.chromium.org/2023/08/towards-https-by-default.html">previously posted</a> about how our goal is to eventually enable “Always Use Secure Connections” by default for all Chrome users. As we work towards this goal, in the last two years we have quietly been enabling it in more places beyond Advanced Protection, to help protect more users in risky situations, while limiting the number of warnings users might click through:
</p>
<ul>

<li>We added a new variant of the setting that only warns on public sites, and doesn’t warn on local networks or single-label hostnames (e.g. <code>192.168.0.1</code>, <code>shortlink/</code>, <code>10.0.0.1</code>). These names often cannot be issued a publicly-trusted HTTPS certificate. This variant protects against most threats—accessing a public website insecurely—but still allows for users to access local sites, which may be on a more trusted network, without seeing a warning. </li>

<li>We’ve automatically enabled “Always Use Secure Connections” for public sites in Incognito Mode for the last year, since Chrome 127 in June 2024.</li>

<li>We automatically prevent downgrades from HTTPS to plaintext HTTP on sites that Chrome knows you typically access over HTTPS (a heuristic version of the <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Strict-Transport-Security">HSTS header</a>), since Chrome 133 in January 2025.</li></ul><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1HgJLjo8SSJOSaofi-04nW0P6izX70Lq12Y8J_Rxm_M0i5DaYCQKTD34SA9KBd4SSWP-7YrsX3N_6x9EU-t4OL54ODNAaLSTxgmHxLn-4khVXEfCrtlX__DYOaeLStl9yaCJOaP7N3FpzwAp-UzdkS9YZvPgSxCeIZSMk1O0sNqKjLsR_zTQk5PGX1XLt/s1600/Screenshot%202025-07-08%20at%2012.26.45%E2%80%AFPM.png"><img alt="" border="0" data-original-height="866" data-original-width="407" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1HgJLjo8SSJOSaofi-04nW0P6izX70Lq12Y8J_Rxm_M0i5DaYCQKTD34SA9KBd4SSWP-7YrsX3N_6x9EU-t4OL54ODNAaLSTxgmHxLn-4khVXEfCrtlX__DYOaeLStl9yaCJOaP7N3FpzwAp-UzdkS9YZvPgSxCeIZSMk1O0sNqKjLsR_zTQk5PGX1XLt/s1600/Screenshot%202025-07-08%20at%2012.26.45%E2%80%AFPM.png"></a></div><p><em>Always Use Secure Connections has two modes—warn on insecure public sites, and warn on any insecure site.</em>
</p>
Any user can enable “Always Use Secure Connections” in the Chrome Privacy and Security settings, regardless of if they’re using Advanced Protection. Users can choose if they would like to warn on <em>any</em> insecure site, or only insecure public sites. Enterprises can opt their fleet into either mode, and set exceptions using the <code><a href="https://chromeenterprise.google/policies/#HttpsOnlyMode">HTTPSOnlyMode</a></code> and <code><a href="https://chromeenterprise.google/policies/#HttpAllowlist">HTTPAllowlist</a></code> policies, respectively. Website operators should protect their users' confidentiality, ensure their content is delivered exactly as they intended, and avoid warnings, by deploying HTTPS.<div><br><h3>Full Site Isolation</h3><p><a href="https://youtu.be/OH-bt7spDgo?si=42mRq7VdtpC1q-5P">Site Isolation</a> is a security feature in Chrome that isolates each website into its own rendering OS process. This means that different websites, even if loaded in a single tab of the same browser window, are kept completely separate from each other in memory. This isolation prevents a malicious website from accessing data or code from another website, even if that malicious website manages to exploit a vulnerability in Chrome’s renderer—a second bug to escape the renderer sandbox is required to access other sites. Site isolation improves security, but requires extra memory to have one process per site. Chrome Desktop isolates all sites by default. However, Android is particularly sensitive to memory usage, so for mobile Android form factors, when Advanced Protection is off, Chrome will only isolate a site if a user logs into that site, or if the user submits a form on that site. On Android devices with 4GB+ RAM in Advanced Protection (and on all desktop clients), Chrome will isolate <em>all</em> sites. Full Site Isolation significantly reduces the risk of cross-site data leakage for Advanced Protection users.
</p><h3>JavaScript Optimizations and Security</h3><p>
Advanced Protection reduces the attack surface of Chrome by disabling the higher-level optimizing Javascript compilers inside V8. V8 is Chrome’s high-performance Javascript and <a href="https://webassembly.org/">WebAssembly</a> engine. The optimizing compilers in V8 make certain websites run faster, however they historically also have been a source of known exploitation of Chrome. Of all the patched security bugs in V8 with known exploitation, disabling the optimizers would have mitigated ~50%. However, the optimizers are why Chrome scores the highest on industry-wide benchmarks such as <a href="https://browserbench.org/Speedometer3.0/">Speedometer</a>. Disabling the optimizers blocks a large class of exploits, at the cost of causing performance issues for some websites.
</p><p>
Javascript optimizers can be disabled outside of Advanced Protection Mode via the “Javascript optimization &amp; security” Site Setting. The Site Setting also enables users to disable/enable Javascript optimizers on a per-site basis. Disabling these optimizing compilers is not limited to Advanced Protection. Since Chrome 133, we’ve exposed this as a Site Setting that allows users to enable or disable the higher-level optimizing compilers on a per-site basis, as well as change the default.
</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-Dq8CpPPUekjbnx8TsxdjfADyWQwNAc4C_yzqUSk7fOmORNB_CAbEoNz9TOGr_8uhZyzBsgdShufodjp4gQAQeTZP1OF_sit9wEjBhZmRbDDp1CyOQsHBCJEGuQ1gHj2mSxoHW6ixhlmzEvcCY5ko8J7krahh8jZxNYwsGN-zTUQsJ4Psm-E810GmrAy9/s1600/Screenshot%202025-07-08%20at%2012.31.19%E2%80%AFPM.png"><img alt="" border="0" data-original-height="730" data-original-width="672" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-Dq8CpPPUekjbnx8TsxdjfADyWQwNAc4C_yzqUSk7fOmORNB_CAbEoNz9TOGr_8uhZyzBsgdShufodjp4gQAQeTZP1OF_sit9wEjBhZmRbDDp1CyOQsHBCJEGuQ1gHj2mSxoHW6ixhlmzEvcCY5ko8J7krahh8jZxNYwsGN-zTUQsJ4Psm-E810GmrAy9/s1600/Screenshot%202025-07-08%20at%2012.31.19%E2%80%AFPM.png"></a></div><p><em>Settings -&gt; Privacy and Security -&gt; Javascript optimization and security</em>
</p><p>
This setting can be controlled by the <code><a href="https://chromeenterprise.google/policies/#DefaultJavaScriptOptimizerSetting">DefaultJavaScriptOptimizerSetting</a></code>  enterprise policy, alongside <code><a href="https://chromeenterprise.google/policies/#JavaScriptOptimizerAllowedForSites">JavaScriptOptimizerAllowedForSites</a></code> and <code><a href="https://chromeenterprise.google/policies/#JavaScriptOptimizerBlockedForSites">JavaScriptOptimizerBlockedForSites</a></code> for managing the allowlist and denylist. Enterprises can use this policy to block access to the optimizer, while still allowlisting<sup><a href="http://security.googleblog.com/2025/07/advancing-protection-in-chrome-on.html#fn1" rel="footnote">1</a></sup> the SaaS vendors their employees use on a daily basis. It’s available on Android and desktop platforms

</p><p>
Chrome aims for the default configuration to be secure for all its users, and we’re continuing to raise the bar for V8 security in the default configuration by <a href="https://v8.dev/blog/sandbox">rolling out the V8 sandbox</a>. 
</p><h3>Protecting All Users</h3><p>
Billions of people use Chrome and Android, and not all of them have the same risk profile. Less sophisticated attacks by commodity malware can be very lucrative for attackers when done at scale, but so can sophisticated attacks on targeted users. This means that we cannot expect the security tradeoffs we make for the default configuration of Chrome to be suitable for everyone. 
</p><p>
Advanced Protection, and the security settings associated with it, are a way for users with varying risk profiles to tailor Chrome to their security needs, either as an individual at-risk user. Enterprises with a fleet of managed Chrome installations can also enable the underlying settings now. Advanced Protection is available on Android 16 in Chrome 137+. 
</p><p>
We additionally recommend at-risk users join the <a href="https://landing.google.com/intl/en_in/advancedprotection/">Advanced Protection Program with their Google accounts</a>, which will require the account to use phishing-resistant multi-factor authentication methods and enable Advanced Protection on any of the user’s Android devices. We also recommend users enable automatic updates and always keep their Android phones and web browsers up to date.
</p><!--Footnotes themselves at the bottom.-->

<h3>Notes</h3><div class="footnotes"><hr><ol><li>
     Allowlisting only works on platforms capable of full site isolation—any desktop platform and Android devices with 2GB+ RAM. This is because internally allowlisting is dependent on <a href="http://security.googleblog.com/2025/07/issues.chromium.org/issues/40259221">origin isolation</a>. <a href="http://security.googleblog.com/2025/07/advancing-protection-in-chrome-on.html#fnref1" rev="footnote">↩</a></li></ol></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The great convergence: Why your data’s past and future are colliding]]></title>
<description><![CDATA[For decades, a fundamental divide has shaped enterprise data strategy: the absolute separation between operational and analytical systems. On one side stood the digital engine of the company: the online transaction processing (OLTP) systems that manage inventory in real-time. On the other, the st...]]></description>
<link>https://tsecurity.de/de/2874058/it-security-nachrichten/the-great-convergence-why-your-datas-past-and-future-are-colliding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2874058/it-security-nachrichten/the-great-convergence-why-your-datas-past-and-future-are-colliding/</guid>
<pubDate>Tue, 08 Jul 2025 15:03:59 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For decades, a fundamental divide has shaped enterprise data strategy: the absolute separation between operational and analytical systems. On one side stood the digital engine of the company: the online transaction processing (OLTP) systems that manage inventory in real-time. On the other, the strategic brains: the online analytical processing (OLAP) platforms that sift through historical data to support planning and strategy. This divide, traditionally bridged by batch extract, transform, load (ETL), forced leaders to make decisions based on yesterday’s insights.</p>



<p>The availability of AI that can provide strategic insights in real-time is tearing down this wall. Forward-thinking organizations are building unified platforms that combine operational and analytical capabilities. This convergence enables real-time analysis of live data streams, allowing companies to replace reactive reporting with proactive decision-making that delivers immediate business value.</p>



<h3 class="wp-block-heading"><strong>From reactive to proactive: Real-time value in action</strong></h3>



<p>The convergence of operational and analytical data transforms business decision-making from reactive to in-the-moment thinking. Instead of asking “what happened,” organizations can focus on “what’s happening <em>now</em>?” and “what can I influence next?”</p>



<p>For example:</p>



<ul class="wp-block-list">
<li><a href="https://marketingplatform.google.com/about/resources/how-the-north-face-increased-conversions-3x/#:~:text=By%20using%20Google%20Tag%20Manager,increase%20in%20conversions%20and%20revenue." target="_blank" rel="noreferrer noopener"><strong>The North Face</strong></a> analyzed real-time search data to discover that customers were searching for a “midi parka,” a term absent from their product descriptions. By quickly renaming a product to match this trend, they saw a three-fold increase in conversions overnight.</li>



<li>In logistics, <a href="https://cloud.google.com/transform/101-real-world-generative-ai-use-cases-from-industry-leaders#:~:text=Geotab%2C%20a%20global%20leader%20in,safer%20and%20more%20sustainable%20cities." target="_blank" rel="sponsored"><strong>Geotab</strong></a> is analyzing billions of daily data points from 4.6 million connected vehicles for real-time fleet optimization and driver safety.</li>



<li>In financial services,<a href="http://transparently.ai/" rel="sponsored"> </a><a href="https://cloud.google.com/customers/transparentlyai?e=48754805" target="_blank" rel="sponsored"><strong>Transparently.AI</strong></a> built a fraud detection platform that achieves 90% accuracy by analyzing transactions as they happen, not after the fact.</li>
</ul>



<h3 class="wp-block-heading"><strong>The technology making convergence a reality</strong></h3>



<p>The shift from siloed, lagging data to real-time, actionable intelligence is made possible by a new generation of cloud-native technologies. Together, they create a powerful <strong>data flywheel</strong>: a continuous loop where live operational data is analyzed for insights, which are then pushed back into business systems to guide action and improve operations. This self-reinforcing cycle is built on four key technologies:</p>



<p><strong>Data federation</strong>: Federation allows an analytical platform to query data directly from operational databases, without moving or copying it. This zero-copy approach allows analysts to combine real-time transactional data with historical data to get a complete, up-to-the-second view of a business operations.</p>



<p><strong>Real-time data streaming: </strong>Technologies like change data capture (CDC) can stream updates from operational systems to analytical platforms as they happen, without impacting performance. This ensures that analytical tools are always working with the freshest available data.</p>



<p><strong>Unified storage layer</strong>: A modern data lakehouse stores information in open formats accessible to both analytical engines and transactional databases. This eliminates data duplication and allows a single dataset to support everything from advanced analytics and BI dashboards to operational decision-making.</p>



<p><strong>Reverse ETL:</strong> Reverse ETL sends insights, such as customer scores or product recommendations, back into business systems like CRMs and marketing platforms. This puts analytics directly into the hands of frontline teams to drive action in real time.</p>



<h3 class="wp-block-heading"><a></a><strong>The ultimate catalyst: Giving AI a memory</strong></h3>



<p>Converged operational and analytic data systems lay the groundwork for real-time intelligence, but the next wave of business impact will come from autonomous agents that can make and act on decisions – not just support them. However, today’s large language models have a fundamental limitation: They lack business context and are, simply put, forgetful. Without an external brain, every interaction starts from a blank slate.</p>



<p>This is where connecting agents with data across analytical and operational platforms becomes critical. To build truly useful agents, we must give them two types of memory:</p>



<p><strong>1. Semantic memory:</strong> This is the agent’s deep, contextual library of knowledge about your business, products, and industry. To improve AI accuracy and reduce hallucinations, modern data platforms now support retrieval-augmented generation (RAG), a technique that lets AI models ground responses in real business data, not just their generic training patterns. This capability relies on vector embeddings and vector search, which finds relevant content by comparing the meaning of queries and data, rather than by exact keywords. By using this approach, AI systems can retrieve the right information from enterprise data platforms, multimodal datasets (e.g., documents), knowledge bases, or even live operational data.</p>



<p><strong>2. Transactional memory:</strong> For personalization and reliability, agents need to remember specific interactions and maintain state. This includes both <strong>episodic memory</strong> (a log of conversations and user preferences, so the agent can carry on conversations that feel continuous, not like a reset each time) and <strong>state management</strong> (tracking progress through complex tasks). If interrupted, an agent uses this stateful memory to pick up where it left off.</p>



<p>Supporting this memory architecture requires a new generation of data infrastructure: systems that handle both structured and unstructured data, offer strong consistency, and persist state reliably. Without this foundation, AI agents will remain clever but forgetful, unable to reason or adapt in meaningful ways.</p>



<h3 class="wp-block-heading"><strong>The CIO’s new playbook: Architecting the intelligent enterprise</strong></h3>



<p>For CIOs, this convergence means a fundamental shift from managing siloed systems to architecting a unified enterprise platform where a real-time data flywheel can spin. This requires building a resilient data foundation that can deliver immediate business value today while also supporting the semantic and transactional memory that tomorrow’s autonomous AI agents require. By solving AI’s inherent “memory problem,” this approach paves the way for truly intelligent systems that can reason, plan, and act with full business context, driving unprecedented innovation.</p>



<p>At Google Cloud, we’ve seen these patterns emerge across industries, from retail to travel to finance. Our platform is designed to support this shift: open by design but also unified and built for scale. It is engineered to converge operational and analytical data so organizations can move from insight to action, without delay.</p>



<p>Learn more by <a href="https://cloud.google.com/resources/content/executives-guide-value-data-ai" target="_blank" rel="noreferrer noopener">reading</a> the data leaders’ best practice guide for data and AI.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.13 update gets fixes for more handhelds, fixes WiFi regression on Steam Deck OLED]]></title>
<description><![CDATA[Valve have launched the latest SteamOS 3.7.13 stable update, further enhancing how it runs on more handheld gaming PCs..Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/2860697/linux-tipps/steamos-3713-update-gets-fixes-for-more-handhelds-fixes-wifi-regression-on-steam-deck-oled/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2860697/linux-tipps/steamos-3713-update-gets-fixes-for-more-handhelds-fixes-wifi-regression-on-steam-deck-oled/</guid>
<pubDate>Tue, 01 Jul 2025 00:35:42 +0200</pubDate>
<content:encoded><![CDATA[Valve have launched the latest SteamOS 3.7.13 stable update, further enhancing how it runs on more handheld gaming PCs.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt>.</p><p>Read the full article on <a href="https://www.gamingonlinux.com/2025/06/steamos-3-7-13-update-gets-fixes-for-more-handhelds-fixes-wifi-regression-on-steam-deck-oled/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SteamOS 3.7.13 update brings wider handheld support, fixes WiFi regression on Steam Deck OLED]]></title>
<description><![CDATA[Valve have launched the latest SteamOS 3.7.13 stable update, further enhancing support for more handheld gaming PCs..Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/2860678/linux-tipps/steamos-3713-update-brings-wider-handheld-support-fixes-wifi-regression-on-steam-deck-oled/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2860678/linux-tipps/steamos-3713-update-brings-wider-handheld-support-fixes-wifi-regression-on-steam-deck-oled/</guid>
<pubDate>Tue, 01 Jul 2025 00:21:12 +0200</pubDate>
<content:encoded><![CDATA[Valve have launched the latest SteamOS 3.7.13 stable update, further enhancing support for more handheld gaming PCs.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/steamos%20plain%202025.jpg" alt>.</p><p>Read the full article on <a href="https://www.gamingonlinux.com/2025/06/steamos-3-7-13-update-brings-wider-handheld-support-fixes-wifi-regression-on-steam-deck-oled/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[News alert: SquareX research  finds browser AI agents are proving riskier than human employees]]></title>
<description><![CDATA[Palo Alto, Calif., Jun. 30, 2025, CyberNewswire–Every security practitioner knows that employees are the weakest link in an organization, but this is no longer the case.

SquareX’s research reveals that Browser AI Agents are more likely to fall prey … (more…) 
The post News alert: SquareX researc...]]></description>
<link>https://tsecurity.de/de/2860288/it-security-nachrichten/news-alert-squarex-research-finds-browser-ai-agents-are-proving-riskier-than-human-employees/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2860288/it-security-nachrichten/news-alert-squarex-research-finds-browser-ai-agents-are-proving-riskier-than-human-employees/</guid>
<pubDate>Mon, 30 Jun 2025 18:48:41 +0200</pubDate>
<content:encoded><![CDATA[<p>Palo Alto, Calif., Jun. 30, 2025, CyberNewswire–Every security practitioner knows that employees are the weakest link in an organization, but this is no longer the case.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/SquareX-logo.png" rel="nofollow"><img decoding="async" class="aligncenter size-full wp-image-33169" src="https://www.lastwatchdog.com/wp/wp-content/uploads/SquareX-logo.png" alt="" width="209" height="69" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/SquareX-logo.png 209w, https://www.lastwatchdog.com/wp/wp-content/uploads/SquareX-logo-100x33.png 100w" sizes="(max-width: 209px) 100vw, 209px"></a></p>
<p><a href="https://sqrx.com/?utm_campaign=15399438-YOBB%20-%20June%202025&amp;utm_source=pressrelease&amp;utm_medium=pressrelease" rel="nofollow">SquareX</a>’s research reveals that Browser AI Agents are more likely to fall prey … <a href="https://www.lastwatchdog.com/news-alert-squarex-research-finds-browser-ai-agents-are-proving-riskier-than-human-employees/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/news-alert-squarex-research-finds-browser-ai-agents-are-proving-riskier-than-human-employees/">News alert: SquareX research  finds browser AI agents are proving riskier than human employees</a> first appeared on <a href="https://www.lastwatchdog.com/">The Last Watchdog</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,43ms -->